Expired at the registrar
When the delegation chain is cleanly cut at its root, every nameserver you run is beside the point.

The cut is higher than you think
A zone can be perfectly configured — DNSSEC signed, secondaries in sync, anycast-backed nameservers answering in milliseconds — and still resolve to nothing. The failure that causes total outage more often than any server misconfiguration is a domain registration that has lapsed. When the registrar drops the delegation, the parent zone stops publishing NS records for the name. From that moment, the referral chain is broken at its first step: a resolver asking the TLD nameservers gets no referral back, typically an NXDOMAIN, where a delegation used to be.
The mechanics are straightforward. A registrar communicates your NS set to the registry, which publishes it in the TLD zone. That publication is contingent on the registration remaining active. Most registries apply a grace period after expiry — a window of days to weeks during which the name is still technically held but may already be removed from the zone. ICANN's expired registration policy ↗ mandates minimum grace-period durations for gTLDs, but operators in a hurry have consistently discovered those windows are shorter than assumed.
Nothing at the authoritative layer signals this. The servers are running, the zone file is intact, the SOA serial is current. Every health check you have on the DNS infrastructure will pass, because the infrastructure is fine. The break is in the registry's copy of the parent zone, one level above anything you control. Resolvers that still have the old NS records cached will continue to answer until those TTLs drain — which can look like a partial or intermittent outage before becoming total, and which is exactly the period during which the problem is hardest to diagnose.

The fix is the same as the prevention: treat the registration renewal as infrastructure maintenance, not admin overhead. Many operators automate server provisioning, secondary configuration, and certificate renewal; domain registration renewal is the one dependency that usually sits outside that automation stack. Auto-renew on the registrar account is the minimum; a calendar alert independent of registrar email — which often lands in a filter — is worth adding. A monitoring check that queries the TLD nameservers directly for your NS records, not your own resolvers, will catch the delegation disappearing before a user does.
The authority to answer a zone and the authority to appear in the parent zone are separate things held by separate institutions. Every other failure mode in DNS sits below that line. This one sits above it.
A monitoring check that queries the TLD nameservers directly for your NS records, not your own resolvers, will catch the delegation disappearing before a user does.

The failure that causes total outage more often than any server misconfiguration is a domain registration that has lapsed.