DENIC DNSSEC Misconfiguration Causes .de SERVFAIL Outage, Cloudflare Mitigates with Override Rule
Configure your DNS resolver to treat .de as an insecure zone using an override rule to bypass DNSSEC validation during the outage.
Configure your DNS resolver to treat .de as an insecure zone using an override rule to bypass DNSSEC validation.
Summary
On May 5, 2026 at roughly 19:30 UTC, DENIC, the operator of the .de country-code top-level domain, began publishing incorrect DNSSEC signatures for the .de zone. Any validating resolver, including Cloudflare’s public DNS 1.1.1.1, had to reject the signatures and return SERVFAIL, causing a spike in failure responses that grew over the next three hours as cached records expired. The incident also saw a large increase in query volume as clients retried failed queries, while the NOERROR rate remained stable thanks to the resolver’s serve‑stale behavior.
Cloudflare’s mitigation involved marking .de as an insecure zone via an existing override rule in its Big Pineapple resolver, effectively acting as a Negative Trust Anchor. This bypassed DNSSEC validation for .de domains, allowing queries to succeed until the registry corrected the signatures. The event underscored the critical need for coordinated key rotation and the value of RFC‑8767 serve‑stale in reducing user impact during DNS outages.
Key changes
- DENIC published incorrect DNSSEC signatures for .de on May 5, 2026 at ~19:30 UTC
- Validating resolvers returned SERVFAIL for .de queries, causing a spike that grew over 3 hours
- Serve‑stale per RFC 8767 allowed resolvers to continue serving cached records past TTL
- Cloudflare’s Big Pineapple resolver marked .de as insecure via an override rule, equivalent to a Negative Trust Anchor
- The NOERROR rate stayed stable due to serve‑stale, masking user impact
- The incident highlighted the importance of coordinated DNSSEC key rotation
- Cloudflare’s mitigation prevented widespread SERVFAIL for its users