DENIC: .de DNSSEC Signatures Failed Validation on 5 May 2026
A key rollover in DENIC's new signing system produced signatures validating resolvers rejected; .de names were unreachable for them for about 3 hours.
Published: · 2 min read
Event date: 2026-05-05 · Source: Analyse des DNS-Ausfalls vom 5. Mai 2026 (German), published 2026-05-08.
What happened
On 5 May 2026 a routine DNSSEC key rollover for the .de zone went wrong. DENIC, the registry for Germany's country-code TLD, published its analysis three days later, on 8 May 2026. During the rollover the zone was signed with signatures that DNSSEC-validating resolvers could not verify. For roughly three hours, resolvers that validate treated .de answers as bogus, so the domains behind them did not resolve for those users. Full normal operation was restored during the night of 5 to 6 May.
According to DENIC, the cause was a defect in custom code of its third-generation signing system, in production since April 2026. Instead of generating one key pair and replicating it to the three hardware security modules, the software generated a separate key pair on each module. Only one of the three matched the public key published in the DNSKEY record, so about two thirds of the signatures could not be validated. Monitoring did detect anomalies, but the alerts were not handled as they should have been.
Who is affected
Anyone whose users sit behind a validating resolver and who runs a .de domain, whether or not that domain has DNSSEC itself: when the delegation data in the parent zone cannot be validated, the child is unreachable too. Users behind non-validating resolvers noticed nothing. The incident is over; there is nothing to fix on the domain-owner side.
What to do
Nothing for this incident. Two lessons carry over to your own zones: after any key rollover, validate from an independent resolver rather than only from the signer, and make sure monitoring alerts reach a person. DENIC states that it is adjusting tests and alert handling.
How to check
The DNSSEC checker validates a domain's chain from the root, which is exactly the check that failed for .de that afternoon. A failed check means "could not be validated right now", not that the domain is gone.
Background
DNSSEC explained describes signing keys and DS records; the .de TLD page has the registry facts.
Sources
- DENIC eG, "Analyse des DNS-Ausfalls vom 5. Mai 2026", 8 May 2026: https://blog.denic.de/analyse-des-dns-ausfalls-vom-5-mai-2026/