
3/9/2022 · David Belson
What this post added
This post details a specific DNSSEC misconfiguration at the .fj ccTLD that caused widespread outages. It explains how a missing DNSKEY record in the root zone, likely due to an improperly timed rollover, led to SERVFAIL errors for resolvers performing strict DNSSEC validation. The post uses `dig` output and Cloudflare's 1.1.1.1 resolver data to illustrate the problem and its resolution, emphasizing the significant impact of ccTLD-level DNSSEC errors.