Home / News
DNS news
DNSSEC rollovers, resolver outages, encrypted DNS standards and public resolver performance — the changes that actually affect how you configure a network.
-
SecurityVulnerabilitiesAugust 4, 2026
Cybersecurity News: SonicWall VPN Flaws Fuel INC Attacks
INC Ransomware is chaining two SonicWall SMA 1000 zero-days to steal credentials, session databases and TOTP MFA seeds from internet-facing VPN gateways. Technical breakdown and response checklist.
Read more → -
ResolversPerformanceAugust 3, 2026
329 queries to resolve one name: what a cold resolver cache actually costs
At IETF 126 in Vienna, ISC's Ondřej Surý showed a BIND resolver taking 329 queries to resolve a single IPv6 reverse-DNS name from a cold cache. The number is a useful reminder that DNS is fast because of caching, not because resolution is cheap — and that the shape of your zone matters as much as the resolver you pick.
Read more → -
DNSSECEncrypted DNSAugust 3, 2026
Post-quantum DNSSEC: a 23KB DNSKEY, a ten-minute key roll, and a good argument for doing nothing yet
A side meeting at IETF 126 produced three concrete post-quantum DNSSEC experiments, including a DNSKEY response of 23,843 bytes and a KSK rolled every ten minutes. The interesting conclusion is that DNS keys do not need post-quantum algorithms nearly as urgently as transport-layer encryption does — and that shorter key lifetimes are the cheaper fix today.
Read more → -
SecurityAbuseAugust 3, 2026
Infoblox says 22% of new domains are hostile — and the best tricks are DNS tricks
Infoblox's 2026 Threat Landscape Report counts 120 million newly registered domains in a year, of which more than 22% show threat characteristics. The techniques it documents — dangling CNAMEs, .arpa abuse, traffic distribution systems — are all designed specifically to beat the reputation systems your filtering resolver runs on.
Read more → -
StandardsIETFJuly 31, 2026
"Optimistic DNS is evil": IETF 126 reopens the fight over serving stale answers fast
At IETF 126 in Vienna, the DNSOP working group revisited Optimistic DNS — serving an expired cache entry immediately while refreshing it in the background. It is a real latency win and a real erosion of the TTL contract, and nobody has proposed a limit on how stale is too stale.
Read more → -
DNSSECICANNJuly 29, 2026
The root zone KSK rollover lands on 11 October — here is what actually breaks
On 11 October 2026 ICANN switches the root zone to KSK-2024. Resolvers that never picked up the new trust anchor will start returning SERVFAIL for everything. Here is who is exposed and how to check.
Read more → -
DNSSECCloudflareJuly 15, 2026
After .AL went dark, 1.1.1.1 now admits when it has switched DNSSEC off
A botched key rollover took Albania's .AL TLD offline on 3 July. Cloudflare's fix — a Negative Trust Anchor — has always been invisible to users. This time 1.1.1.1 returned a brand new error code saying so.
Read more → -
IndustryDDIJuly 9, 2026
Infoblox buys Kentik, betting that DNS data is really network observability data
Infoblox has acquired network observability vendor Kentik, folding flow and telemetry analysis into its DNS, DHCP and IP address management platform.
Read more → -
PrivacyPolicyJuly 2, 2026
DNS4EU one year on: Europe's sovereign resolver looks for a business model
Launched in June 2025 to reduce Europe's dependence on American resolvers, DNS4EU has passed its first birthday. Adoption is voluntary, and the EU funding that built it was never meant to run forever.
Read more → -
DNSSECOutagesMay 7, 2026
When Germany's TLD broke: the .DE DNSSEC outage and what "serve stale" saved
On 5 May 2026, DENIC published broken DNSSEC signatures for .DE, putting millions of German domains at risk of vanishing. Cached records and a Negative Trust Anchor absorbed most of the damage.
Read more → -
OutagesCloudflareJanuary 12, 2026
A standards-compliant DNS change put Cisco routers into reboot loops
Cloudflare changed the order of CNAME and non-CNAME records in cached responses. The change broke nothing in the spec — and knocked Cisco devices worldwide into fatal reboot loops.
Read more →
Reporting here is compiled from operator advisories, IETF proceedings, registry and vendor disclosures, and published research — each linked at the foot of the article. Resolver behaviour and rollover schedules change; confirm against the relevant operator before acting on anything here. Measurements referenced in these articles can be reproduced with our free browser-based DNS benchmark. See our terms and disclaimer.