A broken DNSSEC rollover took down .al. Now 1.1.1.1 tells you when validation is bypassed
ARCHITECT FEATURED ANALYSIS

A broken DNSSEC rollover took down .al. Now 1.1.1.1 tells you when validation is bypassed

BY

Sebastiaan Neuteboom

SOURCE

The Cloudflare Blog

DATE

READ

1 min read

When a failed DNSSEC key rollover took down the .al TLD, we deployed a Negative Trust Anchor to restore resolution. This time, though, clients didn’t have to take our word for it: 1.1.1.1 returned EDE 33, a new DNS …

When a failed DNSSEC key rollover took down the .al TLD, we deployed a Negative Trust Anchor to restore resolution. This time, though, clients didn’t have to take our word for it: 1.1.1.1 returned EDE 33, a new DNS error code that signals directly in the response that DNSSEC validation was bypassed.