A broken DNSSEC rollover took down .AL. Now 1.1.1.1 tells you when validation is bypassed
Summary
Cloudflare explains a DNSSEC rollover failure on the Albanian TLD .AL, which caused validation to fail for resolvers. To maintain connectivity, 1.1.1.1 applied a Negative Trust Anchor, temporarily bypassing DNSSEC validation and returning Extended DNS Error codes to signal the bypass. The post discusses how NTAs work, the transparency gap they create, and the rollout of EDE codes to provide visibility to clients and operators.