On 3 July the Albanian domain .AL stopped opening for resolvers with DNSSEC checking on. The operator AKEP had changed the key. But the record in the root zone still pointed to the old one. Cloudflare's public resolver 1.1.1.1 restored access with a workaround, but for the first time marked the answer with a code that openly says: this check was skipped.
- The .AL zone has been broken for DNSSEC validation since 3 July - AKEP rotated the key, the root zone still points to the old one (id=26319).
- Cloudflare's 1.1.1.1 fixes it on the spot with a negative trust anchor, until 17:15 UTC the same day.
- What's new: the answers carry code EDE 33 - they openly say the check was bypassed, instead of just staying silent.
DNSSEC is the signature under the DNS answer. Every domain in that chain carries a cryptographic key, and the parent registry, the root zone, holds a fingerprint of it - a DS record. Before it hands you the site's address, the resolver checks whether the signature matches the fingerprint. If the domain's operator rotates the key (a normal procedure, called a 'rollover'), it has to upload the new fingerprint too. Skip that, and the chain of trust breaks, and every resolver that checks signatures refuses to resolve the domain. That's exactly what happened on 3 July with .AL, the Albanian national domain.
Keys break all the time. The outage itself is the boring part. What's interesting is what Cloudflare does after it. The standard quick fix is a negative trust anchor - the resolver simply stops checking that domain and returns the answer as if nothing happened. And here's the subtle part - a resolver that quietly stops checking looks, from outside, identical to one that checked and confirmed everything's fine. EDE code 33 puts a machine-readable label on the workaround: 'I skipped the check here', written right into the answer itself. .AL is still effectively unsigned today, so the fix is a temporary compromise - it buys access while the domain gets fixed.
The lesson goes beyond DNS. A system that admits when it's dropped its guard is safer than one that looks clean and has simply stopped watching. If you're building something that guards - a firewall, an auth layer, whatever - the question isn't just whether it works, it's whether it tells you when it stops working the way it should. A transparent bypass beats a silent failure every time.