we_are_coded.by CODE · The world, decoded
БГ
Cloudflare

Cloudflare rolled out a code that shows when DNSSEC has been bypassed

CloudflareInfra

On 3 July the Albanian domain .AL stopped opening for resolvers with DNSSEC checking on. The operator AKEP had changed the key. But the record in the root zone still pointed to the old one. Cloudflare's public resolver 1.1.1.1 restored access with a workaround, but for the first time marked the answer with a code that openly says: this check was skipped.

In short
  • The .AL zone has been broken for DNSSEC validation since 3 July - AKEP rotated the key, the root zone still points to the old one (id=26319).
  • Cloudflare's 1.1.1.1 fixes it on the spot with a negative trust anchor, until 17:15 UTC the same day.
  • What's new: the answers carry code EDE 33 - they openly say the check was bypassed, instead of just staying silent.
Checked on15 July 2026Responsible editorTsvetelin IvanovHow we workMethod · Corrections

DNSSEC is the signature under the DNS answer. Every domain in that chain carries a cryptographic key, and the parent registry, the root zone, holds a fingerprint of it - a DS record. Before it hands you the site's address, the resolver checks whether the signature matches the fingerprint. If the domain's operator rotates the key (a normal procedure, called a 'rollover'), it has to upload the new fingerprint too. Skip that, and the chain of trust breaks, and every resolver that checks signatures refuses to resolve the domain. That's exactly what happened on 3 July with .AL, the Albanian national domain.

The facts: on 3 July 2026 .AL stopped opening for DNSSEC-validating resolvers - AKEP published a new DNSKEY, but the DS record in the root zone still pointed to the old key (id=26319), so the chain of trust broke. Cloudflare's public resolver 1.1.1.1 added a negative trust anchor (NTA) the same day, until 17:15 UTC, to restore access to .AL. As of Cloudflare's post (14 July), .AL remains effectively unsigned - a corrected DS record still doesn't exist. Source: Cloudflare, blog.cloudflare.com/dnssec-nta-ede-33/.

Keys break all the time. The outage itself is the boring part. What's interesting is what Cloudflare does after it. The standard quick fix is a negative trust anchor - the resolver simply stops checking that domain and returns the answer as if nothing happened. And here's the subtle part - a resolver that quietly stops checking looks, from outside, identical to one that checked and confirmed everything's fine. EDE code 33 puts a machine-readable label on the workaround: 'I skipped the check here', written right into the answer itself. .AL is still effectively unsigned today, so the fix is a temporary compromise - it buys access while the domain gets fixed.

A resolver that quietly stops checking looks exactly like one that checked.

The lesson goes beyond DNS. A system that admits when it's dropped its guard is safer than one that looks clean and has simply stopped watching. If you're building something that guards - a firewall, an auth layer, whatever - the question isn't just whether it works, it's whether it tells you when it stops working the way it should. A transparent bypass beats a silent failure every time.

The visual is generated code art. No third-party images.
Follow usFacebookLinkedIn
Official primary sources
→Cloudflare - Broken DNSSEC in .AL and EDE code 33, 14.07.2026
Original: https://wearecoded.com/en/articles/cloudflare-dnssec-al-ede-33.html
ShareFacebookXLinkedInTelegramWhatsApp
← Back to all news