0

airtable.com wrongly blocked by Threat Intelligence Feeds (false positive, business impact)

Hello,

Today (24 September 2026, morning CEST) our NextDNS profile started returning 0.0.0.0 for airtable.com and all of its subdomains (www, api, static, app). The block was attributed to the Threat Intelligence Feeds feature. No other setting on the profile targets this domain.

Impact: airtable.com is a core business tool for us. Our entire Windows fleet uses your resolver through the browser's DNS-over-HTTPS policy, so every employee lost access to Airtable at the same time, across several countries. We had to identify the cause ourselves and add airtable.com to the allowlist as an emergency workaround. Resolution recovered within minutes after that.

Airtable is a well-known, long-established SaaS vendor. A domain of this reputation should never be blocked outright by a curated threat feed without a reputation or popularity safeguard.

I would like NextDNS to:

  1. Confirm which feed flagged airtable.com, and when the entry was added and removed.
  2. Explain what safeguards exist to prevent top-ranked, established domains from being blocked by a single feed entry, and whether they failed here.
  3. Say whether a notification mechanism exists, or is planned, when a high-traffic domain on a customer's profile becomes blocked by a security feature. We had no signal other than users being unable to work.
  4. Confirm the false positive has been corrected upstream, so that customers who have not allowlisted airtable.com are no longer affected.

I can share the profile ID and the exact query timestamps privately if it helps your investigation.

Thank you for a prompt acknowledgement.

Reply

null

Content aside

  • yesterdayLast active
  • 9Views
  • 1 Following