A broken DNSSEC rollover took down .AL. Now 1.1.1.1 tells you when validation is bypassed

TL;DR AI
2 min readKey summary
On July 3, 2026, a flawed DNSSEC rollover for Albania’s .al TLD caused DNSKEY and DS records to stop matching, triggering validation failures.
Validating resolvers, including Cloudflare’s 1.1.1.1, returned SERVFAIL for affected .al domains until Cloudflare temporarily restored resolution with a Negative Trust Anchor.
The outage made .al sites unreachable for users relying on DNSSEC-validating resolvers and highlighted the operational risk of DNSSEC rollovers gone wrong.
For the first time in this kind of incident, 1.1.1.1 also returned an Extended DNS Error to signal that DNSSEC validation had been bypassed.
The .al zone later remained unsigned after the DS record was removed from the root.
