.de TLD offline due to DNSSEC? | Hacker News
TL;DR AI
2 min readKey summary
A DNSSEC signing error in the .de zone caused validating resolvers to return SERVFAIL for many .de domains.
DENIC had published a malformed RRSIG for an NSEC3 record that did not validate against the active ZSK.
Direct queries to authoritative nameservers still worked, but recursive resolvers such as Unbound and Google Public DNS failed validation.
Because of anycast, some requests intermittently succeeded when they hit servers still serving the older signature.
The issue affected major sites like Amazon.de and SPIEGEL.de until the signature problem was corrected.



