dnssec-keygen -a RSASHA512 -b 2048 -n HOST -T KEY mail.svr02.mucip.net
-rw------- 1 root root 1777 Aug 27 22:53 Kmail.svr02.mucip.net.+010+62877.private -rw-r--r-- 1 root root 393 Aug 27 22:53 Kmail.svr02.mucip.net.+010+62877.key
Note the local-ddns part that matches the behaviour of update-policy local
update-policy { grant local-ddns wildcard * ANY; grant mail.svr02.mucip.net wildcard * TXT; };