Again: this mitigates (but probably does not decisively solve)
one avenue for downgrade attacks. But downgrade attacks against HTTPS would remain possible --- trivial, in fact, without HSTS, which leaves you with the first-contact problem with or without DNSSEC.
So again: what's the point? Compared to HSTS headers, DNSSEC is incredibly expensive.