Live data from Hacker News

Ask HN: Cloudflare broke my domain's DNSSEC making it unreachable since 4 days

news.ycombinator.com

1–10 of 123 posts

Ask HN: Cloudflare broke my domain's DNSSEC making it unreachable since 4 days

#1
tl;dr - Cloudflare rendered my domain inaccessible and support has been ignoring the ticket for 4 days, what's the fastest way to get technical assistance when on a free plan?

Last week I transferred a domain used for a personal project from my old registrar to Cloudflare. After the transfer was finalized and new NS records had propagated, everything resolved normally and everything was working fine. I then enabled DNSSEC, and after a while the domain would no longer resolve. Every DNS server I try - Google, Quad9, OpenDNS, even Cloudflare's own DNS on 1.1.1.1 - returns SERVFAIL. The excellent diagnostic tool on dnsviz.net tells me that the domain is returning bogus DNSKEY/DS/NSEC responses and bogus delegation status. "no SEP matching the DS found".

I tried canceling the DNSSEC setup and waiting for over a day, with no effect. I re-enabled DNSSEC setup and waited for 3 days, with no effect. Cloudflare's control panel has since several days now been saying that DNSSEC will be enabled "in the next 24 hours". My site cannot be reached, and Cloudflare's support cannot be reached.

I've been forced to migrate the project and its (few) users to a completely different domain. I cannot inconvenience users by bouncing them back and forth, so the domain Cloudflare ruined for me is now effectively lost, as is the "branding" of the project which was reflected in the domain's name.

How can I get their attention without paying for an Enterprise plan? I would like to think that basic functional service should be accessible even when using Cloudflare only as a registrar with fundamental DNS on a free plan.

Re: Ask HN: Cloudflare broke my domain's DNSSEC making it unreachable since 4 days

#2
> what's the fastest way to get technical assistance when on a free plan?

Upgrading to a non-free plan?

You don't have to upgrade to enterprise, but even their $20/mo plan comes with support.

(Also, I hate to victim-blame here but using DNSSEC was a bad idea in the first place)

Re: Ask HN: Cloudflare broke my domain's DNSSEC making it unreachable since 4 days

#4

> what's the fastest way to get technical assistance when on a free plan? Upgrading to a non-free plan? You don't have to upgrade to enterprise, but even their $20/mo plan comes with support. (Also, I hate to victim-blame here but using DNSSEC was a bad idea in the first place)

Why was enabling DNSSEC a bad idea? Clearly the origin registrar isn't handling DNSSEC requests properly, but the OP should still be able to revert to non-DNSSEC without issues.

Re: Ask HN: Cloudflare broke my domain's DNSSEC making it unreachable since 4 days

#6

> what's the fastest way to get technical assistance when on a free plan? Upgrading to a non-free plan? You don't have to upgrade to enterprise, but even their $20/mo plan comes with support. (Also, I hate to victim-blame here but using DNSSEC was a bad idea in the first place)

Can you please explain why DNSSEC was a bad idea in the first place? It worked perfectly fine with the old registrar.

Re: Ask HN: Cloudflare broke my domain's DNSSEC making it unreachable since 4 days

#8

> what's the fastest way to get technical assistance when on a free plan? Upgrading to a non-free plan? You don't have to upgrade to enterprise, but even their $20/mo plan comes with support. (Also, I hate to victim-blame here but using DNSSEC was a bad idea in the first place)

[deleted]

Re: Ask HN: Cloudflare broke my domain's DNSSEC making it unreachable since 4 days

#10
post #7
post #5

Does your TLD definitely support DNSSEC?

Yes. It had DNSSEC enabled for over a year when it was with the old registrar.

You would usually need to disable DNSSEC, wait 24h, transfer, and then wait for at least 24h before enabling DNSSEC again.
Post reply on HN