
7/14/2026 · Sebastiaan Neuteboom
What this post added
Introduced Extended DNS Error (EDE) code 33 to signal the use of Negative Trust Anchors (NTAs) during DNSSEC validation bypasses. This provides transparency to clients and monitoring tools about why a response was served without full DNSSEC validation. Implemented this alongside EDE 9 (DNSKEY Missing) during the .al TLD DNSSEC incident. Updated kdig and submitted a pull request for Unbound to recognize EDE 33. Submitted an Internet-Draft to the IETF DNSOP Working Group for standardization.