dnssec-keygen -a RSASHA512 -b 2048 -n HOST -T KEY mail.svr02.mucip.net
-rw------- 1 root root    1777 Aug 27 22:53 Kmail.svr02.mucip.net.+010+62877.private
-rw-r--r-- 1 root root     393 Aug 27 22:53 Kmail.svr02.mucip.net.+010+62877.key

Note the local-ddns part that matches the behaviour of update-policy local

        update-policy {
                grant local-ddns wildcard * ANY;
                grant mail.svr02.mucip.net wildcard * TXT;
        };