Close Menu
    Facebook LinkedIn YouTube Instagram X (Twitter)
    Blue Tech Wave Media
    Facebook LinkedIn YouTube Instagram X (Twitter)
    • Home
    • Leadership Alliance
    • Exclusives
    • Internet Governance
      • Regulation
      • Governance Bodies
      • Emerging Tech
    • IT Infrastructure
      • Networking
      • Cloud
      • Data Centres
    • Company Stories
      • Profiles
      • Startups
      • Tech Titans
      • Partner Content
    • Others
      • Fintech
        • Blockchain
        • Payments
        • Regulation
      • Tech Trends
        • AI
        • AR/VR
        • IoT
      • Video / Podcast
    Blue Tech Wave Media
    Home » Expired DNSSEC signatures disrupt 26 African TLDs
    Expired-DNSSEC-signatures-disrupt-26-African-TLDs
    Expired-DNSSEC-signatures-disrupt-26-African-TLDs
    Governance Bodies

    Expired DNSSEC signatures disrupt 26 African TLDs

    By Vionna Fiducia ThejaDecember 2, 2024No Comments3 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email
    • A technical glitch in one of Afrinic’s authoritative name servers caused expired DNSSEC signatures, disrupting 26 African TLDs, including Madagascar’s .mg. The issue was first reported on 8 November, although it began on 29 October 2024.
    • RIPE Atlas probes revealed that only one instance of the anycasted server, identified as s01-ns2.pkl, was serving outdated data. Afrinic took the server offline to resolve the issue, highlighting challenges with monitoring anycast systems.

    What happened

    At the end of October 2024, a significant technical issue disrupted 26 African Top-Level Domains (TLDs). One of their authoritative name servers, managed by Afrinic, served outdated data, with DNSSEC (Domain Name System Security Extensions) signatures flagged as expired. This issue was first noticed on 8 November, despite originating on 29 October, causing inconsistent DNS resolution experiences for users of the TLD .mg (Madagascar).

    Also read: Supreme Court ruling on AFRINIC: New members no rights, elections by June 2025
    Also read: Exploring global spectrum management at WRS-24

    A deeper analysis revealed that not all servers were affected. Instead, one specific instance of the anycasted name server ns-mg.afrinic.net was running outdated data. Measurements from RIPE Atlas probes showed a clear discrepancy: while most servers reported up-to-date data, a minority still relied on stale information. This server instance, identified by the NSID s01-ns2.pkl, contributed to delays in propagating updates across multiple TLDs.

    Afrinic eventually resolved the issue by taking the problematic instance offline. However, the problem raised questions about monitoring and troubleshooting for distributed systems, especially those critical to internet infrastructure.

    Why this is important

    This incident highlights a key vulnerability in internet infrastructure: servers can appear operational while delivering outdated or incorrect data. For domains using DNSSEC, expired signatures expose users to potential risks, such as failing to resolve valid queries or encountering invalid data responses.

    The affected server hosted not only .mg but also 25 other African TLDs, amplifying the scale of the issue. Though Afrinic’s swift action mitigated further damage, the case underscores the need for robust monitoring systems that ensure both uptime and data accuracy.

    Moreover, this situation demonstrates the challenges of anycast—a widely used technique that boosts DNS resilience by routing requests to geographically distributed instances. While anycast strengthens DNS robustness, it also complicates problem detection and debugging, as was evident here. Tools like RIPE Atlas prove invaluable for identifying such anomalies, but as this case shows, proactive checks for data freshness remain essential for ensuring seamless DNS operations.

    Afrinic
    Vionna Fiducia Theja

    Vionna Fiducia Theja is a passionate journalist with a First Class Honours degree in Media and Communication from the University of Liverpool. A storyteller at heart, she delves into the vibrant worlds of technology, art, and entertainment, where creativity meets innovation. Vionna believes in the power of media to transform lives and spark conversations that matter. Connect with her at v.zheng@btw.media.

    Related Posts

    AFRINIC designated a ‘declared company’ by Prime Minister of Mauritius

    July 19, 2025

    Did ICANN’s lawyer illegally visit AFRINIC when the Official Receiver was away?

    July 19, 2025

    From regional registry to receivership: What AFRINIC’s collapse means for Africa’s internet development

    July 18, 2025
    Add A Comment
    Leave A Reply Cancel Reply

    CATEGORIES
    Archives
    • July 2025
    • June 2025
    • May 2025
    • April 2025
    • March 2025
    • February 2025
    • January 2025
    • December 2024
    • November 2024
    • October 2024
    • September 2024
    • August 2024
    • July 2024
    • June 2024
    • May 2024
    • April 2024
    • March 2024
    • February 2024
    • January 2024
    • December 2023
    • November 2023
    • October 2023
    • September 2023
    • August 2023
    • July 2023

    Blue Tech Wave (BTW.Media) is a future-facing tech media brand delivering sharp insights, trendspotting, and bold storytelling across digital, social, and video. We translate complexity into clarity—so you’re always ahead of the curve.

    BTW
    • About BTW
    • Contact Us
    • Join Our Team
    TERMS
    • Privacy Policy
    • Cookie Policy
    • Terms of Use
    Facebook X (Twitter) Instagram YouTube LinkedIn

    Type above and press Enter to search. Press Esc to cancel.