OpenAlias parsing and authenticated recipient resolution for Dart.
OpenAliasResolver requires locally validated DNSSEC evidence by default.
Supplying trustedValidators also requires local validation and pins the exact
validator identities in that list; it cannot be relaxed to a remote resolver's
AD assertion. Manual selectOpenAliasRecipient calls are always unauthenticated.
The default uniqueAddress policy rejects multiple addresses and conflicting
records. OpenAliasSelection.first is explicitly order-dependent and should be
used only when that OpenAlias policy is intended. Separate payment IDs are
rejected unless allowPaymentId is enabled and the caller handles the returned
field for the selected application.