A broken DNSSEC rollover took down .AL. Now 1.1.1.1 tells you when validation is bypassed
ID: 89e3be97-5786-5eb7-8614-c3ac2d55a2b7
STIX ID: report--89e3be97-5786-5eb7-8614-c3ac2d55a2b7
Feed Name: Cloudflare Blog
Cloudflare reports that on 2026-07-03 the .AL TLD experienced a broken DNSSEC key rollover: the registry replaced its DNSKEY(s) without coordinating the matching DS at the root, causing validating resolvers to fail. Cloudflare applied a Negative Trust Anchor (NTA) on 1.1.1.1 to restore reachability, and simultaneously began returning a new Extended DNS Error (EDE 33) to transparently signal responses served under the NTA; the DS was subsequently removed from the root and .AL remained unsigned.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
