
7/15/2025 · Ash Pallarito, Joe Abley
What this post added
This post details a specific incident where a misconfiguration in service topologies led to a 62-minute outage of the 1.1.1.1 public DNS Resolver. It explains the root cause involving legacy systems for advertising IP addresses, the accidental inclusion of 1.1.1.1 prefixes in a pre-production Data Localization Suite (DLS) service topology, and how a subsequent change triggered the withdrawal of these prefixes globally. The post also discusses the technical investigation, the interaction between legacy and newer configuration systems, the impact on DNS traffic (UDP, TCP, DoT, but not DoH due to different IP usage), and the BGP route withdrawal. It outlines the incident timeline and the fix deployed, emphasizing the need for progressive deployment methodologies and improved synchronization between configuration systems.