logo

A broken DNSSEC rollover took down .AL. Now 1.1.1.1 tells you when validation is bypassed

ID: 89e3be97-5786-5eb7-8614-c3ac2d55a2b7

STIX ID: report--89e3be97-5786-5eb7-8614-c3ac2d55a2b7

Feed Name: Cloudflare Blog

Threat Score
45/100

Date Published: 2026-07-14

Date Updated: 2026-07-15

Author: Sebastiaan Neuteboom

...
...

Cloudflare reports that on 2026-07-03 the .AL TLD experienced a broken DNSSEC key rollover: the registry replaced its DNSKEY(s) without coordinating the matching DS at the root, causing validating resolvers to fail. Cloudflare applied a Negative Trust Anchor (NTA) on 1.1.1.1 to restore reachability, and simultaneously began returning a new Extended DNS Error (EDE 33) to transparently signal responses served under the NTA; the DS was subsequently removed from the root and .AL remained unsigned.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.