[metadata]
algolia_content_type: Reference
algolia_product_filter: 1.1.1.1 (DNS Resolver)
description: Extended DNS error codes returned by 1.1.1.1.
generator: Astro v7.2.0
generator: Nimbus v0.2.2
image: https://developers.cloudflare.com/og-docs.png
og:description: Extended DNS error codes returned by 1.1.1.1.
og:image: https://developers.cloudflare.com/og-docs.png
og:locale: en
og:site_name: Cloudflare Docs
og:title: Extended DNS error codes
og:title: Extended DNS error codes · Cloudflare 1.1.1.1 docs
og:type: article
og:url: https://developers.cloudflare.com/1.1.1.1/infrastructure/extended-dns-error-codes/
pcx_additional_products: 1.1.1.1
pcx_content_group: Consumer services
pcx_content_type: Reference
pcx_last_modified: 6
pcx_product: 1.1.1.1 (DNS Resolver)
pcx_tags: Debugging
twitter:card: summary_large_image
twitter:image: https://developers.cloudflare.com/og-docs.png
twitter:site: @cloudflare
viewport: width=device-width, initial-scale=1

[canonical-links]
https://developers.cloudflare.com/1.1.1.1/infrastructure/extended-dns-error-codes/

[document-links]
/
1.1.1.1 (DNS Resolver): /1.1.1.1/
1.1.1.1 Public DNS Resolver: /1.1.1.1/privacy/public-dns-resolver/
1.1.1.1 llms-full.txt ↗: /1.1.1.1/llms-full.txt
1.1.1.1 llms.txt ↗: /1.1.1.1/llms.txt
AI Security: https://www.cloudflare.com/solutions/ai-security/
API: /api/
About DoH: /1.1.1.1/encryption/dns-over-https/
About: https://www.cloudflare.com/about/
Agent setup ↗: /agent-setup/
Agent setup: /agent-setup/
Android: /1.1.1.1/setup/android/
App innovation report: https://www.cloudflare.com/resource/app-innovation-report/
Athenian Project: https://www.cloudflare.com/athenian/
Azure: /1.1.1.1/setup/azure/
Blog: https://blog.cloudflare.com/
Careers: https://www.cloudflare.com/careers/
Case studies: https://www.cloudflare.com/case-studies/
Changelog: /1.1.1.1/changelog/
Changelog: /changelog/
Cloudflare AI Cloud: https://www.cloudflare.com/solutions/ai/
Cloudflare Docs llms-full.txt ↗: /llms-full.txt
Cloudflare Docs llms.txt ↗: /llms.txt
Cloudflare Radar: https://radar.cloudflare.com/
Cloudflare Resolver for Firefox: /1.1.1.1/privacy/cloudflare-resolver-firefox/
Cloudflare Skills ↗: https://github.com/cloudflare/skills
Cloudflare for Campaigns: https://www.cloudflare.com/campaigns/
Cloudflare status page: https://www.cloudflarestatus.com/
Code Mode MCP Server ↗: https://github.com/cloudflare/mcp
Community: https://community.cloudflare.com/
Compliance resources: https://www.cloudflare.com/trust-hub/compliance-resources/
Configure DoH on your browser: /1.1.1.1/encryption/dns-over-https/encrypted-dns-browsers/
Connect to 1.1.1.1 using DoH clients: /1.1.1.1/encryption/dns-over-https/dns-over-https-client/
Contact sales: https://www.cloudflare.com/resource/contact-enterprise-sales/
DNS Wireformat: /1.1.1.1/encryption/dns-over-https/make-api-requests/dns-wireformat/
DNS configuration: /dns/
DNS in Google Sheets: /1.1.1.1/additional-options/dns-in-google-sheets/
DNS over Discord: /1.1.1.1/additional-options/dns-over-discord/
DNS over TLS: /1.1.1.1/encryption/dns-over-tls/
DNS over Tor: /1.1.1.1/additional-options/dns-over-tor/
DNSKEY: /1.1.1.1/encryption/dnskey/
DNSSEC configuration: /dns/dnssec/
DNSSEC signatures: /dns/dnssec/troubleshooting/
Data Protection: https://www.cloudflare.com/trust-hub/gdpr/
Directory: /directory/
Docs: /
Documentation: https://developers.cloudflare.com/
Domain name search: https://domains.cloudflare.com/
Domain-specific MCP Servers ↗ MCP: https://github.com/cloudflare/mcp-server-cloudflare
Edit page: https://github.com/cloudflare/cloudflare-docs/edit/production/src/content/docs/1.1.1.1/infrastructure/extended-dns-error-codes.mdx
Events: https://www.cloudflare.com/events/
Extended DNS Error Codes ↗: https://www.rfc-editor.org/rfc/rfc8914.html
Extended DNS error codes: /1.1.1.1/infrastructure/extended-dns-error-codes/
FAQ: /1.1.1.1/faq/
Find a partner: https://partnerlocator.cloudflare.com/dashboard
Frontend Development Platform: https://www.cloudflare.com/solutions/frontends/
Gaming consoles: /1.1.1.1/setup/gaming-consoles/
General: /1.1.1.1/setup/
Global network: https://www.cloudflare.com/network/
Google Cloud: /1.1.1.1/setup/google-cloud/
Home: /
IP addresses: /1.1.1.1/ip-addresses/
