Briefing

Albanian .AL TLD DNSSEC Rollover Failure Forces Cloudflare to Deploy NTA and EDE Codes

security
by Sebastiaan Neuteboom · Cloudflare

Patch DNSSEC validation to respect EDE codes and monitor for NTA usage to detect unvalidated responses.

What to do now

Patch DNSSEC validation to respect EDE codes and monitor for NTA usage to detect unvalidated responses.

Summary

On July 3, 2026, the Albanian .AL registry attempted a DNSSEC key rollover that caused validation failures for all resolving clients, including Cloudflare’s 1.1.1.1 resolver.

The failure stemmed from publishing a new DNSKEY while the root DS record still pointed to the old key, followed by the removal of the new key and later the DS record itself, leaving the zone unsigned. Cloudflare responded by installing a Negative Trust Anchor (NTA) to bypass DNSSEC validation and restore resolution.

To signal the bypass, 1.1.1.1 implemented an Extended DNS Error (EDE) code as defined in RFC 8914, marking responses served under the NTA. The NTA was removed once the DS record was deleted from the root zone, restoring normal validation.

This incident highlights the fragility of DNSSEC rollovers and the importance of transparent NTA signaling for clients and monitoring tools.

Key changes

  • .AL DNSSEC key rollover caused validation failures for all resolvers
  • Root DS record still pointed to old DNSKEY during rollover
  • Cloudflare installed NTA to bypass validation and restore resolution
  • Implemented EDE code to signal NTA presence in responses
  • EDE defined in RFC 8914 and now used by 1.1.1.1
  • NTA removed after DS record deleted from root zone
  • Resolution restored once DS record removed
  • Incident underscores need for transparent NTA signaling

Affects

enterprise

Customer impact

Analyzing matches…

Ask about this story

Impact on an agency? Which customers? Compare historically Risks of waiting