When DNSSEC goes wrong: how we responded to the .de TLD outage
ID: c37e874d-5dcc-5822-892a-6c5747c60256
STIX ID: report--c37e874d-5dcc-5822-892a-6c5747c60256
Feed Name: Cloudflare Blog
Threat Score
On May 5, 2026 DENIC published incorrect DNSSEC signatures for the .de TLD causing validating resolvers to reject responses and return SERVFAIL; Cloudflare observed increased SERVFAILs and query retries, relied on RFC8767 “serve stale” behavior to reduce user impact, and deployed an override equivalent to a Negative Trust Anchor to bypass DNSSEC validation for .de while DENIC fixed the key rollover misconfiguration.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
