Tell HN: Silent Netcup Domain Registrar DNSSEC Failure Netcup (a European registrar) has had issues with parts of their DNSSEC infrastructure, leading to many domains advertised DS records not matching Netcups DNSSEC keys. You can verify this by grabbing the DS records for one of the affected domains (pikz.cc):
and comparing it to the DNSSEC key:
Note how neither 51649 nor 37505 are the advertised DS of 33487.I noticed this issue on Saturday, and have contacted support three times. I received an "issue fixed, boss" on Monday, but issues have persisted. The worst part is that this only shows up on DNS servers implementing DNSSEC, which apparently my uptime monitor does not use, so I never got a warning except for a dip in traffic and a "domain unreachable" error in my browser. Google (8.8.8.8) and Cloudlflare (1.1.1.1) notably do enforce DNSSEC, so the pages are down when using their services. |