Outage impacted all DNSSEC-signed domains.

Germany’s .de top-level domain experienced a disruption this evening that affected accessibility for a subset of domains. DENIC, the registry responsible for managing .de, confirmed that the incident impacted all domains using DNSSEC signatures, causing validation failures and access errors for users attempting to reach those sites.
The problem was identified and resolved within a few hours, and DENIC reports that affected domains should now be reachable again. The registry initially began an investigation to determine the root cause, and later clarified that the outage occurred during a scheduled DNSSEC key rollover. During that process, non-validatable signatures were generated and distributed, which led to validation failures by resolvers enforcing DNSSEC.
DNSSEC (Domain Name System Security Extensions) is designed to provide an additional layer of trust in the DNS by allowing resolvers to verify that DNS responses come from an authentic source and have not been tampered with. When DNSSEC signatures are valid, clients can trust that the IP addresses they receive are correct. When signatures are invalid or cannot be validated, resolvers that strictly enforce DNSSEC will treat responses as suspect or refuse to resolve the name, which is what occurred in this incident.
Incidents related to DNSSEC rollovers and signature validation have occurred elsewhere in the past, and coordination and careful testing are essential to prevent disruptions. Registries and operators must ensure that key rollovers are performed in a way that guarantees continuous availability of valid signatures for all published records.
The .de namespace is one of the largest country-code top-level domains globally, with 17.9 million registrations reported at the end of Q1 2026, making it the second-largest after China’s .cn. Given the size of the namespace, any operational issue affecting DNSSEC can have wide-reaching effects on end users and services that rely on DNS for connectivity.
DENIC has indicated that it will continue reviewing its procedures and the rollover process to prevent similar incidents in the future. Operators, registrars, and administrators running DNSSEC-signed zones are advised to monitor their services and verify that signatures and key material are correctly published and propagated after rollovers or any maintenance that touches DNSSEC-related data.