Impact/ESG: https://www.cloudflare.com/impact/
Investors: https://cloudflare.net/
Learning center: https://www.cloudflare.com/learning/
Linux: /1.1.1.1/setup/linux/
Log In: https://dash.cloudflare.com/login
Log in Dashboard: https://dash.cloudflare.com/
Multi-Tenant Platform Development: https://www.cloudflare.com/solutions/platforms/
NSEC/NSEC3 records: https://www.cloudflare.com/dns/dnssec/dnssec-complexities-and-considerations/
Negative Trust Anchor: https://www.rfc-editor.org/rfc/rfc7646
Network operators: /1.1.1.1/infrastructure/network-operators/
Next SLA and support: /1.1.1.1/infrastructure/sla-and-support/
Oblivious DoH: /1.1.1.1/encryption/oblivious-dns-over-https/
Overview: /1.1.1.1
Overview: /1.1.1.1/encryption/
Overview: /1.1.1.1/encryption/dns-over-https/make-api-requests/
Overview: /1.1.1.1/privacy/
Partners: https://www.cloudflare.com/partners/
Plans: https://www.cloudflare.com/plans/
Press kit: https://www.cloudflare.com/press/press-kit/
Press: https://www.cloudflare.com/press/
Previous Support for IPv6-only networks: /1.1.1.1/infrastructure/ipv6-networks/
Privacy policy: https://www.cloudflare.com/policies/privacy/
Project Fairshot: https://www.cloudflare.com/fair-shot/
Project Galileo: https://www.cloudflare.com/galileo/
Report abuse: https://www.cloudflare.com/trust-hub/abuse-approach/
Report issue: https://github.com/cloudflare/cloudflare-docs/issues/new/choose
Report security issues: https://www.cloudflare.com/disclosure/
Responsible AI: https://www.cloudflare.com/trust-hub/responsible-ai/
Router: /1.1.1.1/setup/router/
SDKs: /fundamentals/api/reference/sdks/
SLA and support: /1.1.1.1/infrastructure/sla-and-support/
SSE and SASE platform: https://www.cloudflare.com/sase/
Start Building: https://dash.cloudflare.com/sign-up
Startups: https://www.cloudflare.com/startups/
Status: https://www.cloudflarestatus.com/
Support for IPv6-only networks: /1.1.1.1/infrastructure/ipv6-networks/
Support: https://support.cloudflare.com/
Terms of use: /1.1.1.1/terms-of-use/
Terms of use: https://www.cloudflare.com/policies/terms/
Trademark: https://www.cloudflare.com/trademark/
Transparency report: https://www.cloudflare.com/transparency/
Troubleshooting: /1.1.1.1/troubleshooting/
Trust Hub: https://www.cloudflare.com/trust-hub/
Under attack?: https://www.cloudflare.com/under-attack-hotline/
Upstream resolution: /1.1.1.1/upstream-resolution/
Using JSON: /1.1.1.1/encryption/dns-over-https/make-api-requests/dns-json/
Verify connection: /1.1.1.1/check/
View as Markdown: index.md
Web Security Platform: https://www.cloudflare.com/solutions/security/
Windows: /1.1.1.1/setup/windows/
add a supported DS record: /dns/dnssec/
add the missing DS records: /dns/dnssec/
blog post on EDE 33: https://blog.cloudflare.com/dnssec-nta-ede-33/
community forum: https://community.cloudflare.com/c/reliability/dns-1111/47
https://github.com/cloudflare/cloudflare-docs
iOS: /1.1.1.1/setup/ios/
macOS: /1.1.1.1/setup/macos/
set a Zone Key flag: https://datatracker.ietf.org/doc/html/rfc4035#section-5.3.1
signature key algorithm: /1.1.1.1/encryption/dnskey/
signed with DNSSEC: /dns/dnssec/troubleshooting/
troubleshooting guide: /dns/dnssec/troubleshooting/

[structured-data]
{"@context":"https://schema.org","@id":"https://developers.cloudflare.com/1.1.1.1/infrastructure/extended-dns-error-codes/#page","@type":"TechArticle","dateModified":"2026-08-14","description":"Extended DNS error codes returned by 1.1.1.1.","headline":"Extended DNS error codes · Cloudflare 1.1.1.1 docs","image":"https://developers.cloudflare.com/og-docs.png","inLanguage":"en","isPartOf":{"@id":"https://developers.cloudflare.com/#website","@type":"WebSite","name":"Cloudflare Docs","url":"https://developers.cloudflare.com/"},"keywords":["Debugging"],"publisher":{"@type":"Organization","name":"Cloudflare","url":"https://www.cloudflare.com/"},"url":"https://developers.cloudflare.com/1.1.1.1/infrastructure/extended-dns-error-codes/"}

[content]
Extended DNS error codes · Cloudflare 1.1.1.1 docs
Skip to content
Documentation Index
Fetch the complete documentation index at: https://developers.cloudflare.com/1.1.1.1/llms.txt
Use this file to discover all available pages before exploring further.
