Faulty DNSSEC signatures caused an outage for .de domains
On Tuesday evening, invalid DNSSEC signatures were propagated for the German top-level domain zone .de. Because DNSSEC requires servers to reject responses whose signatures cannot be verified, a range of domains under .de became unreachable. Denic, which manages .de, distributed correct zone files from 00:08 on 6 May, and availability was fully restored roughly an hour later. The root cause is not fully established, but Denic links it to a routine, scheduled key rollover.
What this means for your organisation
The incident is about availability rather than attack, and that is precisely the point. DNS is one of the few places where a single configuration error can take everything down at once, however well your applications are otherwise protected. If you have customers, integrations or email depending on a domain under a top-level domain you do not control, you carry a risk you cannot steer. Your contingency planning has to cover it.
Berigo recommends
- Add DNS failure to the incident response plan as its own scenario, including who notifies customers and how.
- Verify that you use independent name servers and that TTL values are set deliberately.
- Monitor lookups against your own domains from the outside, not just the availability of the servers themselves.
- Keep an alternative channel for reaching customers and staff when website and email are down at the same time.
Source
Security that is understood, governed and works.
Let us help you turn security into an advantage, not a cost. Get in touch for a no-obligation conversation about where your organisation stands and what to prioritise first.
Get in touch