#dnssec
DNSSEC MIGHT BE HARD, BUT IM FUCKING HARDER

LETSGO
May 22, 2026 at 10:39 AM
Update: DNSSEC-Störung bei .de behoben

Die DENIC meldet, dass die DNSSEC-Störung für .de-Domains behoben ist. Alle Systeme laufen wieder stabil. Die Ursachenanalyse läuft; Details folgen transparent, sobald verfügbar.

Danke für die Geduld! 

#DENIC #de #DNSSEC
May 5, 2026 at 11:42 PM
⚠️ Störung bei .de-Domains: Die DENIC meldet Probleme im DNS-Service. Betroffen sind alle DNSSEC-signierten Domains, was zu Fehlern bei der Erreichbarkeit führt. Die Analyse läuft unter Hochdruck.

Details folgen. #DENIC #DNSSEC #InternetStörung
May 5, 2026 at 9:46 PM
me: wow I wish I had *more* anxiety
dnssec: ....hey
August 2, 2026 at 12:14 PM
Every time DNSSEC comes up on HN, I find myself explaining how to write the bash `for` loop to `dig ds` the Tranco Top 1000 to see how low adoption is. Then I remembered I can just vibe code things now. So I did.

dnssecmenot.fly.dev
dnssec-me-not: tracking DNSSEC adoption in top domains
dnssecmenot.fly.dev
June 22, 2025 at 12:48 AM
@scanash.com getting a DNSSEC failure for @brookie.blog's alt account @brookie.readifur.gay tangled.org/strings/did:...
dnssec-failure.txt · by iame.li
tangled.org
July 26, 2026 at 12:56 AM
DNSSEC was such a pain in the ass to implement
May 22, 2026 at 1:24 PM
pretty hard to advocate for DNSSEC if even senate.gov can't keep it working reliably
June 1, 2025 at 8:59 PM
⚠️ Outage Alert: DENIC reports a major DNS service disruption affecting all DNSSEC-signed .de domains. This is causing global reachability issues. Technical teams are working at full speed on a fix.

Stay tuned for updates. #DENIC #DNSSEC #InternetOutage
May 5, 2026 at 9:47 PM
Mark your calendar!

Starting June 15, 2026, DNSSEC strict validation will be active across every Quad9 service endpoint, including 9.9.9.10. 🥳

#DNSSEC #DNS #infosec

quad9.net/news/blog/qu...
April 8, 2026 at 12:44 PM
Das technische Problem lag in der DNSSEC-Validierung. Der SOA-Eintrag für die Zone .de war nicht mehr gültig signiert, weshalb alle DNS-Server, die DNSSEC validierten, die Domains als nicht existent zurückmeldeten. 🤯

Zum Artikel: heise.de/-11283192
May 6, 2026 at 10:05 AM
Tomorrow is the day!! 👇

#DNSSEC #infosec
Mark your calendar!

Starting June 15, 2026, DNSSEC strict validation will be active across every Quad9 service endpoint, including 9.9.9.10. 🥳

#DNSSEC #DNS #infosec

quad9.net/news/blog/qu...
June 14, 2026 at 11:12 AM
Dienstagabend waren .de-Domains wegen DNSSEC-Fehlern nicht erreichbar. Einiges lässt sich rekonstruieren – noch schweigt sich die DENIC über die Ursache aus. #DNSSEC
Probleme mit .de-Domains: Was bisher bekannt ist
Dienstagabend waren .de-Domains wegen DNSSEC-Fehlern nicht erreichbar. Einiges lässt sich rekonstruieren – noch schweigt sich die DENIC über die Ursache aus.
www.heise.de
May 6, 2026 at 4:01 PM
Okay hat sich bestätigt: DENIC hat eine defekte DNSSEC-Signatur in der .de-Zone (NSEC3, keytag=33834). Jeder validierende Resolver — Google, Cloudflare, alle anderen — gibt SERVFAIL zurück. Die Domains und Server sind in Ordnung. DENIC muss neu signieren.
May 5, 2026 at 9:19 PM
Sicherheit bei mailbox erneut unabhängig bestätigt

Auch 2026 wird mailbox in die BSI Hall of Fame aufgenommen. Dieses Jahr stand die erfolgreiche Implementierung von DNSSEC im Zentrum der unabhängigen Prüfung: mailbox.org/de/news/bsi-...
September 21, 2026 at 7:25 AM
We no longer have any active servers in France and are continuing the process of leaving OVH. We'll be rotating our TLS keys and Let's Encrypt account keys pinned via accounturi. DNSSEC keys may also be rotated. Our backups are encrypted and can remain on OVH for now.
November 24, 2025 at 7:54 PM
Someone should make a reverse DNSSEC test that checks if your resolver validates, and if not shows a reassuring “you have good mitigations against DNSSEC misconfigurations.”

Anyway, Quad9 has unsecured versions of their UDP and DoH resolvers, which is what I use: quad9.net/service/serv...
May 6, 2026 at 8:50 AM
Good conversations only if they don't require DNSSEC.
May 5, 2026 at 9:42 PM
翻訳されたー素晴らしい
howdnssec.works/jp/
July 3, 2025 at 2:44 PM
DNSSEC too
February 12, 2025 at 2:37 AM
dnssec und ipv6 sind gut gemeint aber zu komplex für so ein fragiles system wie das internet, wir sollten endlich loslassen und diesen neumodischen quatsch wieder einstampfen
May 6, 2026 at 6:15 AM
Disregard, DNSSEC issue.
February 21, 2025 at 6:30 PM
We've officially migrated all domains under default nameservers to our own DNS nameservers implementation 👏

- DNSSEC support 🔒
- CNAME flattering 🫓
- Written in Rust (fast!!) 🦀
- XRPC API Endpoints (more on this soon)
May 22, 2026 at 12:37 PM