Docs
Directory
API
SDKs
Changelog
Search
Ctrl
K
Log in
Dashboard
1.1.1.1 (DNS Resolver)
/
Overview
IP addresses
Set up
General
Android
Azure
Gaming consoles
Google Cloud
iOS
Linux
macOS
Router
Windows
Encryption
Overview
DNS over TLS
DNS over HTTPS
About DoH
Make API requests to 1.1.1.1
Overview
DNS Wireformat
Using JSON
Configure DoH on your browser
Connect to 1.1.1.1 using DoH clients
Oblivious DoH
DNSKEY
Upstream resolution
Infrastructure
Network operators
Support for IPv6-only networks
Extended DNS error codes
SLA and support
Other ways to use 1.1.1.1
DNS in Google Sheets
DNS over Discord
DNS over Tor
Privacy
Overview
1.1.1.1 Public DNS Resolver
Cloudflare Resolver for Firefox
Verify connection
Troubleshooting
Terms of use
FAQ
Changelog
Agent resources
Agent setup ↗
Cloudflare Skills ↗
Code Mode MCP Server ↗
Domain-specific MCP Servers ↗
MCP
1.1.1.1 llms.txt ↗
1.1.1.1 llms-full.txt ↗
Cloudflare Docs llms.txt ↗
Cloudflare Docs llms-full.txt ↗
Home
/
1.1.1.1 (DNS Resolver)
/
Infrastructure
/
Extended DNS error codes
Extended DNS error codes
Last updated
Aug 14, 2026
|
Copy as Markdown
|
View as Markdown
|
Agent setup
Extended DNS Error Codes
↗
(defined in RFC 8914) is a method to return additional information about the cause of DNS errors. When a DNS query fails, the standard response code (such as
SERVFAIL
) often does not explain
why
it failed. Extended DNS Error Codes solve this by attaching a more specific error code and descriptive text to the response, so you can identify the exact cause without guesswork.
1.1.1.1 supports Extended DNS Error Codes. Below is a list of error codes 1.1.1.1 returns, what they mean, and steps you may want to take to resolve the issue. Many of these errors relate to DNSSEC (DNS Security Extensions) — the set of protocols that add cryptographic signatures to DNS records to prevent tampering. Extended DNS Error Codes appear automatically in the
OPT PSEUDOSECTION
of a
dig
response when the server includes them, for example:
dig
@1.1.1.1
example.com
A
Code number
Code name
Example output
Next steps
1
Unsupported DNSKEY Algorithm
EDE: 1 (Unsupported DNSKEY Algorithm): (failed to verify example.com. A: unsupported key size, DNSKEY example.com., id = 12345)
The domain did not pass DNSSEC validation. Check which
signature key algorithm
your website uses and confirm it is supported by 1.1.1.1.
2
Unsupported DS Digest Type
EDE: 2 (Unsupported DS Digest Type): (no supported DS digest type for example.com.)
The domain did not pass DNSSEC validation due to an unsupported digest type on the DS record. If none of the provided DS records are supported, the domain will fail to resolve. Make sure to
add a supported DS record
with your registrar.
3
Stale Answer
EDE: 3 (Stale Answer)
This is a silent error. It notifies that the DNS resolver could only return stale data. If the issue persists reach out on the 1.1.1.1
community forum
.
