Skip to content

DNS issues for diff.rs domain (caused by expired DNSSEC keys?)

It looks like neither Google DNS nor Cloudflare resolve diff.rs correctly any longer, both return no results.

From what I can tell, this is caused by an expired DNSSEC key (from dig output):

$ dig diff.rs @1.0.0.1

...

;; OPT PSEUDOSECTION:
; EDNS: version: 0, flags:; udp: 1232
; EDE: 7 (Signature Expired): (for DNSKEY diff.rs., id = 25689: RRSIG diff.rs., expiration = 1747872000)
;; QUESTION SECTION:
;diff.rs.			IN	A