On 11 October 2026 the DNS root changes its key-signing key (KSK) for only the second time ever; the first was in 2018. The new KSK-2024 replaces KSK-2017. Cloudflare says most website operators need to do nothing, but a resolver that validates DNSSEC must trust the new key before the switch.
- On 11 October 2026 KSK-2024 (key tag 38696) is scheduled to take over from KSK-2017 (20326) the signing of the DNS root's keys. The second rollover ever, after the one in 2018.
- A DNSSEC-validating resolver that does not trust KSK-2024 before the switch may leave healthy websites unreachable. ICANN: do not assume automatic updates succeeded.
- Cloudflare DNS, 1.1.1.1 and Gateway DNS customers do nothing. Readiness test: dnstest.dev/ksk-2024.
On Monday we entered a DS record for our site and DNSSEC went live here. On Sunday the key under the whole chain above us changes.
The root has no parent to vouch for it. So the resolver, the program that looks up a site's address for your device, starts its check from a key it trusts in advance, and that very key is being replaced.
The cost of a miss is clear. If a resolver does not trust the new key, its users may be unable to reach websites under any top-level domain, Cloudflare writes, even though the sites work normally.
Most people do nothing. If you just run a website or use someone else's resolver, this is not about you. That leaves those who run their own resolver with DNSSEC validation. The new key has sat in the root since January 2025, and a resolver waits at least 30 days before it trusts it. ICANN still wants you not to assume that worked.
The readiness test is at dnstest.dev/ksk-2024. It asks the resolver your browser uses whether it trusts KSK-2024. An inconclusive result does not mean the key is missing: it means the test could not establish whether the resolver supports the check. Secure DNS or a VPN in the browser can also change which resolver you are checking.
The old key does not vanish on Sunday. Under ICANN's plan it is revoked and removed from the root in the first quarter of 2027, and deleted from the two key management facilities in the second and third quarters.
Run a resolver with DNSSEC? Check it before Sunday, 11 October. After that, other people will feel the mistake.