.de domain outage caused by DNSSEC error
A faulty DNSSEC key change at DENIC on May 5th rendered millions of .de domains unreachable for approximately two hours.

DENIC eG, the registry for all German domain names, experienced a significant outage on May 5th, where a faulty DNSSEC key change made millions of .de domains globally inaccessible for about two hours.
Paradoxically, users with more security-oriented DNS configurations were disproportionately affected. DNSSEC (Domain Name System Security Extensions) is a security mechanism that cryptographically signs DNS responses to prevent spoofing and cache poisoning. When DENIC's routine key rollover failed and an invalid signature was introduced into the .de zone, all DNS-validating resolvers, including those from Cloudflare, Google, and Quad9, rejected responses. This resulted in users being unable to reach .de websites, even though the underlying web servers were functioning correctly.
The outage began around 9:40 PM local time, with DENIC issuing its first official incident report at 11:28 PM. Corrected data was distributed swiftly, and normal operations were largely restored by early morning on May 6th. Several prominent entities, including Deutsche Bahn and DHL, were impacted.
Experts suggest that businesses can mitigate such risks by enhancing DNS monitoring, paying close attention to DNSSEC errors, and selecting DNS providers with clear escalation procedures. While DNSSEC remains a crucial security feature, this incident highlights the need for resilient network planning.