A Broken DNSSEC Rollover Took Down .al. Now 1.1.1.1 Tells You When Validation Is Bypassed
Cloudflare, Tuesday, July 14th, 2026
Cloudflare's 1.1.1.1 now returns EDE 33 to signal when a Negative Trust Anchor bypassed DNSSEC validation.
On 3 July 2026 Albania's .al TLD went dark after its communications authority AKEP botched a DNSSEC key rollover, breaking the chain of trust and causing validating resolvers such as 1.1.1.1 to return SERVFAIL for every .al query.
Cloudflare restored resolution by deploying a Negative Trust Anchor, which temporarily suspends DNSSEC validation for the affected zone.
That fix created a transparency gap, because clients could not tell a validated answer from an unvalidated one.
For the first time, 1.1.1.1 now returns Extended DNS Error code 33 to signal directly in the response that an NTA has been applied. Cloudflare co-authored an Internet-Draft proposing the standard and hopes other resolver implementations adopt it.