When DNSSEC goes wrong: how we responded to the .de TLD outage
On May 5, 2026, DENIC's publication of broken DNSSEC signatures for the .de TLD caused widespread domain inaccessibility, but the impact was mitigated by serve stale, and resolution was eventually restored.
MAIN POINTS
- DENIC published broken DNSSEC signatures for the .de TLD on May 5, 2026.
- Millions of domains became unreachable due to the DNSSEC issue.
- Serve stale helped cushion the impact of the DNSSEC failure.
- Efforts were made to restore domain resolution after the incident.
TAKEAWAYS
- DNSSEC issues can lead to significant domain accessibility problems.
- Serve stale is an effective tool for mitigating DNS resolution disruptions.
- Quick response is crucial in restoring domain functionality after DNSSEC failures.
- Monitoring and addressing DNSSEC integrity is vital for maintaining domain accessibility.