Fixed - Post-mortem: this was a DNS flood attack which targeted all 9 of our regional name servers. The attack originated from several cloud provider subnets, including Google and Cloudflare.
To mitigate the attack we had to temporarily block the provider subnets. This had some unintended and undesirable side effects:
The block was lifted over 24 hours ago and there have been no further issues since that time.
Going forward, we’ll refine our mitigation techniques to avoid blocking major providers when possible. We’ll also move this status page to an externally-hosted domain to ensure that system status updates will be available regardless of the state of our infrastructure. (16:40 UTC — Dec 30)
Fixed - We’ve seen no further issues in the past several hours and consider this to be resolved. (21:18 UTC — Dec 29)
Watching - The attack has subsided, we’ll continue to monitor. (14:27 UTC — Dec 29)
Over the last few hours we’ve identified and mitigated an ongoing DDOS attack against our DNS infrastructure. This attack has also effected our Singapore and German DNS servers.
We’re continuing to monitor the attack. (12:00 UTC — Dec 29)