INFRA Signal 202
A broken DNSSEC rollover took down .al. Now 1.1.1.1 tells you when validation is bypassed
Operators of DNSSEC-signed zones now have visibility into when a resolver has suspended validation, rather than receiving a seemingly legitimate response with no indication that spoofing protections are inactive. This makes the security tradeoff of NTAs explicit to clients and aids debugging during DNSSEC incidents.
Written by elseif from the cluster below · every claim links back to a sourceThe three things worth knowing
The .al TLD became unreachable on validating resolvers after the operator published a new DNSKEY but the root zone DS record still pointed to the old key, breaking the chain of trust.
Cloudflare deployed a Negative Trust Anchor for .al roughly three hours after the break, restoring resolution at the cost of DNS spoofing protection for the entire TLD.
Cloudflare's 1.1.1.1 now returns EDE 33 alongside responses served under an NTA, giving clients direct notification in the DNS response that validation was bypassed.
THE CLUSTER
↗