DNS Infrastructure & Naming Conventions
When DNSSEC goes wrong: how we responded to the .de TLD outage

When DNSSEC goes wrong: how we responded to the .de TLD outage

5/6/2026 · Sebastiaan Neuteboom, Christian Elmerot, Max Worsley

What this post added

This post details Cloudflare's response to a DNSSEC outage affecting the .de TLD. It explains the technical details of DNSSEC, the observed impact on 1.1.1.1 (spike in SERVFAILs, increased query volume), the effectiveness of 'serve stale' (RFC 8767) in mitigating user impact, and the implementation of a temporary mitigation equivalent to a Negative Trust Anchor (NTA) to bypass DNSSEC validation for .de domains. It also highlights a bug in Extended DNS Error (EDE) propagation for DNSSEC validation failures.

Read the original post ↗