logo

When DNSSEC goes wrong: how we responded to the .de TLD outage

ID: c37e874d-5dcc-5822-892a-6c5747c60256

STIX ID: report--c37e874d-5dcc-5822-892a-6c5747c60256

Feed Name: Cloudflare Blog

Threat Score
0/100

Date Published: 2026-05-06

Date Updated: 2026-05-06

Author: Sebastiaan Neuteboom

...
...

On May 5, 2026 DENIC published incorrect DNSSEC signatures for the .de TLD causing validating resolvers to reject responses and return SERVFAIL; Cloudflare observed increased SERVFAILs and query retries, relied on RFC8767 “serve stale” behavior to reduce user impact, and deployed an override equivalent to a Negative Trust Anchor to bypass DNSSEC validation for .de while DENIC fixed the key rollover misconfiguration.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.