DNSSEC is an extension to the existing DNS packet format and so does not need any encryption or related consideration from a packet capture point of view. As with traditional DNS packets, Wireshark will be able to capture DNSSEC packets using the same port mirroring concept.