DNSSEC validation failures during our move off Cloudflare
Our DNS migration caused intermittent DNSSEC validation failures for onetimesecret.com; custom domains on onetime.co were unaffected.
- Some DNSSEC-validating resolvers could not resolve onetimesecret.com and its subdomains intermittently from about 19–26 August
- Custom domains route through onetime.co, which never used Cloudflare, and were unaffected
- Mitigation is in place: Bunny's ZSK was added to Cloudflare's DNSKEY set, stale Hetzner records were removed, and the Cloudflare zone was deleted
- Cloudflare nameserver and DS removal from the parent delegation remains pending; recovery will be verified from independent validating resolvers
- A temporary DNS probe now monitors DNSSEC validation and hostname resolution while we work on a more robust solution