What is changing?
The DNS root zone will change its key-signing key (KSK) on October 11, 2026. This is only the second root KSK rollover ever. The KSK anchors DNSSEC's chain of trust, which lets resolvers authenticate DNS answers using cryptographic signatures.
Why it matters
If validating resolvers do not trust the new key before the switch, otherwise healthy websites could become unreachable. Because the root KSK is the starting point of trust for every top-level domain, a failure can have broad impact.
Who needs to do what
- Most website operators do not need to make any changes for this rollover.
- If you run a DNSSEC-validating resolver, check that it trusts the new root key, KSK-2024, and follow your software vendor's instructions to update its trust anchors if the key is missing.
- If you use Cloudflare for your domain's DNS or rely on 1.1.1.1 and Gateway DNS, you do not need to take any action — those systems already trust KSK-2024.
The new key and the test
The new key is KSK-2024, identified by key tag 38696. It will replace KSK-2017 (key tag 20326) as the signer of the root's DNSKEY set. Cloudflare's rollover readiness test asks the resolver your browser uses whether it trusts the new key; the test uses RFC 8509 and has been implemented in 1.1.1.1.
How resolvers learn the new key
RFC 5011 lets resolvers learn a new root trust anchor automatically. The root publishes the new KSK alongside the existing one in its DNSKEY set; the existing KSK keeps signing that set, so a resolver can use the key it already trusts to verify the records containing the replacement. Before accepting the new key as a trust anchor, the resolver waits at least 30 days and keeps checking the root's signed DNSKEY records.



