Routine DNSSEC Key Rollover Error Causes Massive .de Domain Outage in Germany
On May 5, 2026, a routine DNSSEC key rollover error at DENIC, the registry for Germany's .de top-level domain, caused widespread internet outages affecting millions of domains. The incident was not a cyberattack but resulted from faulty code in DENIC's new signing system, which generated invalid cryptographic signatures. Consequently, DNSSEC-validating resolvers globally, including Cloudflare and Google Public DNS, rejected these records, returning SERVFAIL errors. Although only 3.6% of .de domains use DNSSEC, the outage impacted nearly all .de sites because invalid NSEC3 records poisoned the delegation chain for unsigned domains too. Major services like Amazon.de, Deutsche Bahn, and banking apps became unreachable for several hours across Germany and neighboring countries. The outage spread gradually as DNS caches expired. This event highlights critical vulnerabilities in internet infrastructure, emphasizing that a single point of failure in cryptographic key management can disrupt national digital services. Organizations relying on .de domains faced significant revenue loss and trust damage, underscoring the need for robust monitoring systems to detect such infrastructure failures rapidly rather than relying on customer complaints.
Editorial responsibility
- No named human review is recorded for this page.
- Reports are grouped by semantic similarity and deterministic rules. Language models may assist titles, summaries, translation and cross-source analysis; the page itself is projected from evidence records.
- Current automated evidence projection