DENIC .de Domain Outage Caused by Signature Error
German domain registry DENIC experienced a major outage in May 2026, rendering thousands of .de domains temporarily inaccessible. The cause was identified as a DNSSEC signature error within Germany's DNS infrastructure.

The German domain registry DENIC experienced a significant disruption during the night of May 5-6, 2026, making numerous .de domains, including prominent ones like bahn.de and spiegel.de, globally inaccessible to a portion of users. The issue was not attributed to a cyberattack or incorrect domain configuration, but rather to a deep-seated signature error within Germany's DNS infrastructure.
The outage began during a scheduled maintenance window on May 5, around 21:40 CEST, and lasted until 23:30. During this period, users encountered error messages such as "DNS address of the server could not be found." DENIC confirmed the disruption and reported its resolution later that night.
The technical cause was identified as a faulty DNSSEC signature in the .de zone's DNSSEC records. Specifically, NSEC3 records, which cryptographically attest to the non-existence of a DS record for a given domain, were incorrectly signed. This faulty signature led DNSSEC-validating resolvers, including Google DNS and Cloudflare, to reject queries for affected .de domains, resulting in a SERVFAIL error.
DNSSEC (Domain Name System Security Extensions) is a security mechanism designed to protect DNS queries from manipulation by ensuring the authenticity of responses through cryptographic signatures. While the mechanism technically functioned correctly to protect users, in this instance, the failure originated within the registry's own signing infrastructure, rather than a compromise of the domains themselves.
The outage's impact was selective. Users employing modern, security-conscious DNS services that actively validate DNSSEC signatures were affected. Many domestic internet service providers, which do not validate signatures as strictly, were not impacted. Domain operators had no feasible recourse in this situation, as the error lay within the infrastructure managed by DENIC.