6
DNSSEC Bogus
EDE: 6 (DNSSEC Bogus): (proof of non-existence of example.com. A)
EDE: 6 (DNSSEC Bogus): (found duplicate CNAME records for example.com. (1 duplicate RRs))
This domain did not pass DNSSEC validation. The signatures for the target record, or the proof of non-existence of the target records, are invalid. Check your
DNS configuration
.
7
Signature Expired
EDE: 7 (Signature Expired): (for DNSKEY example.com., id = 12345: RRSIG example.com., expiration = 123456)
This domain did not pass DNSSEC validation due to an expired signature. Make sure your zone is signed with valid
DNSSEC signatures
.
8
Signature Not Yet Valid
EDE: 8 (Signature Not Yet Valid): (for DNSKEY example.com., id = 12345: RRSIG example.com., inception = 12345)
This domain did not pass DNSSEC validation. Make sure your zone is signed with valid
DNSSEC signatures
.
9
DNSKEY Missing
EDE: 9 (DNSKEY Missing): (no SEP matching the DS found for example.com.)
This domain did not pass DNSSEC validation. It does not have a SEP DNSKEY that matches the set of DS records at the registry. Make sure to either sign the zone using keys that match the current DS set, or
add the missing DS records
with your registrar.
10
RRSIGs Missing
EDE: 10 (RRSIGs Missing): (for DNSKEY example.com., id = 12345)
1.1.1.1 was unable to retrieve Resource Record Signatures (RRSigs) to verify the authenticity of the records. Check your
DNS configuration
and the response code. If the response code is not
SERVFAIL
, this error indicates that there is a non-operational key issue somewhere along the path, but the resolver found at least one successful path for validation. Examples of non-operational key issues include but are not limited to key rollover in-progress, stand-by key, and attacker stripping signatures made by a certain key.
11
No Zone Key Bit Set
EDE: 11 (No Zone Key Bit Set): (for DNSKEY example.com., id = 12345)
This domain did not pass DNSSEC validation. The zone's SEP DNSKEY must
set a Zone Key flag
. Check your
DNSSEC configuration
or DNSSEC's
troubleshooting guide
.
12
NSEC Missing
EDE: 12 (NSEC Missing): failed to verify an insecure referral proof for example.com
This domain did not pass DNSSEC validation. The upstream nameserver did not include a valid proof of non-existence for the target name. Make sure the zone is
signed with DNSSEC
and has valid
NSEC/NSEC3 records
.
13
Cached Error
EDE: 13 (Cached Error)
1.1.1.1 returned a cached error. If this issue persists, reach out to the
community forum
.
22
No Reachable Authority
EDE: 22 (No Reachable Authority): (at delegation example.com.)
1.1.1.1 could not reach some or all of the authoritative nameservers (or they potentially refused to resolve). This can occur if the authoritative nameservers are overloaded or temporarily unavailable. If this issue persists, reach out to the
community forum
.
23
Network Error
EDE: 23 (Network Error): (1.1.1.1:53 rcode=SERVFAIL for example.com. A)
1.1.1.1 could not determine a network path to the upstream nameservers, or the nameserver did not respond. If this issue persists, reach out to the
community forum
.
30
Invalid Query Type
EDE: 30 (Invalid Query Type): Invalid Query Type
The record type in the request cannot give a valid answer. If this is returned for standard query types, such as A or AAAA records, please reach out to the
community forum
.
33
Negative Trust Anchor
EDE: 33 (Negative Trust Anchor): (a Negative Trust Anchor has been applied for this query (see RFC 7646))
A
Negative Trust Anchor
was applied to this query, bypassing DNSSEC validation. Check the
Cloudflare status page
for any details, and read our
blog post on EDE 33
for more information.
Previous
Support for IPv6-only networks
Next
SLA and support
Was this helpful?
Yes
No
Edit page
Report issue
On this page
Overview
Edit page
Report issue
Getting started
Plans
Contact sales
Partners
Find a partner
Startups
Under attack?
Domain name search
Company
About
Careers
Investors
Press
Press kit
Global network
Public interest
Project Galileo
Athenian Project
Cloudflare for Campaigns
Project Fairshot
Impact/ESG
Compliance
Compliance resources
Trust Hub
Data Protection
Responsible AI
Transparency report
Report abuse
Resources
App innovation report
Cloudflare Radar
Case studies
Status
Support
Events
Blog
Developers
Documentation
Learning center
Community
Solutions
SSE and SASE platform
Cloudflare AI Cloud
AI Security
Frontend Development Platform
Multi-Tenant Platform Development
Web Security Platform
Start Building
Log In
© 2026 Cloudflare, Inc.
Privacy policy
|
Report security issues
|
Terms of use
|
Trademark
|
Your privacy choices
Docs
