ON 11 October 2026, the DNS root is due to change its key-signing key (KSK) for only the second time, in a move known as a KSK rollover. The root anchors DNSSEC’s chain of trust, allowing resolvers to verify signatures on DNS records. The new key is KSK-2024 (key tag 38696), which will replace KSK-2017 (key tag 20326) as the signer of the root’s DNSKEY set. Validating resolvers must trust KSK-2024 before the switch, or risk widespread reachability issues for websites under any top‑level domain.
Cloudflare notes that their own resolvers and services already trust KSK-2024, and provides guidance for operators of DNSSEC‑validating resolvers to update trust anchors if needed.
To help operators prepare, Cloudflare describes how resolvers obtain and validate the new root key using RFC 5011, including a mandatory 30‑day waiting period during which the resolver must verify the new key and then re‑verify after accepting it. They emphasise that KSK-2024 has been published in the root DNSKEY set since 11 January 2025, giving automatic trust‑anchor updates time to propagate. Cloudflare has also added KSK-2024 to built‑in trust anchors in July 2024 to reduce reliance on local learned state.
The article promotes RFC 8509 trust anchor sentinels and points readers to a readiness test at dnstest[.]dev/ksk-2024 to check whether a resolver trusts the new key. The rollover will continue into 2027, with plans to revoke KSK-2017 and, separately, to pursue a post‑quantum or alternate algorithm path for the root in the longer term.