DNS Infrastructure & Naming Conventions
A broken DNSSEC rollover took down .AL. Now 1.1.1.1 tells you when validation is bypassed

A broken DNSSEC rollover took down .AL. Now 1.1.1.1 tells you when validation is bypassed

7/14/2026 · Sebastiaan Neuteboom

What this post added

Introduced Extended DNS Error (EDE) code 33 to signal the use of Negative Trust Anchors (NTAs) during DNSSEC validation bypasses. This provides transparency to clients and monitoring tools about why a response was served without full DNSSEC validation. Implemented this alongside EDE 9 (DNSKEY Missing) during the .al TLD DNSSEC incident. Updated kdig and submitted a pull request for Unbound to recognize EDE 33. Submitted an Internet-Draft to the IETF DNSOP Working Group for standardization.

Read the original post ↗