
DNS Root Key-Signing Key Rollover Scheduled for October 11, 2026
The DNS root zone is scheduled to change its key-signing key on October 11, 2026, only the second such rollover ever. Cloudflare explains what KSK-2024 means for resolvers and how to check readiness.
What changes on October 11
On October 11, 2026, the DNS root zone is scheduled to change its key-signing key (KSK) for only the second time ever. The change, known as a KSK rollover, replaces KSK-2017 (key tag 20326) with KSK-2024 (key tag 38696) as the signer of the root's DNSKEY record set. The KSK anchors DNSSEC's chain of trust, which lets validating resolvers authenticate DNS answers using cryptographic signatures. If a resolver does not trust the new key before the switch, its users may be unable to reach websites under any top-level domain.
Most website operators do not need to make any changes. Operators of DNSSEC-validating resolvers should confirm their software trusts KSK-2024 and follow their vendor's instructions to update trust anchors if the key is missing. Cloudflare says its systems, including 1.1.1.1 and Gateway DNS, already trust the new key, so users do not need to take any action.
How resolvers pick up the new key
Under RFC 5011, resolvers can learn a new root trust anchor automatically. The root publishes the new KSK alongside the existing one, and the existing KSK continues signing that set so resolvers can verify the replacement with a key they already trust. A resolver then waits at least 30 days and keeps checking the root's signed DNSKEY records before accepting the new key. KSK-2024 has been published in the root's DNSKEY set since January 11, 2025, giving automatic updates time to converge. Cloudflare added KSK-2024 directly to its resolver's built-in trust anchors in July 2024, after the 2018 rollover showed that software upgrades and machine moves could cause resolvers to lose learned trust-anchor state.
A new way to check readiness
Cloudflare has implemented RFC 8509, the root key trust anchor sentinel, in 1.1.1.1. The protocol uses specially named DNS queries, is-ta-38696 and not-ta-38696, to ask a resolver whether it trusts the new key. A supporting resolver returns a valid response or SERVFAIL depending on its answer. Cloudflare's readiness test at dnstest.dev/ksk-2024 uses this protocol to check the resolver a browser actually uses, along with control queries that distinguish a meaningful result from a failed lookup or unsupported protocol. The company encourages DNS providers and resolver developers to support the sentinel.
Same algorithm, more to come
Both KSK-2017 and KSK-2024 use RSA/SHA-256, so the rollover replaces the key pair without changing the signature method. IANA plans an idealized three-year rollover interval; the gap since 2018 is longer, which ICANN attributes to pandemic disruption and upgrades to the hardware protecting the private signing keys. The process continues into 2027, when ICANN plans to revoke KSK-2017, remove it from the root zone, and delete its private key. ICANN has also proposed a future algorithm rollover to ECDSA P-256, which is not post-quantum. Meanwhile, 1.1.1.1 now validates ML-DSA-44 signatures, and Cloudflare says the rollovers performed now will exercise the trust-anchor updates needed when the root eventually moves to post-quantum cryptography.
Sources: Cloudflare
SiTech — AI-powered web development
We build fast, modern websites and bring AI into real business workflows. Have a project or a question? We'd love to help.