Hi Markus
the name server from swizzonic is not supposed to provide you with a answer to all the queries.
I guess if I point to our recursive validating caching NS and it does not possess this data in it's cache, it will start by following from the root by asking for _.numberportability.ch to avoid revealing which host it is exactly looking for until it reaches the authoritative DNS for that zone and then ask this one directly for the desired RR.
I guess this is where something is breaking the chain.
I also don't see why the swizzonic DNS which is the authoritative primary should not answer to all queries. Well of course the DNSSEC chain (Signed DS entries) has to be followed from the root over ch. to swizzonic. But everything else should be obtainable from the authoritative server for that zone, right?
Right now, all needed RR within numberportability.ch resolve ok. So maybe the now found and fixed he issue.