
5/6/2026 · Sebastiaan Neuteboom, Christian Elmerot, Max Worsley
What this post added
This post details Cloudflare's response to a DNSSEC outage affecting the .de TLD. It explains the technical details of DNSSEC, the observed impact on 1.1.1.1 (spike in SERVFAILs, increased query volume), the effectiveness of 'serve stale' (RFC 8767) in mitigating user impact, and the implementation of a temporary mitigation equivalent to a Negative Trust Anchor (NTA) to bypass DNSSEC validation for .de domains. It also highlights a bug in Extended DNS Error (EDE) propagation for DNSSEC validation failures.