DNS root switches its DNSSEC signing key on 11 October: what resolver operators should check
The DNS root is scheduled to change its key-signing key on 11 October. Cloudflare says most site operators need not act, but anyone running a validating resolver should confirm it trusts KSK-2024.

Key points
- 1The DNS root is scheduled to start signing with KSK-2024 (key tag 38696) on 11 October 2026, replacing KSK-2017 (key tag 20326).
- 2Cloudflare says most website operators need not act; operators of DNSSEC-validating resolvers should confirm that their resolver trusts KSK-2024.
- 3Domains on Cloudflare DNS and users of 1.1.1.1 and Gateway DNS need no action, according to Cloudflare.
- 4A Cloudflare readiness test uses RFC 8509 sentinel queries to ask a resolver whether it trusts the new key.
- 5ICANN plans to revoke and remove KSK-2017 in 2027, Cloudflare says.
Full story
The DNS root zone is scheduled to switch to a new key-signing key (KSK) on 11 October 2026, Cloudflare says in a blog post dated 6 October. According to the post, it is only the second time the root has changed this key. The KSK sits at the top of DNSSEC's chain of trust: a validating resolver starts from a root key it already trusts, known as a trust anchor, uses it to verify the root's list of public keys and works its way down from there. The new key, KSK-2024 with key tag 38696, replaces KSK-2017 (key tag 20326) in signing the root's DNSKEY set. Cloudflare warns that a resolver which fails to trust the replacement in time could leave its users cut off from sites under every top-level domain, even when those sites are running normally.
Cloudflare says most website operators have nothing to change. The rollover matters to anyone who runs a DNSSEC-validating resolver: they should confirm that it trusts KSK-2024 and, where the key is missing, update the trust anchors as described in ICANN's guidance and in their software vendor's instructions. Domains that use Cloudflare for DNS, and users of 1.1.1.1 and Gateway DNS, need no action, according to the company, because its systems already trust the new key. Cloudflare says it added KSK-2024 to the built-in trust anchors of its resolver software in July 2024, next to KSK-2017.
Resolvers can also learn a new root key automatically under RFC 5011. The root has carried KSK-2024 alongside the current key in its DNSKEY set since 11 January 2025, and a resolver using this mechanism accepts it only after observing it for at least 30 days and verifying it once more. Cloudflare recalls that while preparing for the first rollover in 2018, it saw resolvers lose such learned trust after software upgrades or moves to other machines, which is why it now ships the new key with its software instead of relying on each resolver to keep it.
To let users check in advance, Cloudflare has put up a readiness test that asks the resolver used by the browser whether it trusts the new key. The test relies on the root key trust anchor sentinel from RFC 8509, which Cloudflare has implemented in 1.1.1.1: two specially named queries, is-ta-38696 and not-ta-38696, return either a normal answer or SERVFAIL depending on whether the resolver trusts the key. Cloudflare notes that the browser result can be influenced by Secure DNS or a VPN, and that a result is inconclusive, not proof of a missing key, when the resolver's sentinel support cannot be established. KSK-2024 uses the same RSA/SHA-256 algorithm as its predecessor, and the process continues after October: in 2027, according to the post, ICANN intends to revoke the old key, take it out of the root zone and delete its private key.
Why it matters
The root key is the starting point of DNSSEC validation, so a resolver that misses the change can cut its users off from sites under every top-level domain, not just one. Cloudflare says the 2018 rollover showed that resolvers can lose a learned key during upgrades or migrations. The company also presents this rollover as practice for a later move of the root to post-quantum cryptography, which would need yet another root key change.
Timeline
· Published
Topics#DNSSEC#DNS#Cloudflare#KSK rollover#ICANN
Sources
This story draws on the following sources. Read them for full context.



