It appears bind version <9.9.0 requires extra NSEC3 records to validate positive wildcard queries. It would be nice to have a compatibility config switch/option and ability for pdns to serve these extra records that older bind versions require to properly validate.
Ref to same issue with NSD: https://www.nlnetlabs.nl/bugs-script/show_bug.cgi?id=390
This issue was fixed in all bind production releases in December 2011 / January 2012
look for RT #26200
send extra NSEC3 because old BIND9 needs it, closes #814