appliedbits
FIELD NOTES PUBLISHED
PUBLISHED 2026-10-02

The case for watching DNSSEC between outages instead of after them

CircleID  ·  Muhammad Shahzaib  ·  source ↗

Muhammad Shahzaib argues in CircleID that DNSSEC failures get diagnosed from point-in-time snapshots, and that the same handful of failure modes keep recurring because nothing records how the signed namespace changes between incidents. “A snapshot shows what is broken.” He discloses that his team is building the archive he is arguing for, AUDNSXplore, as an ICANN Grant Program project.

The incidents carry the argument. DENIC’s scheduled .de key rollover on 5 May 2026 published signatures that did not validate; over roughly three hours, as caches expired, a growing share of .de went unreachable to validating resolvers, and Cloudflare disabled validation for .de on its public resolver. .nz ran about thirteen hours in May 2023 after a rollover used the old timing when the DS TTL had changed from one hour to one day — InternetNZ’s registry system, in production since November 2022, could not set an explicit DS TTL. The ianix outage list goes back to 2009 and runs to several hundred entries.

The measurement gap is specific. OpenINTEL has queried every name in the gTLD zone files daily since 2015, more than 216 million domains a day, and records responses without validating them. DNSViz validates and archives back to 2011, for roughly 100,000 user-requested names. Chung et al. found 28 to 32 percent of signed .com, .net and .org domains had no DS record in the parent — one hosting provider published DNSKEY records for more than 131,000 domains with a DS record for one of them. KSK-2024 begins signing the root zone key set on 11 October 2026 against a 48-hour root DNSKEY TTL, so resolvers still trusting only the old key fail at staggered times across the following two days.

The coverage limit is the one worth carrying forward. ICANN’s CZDS supplies a daily list of every delegated gTLD name as a crawl seed; ccTLDs carry no equivalent obligation and mostly publish nothing. The largest DNSSEC outages of the last three years were all ccTLDs. Shahzaib made the same zone-file argument for abuse detection a week earlier, and the same gap bounds both.

Tagsdnssecdnsmeasurementczds