we_are_coded.by CODE · The world, decoded
БГ
Cloudflare

On 11 October the DNS root changes its key for only the second time ever, and if you run your own resolver, you check that it trusts the new one

Cloudflare · event date: 6 October 2026Infra

On 11 October 2026 the DNS root changes its key-signing key (KSK) for only the second time ever; the first was in 2018. The new KSK-2024 replaces KSK-2017. Cloudflare says most website operators need to do nothing, but a resolver that validates DNSSEC must trust the new key before the switch.

In short
  • On 11 October 2026 KSK-2024 (key tag 38696) is scheduled to take over from KSK-2017 (20326) the signing of the DNS root's keys. The second rollover ever, after the one in 2018.
  • A DNSSEC-validating resolver that does not trust KSK-2024 before the switch may leave healthy websites unreachable. ICANN: do not assume automatic updates succeeded.
  • Cloudflare DNS, 1.1.1.1 and Gateway DNS customers do nothing. Readiness test: dnstest.dev/ksk-2024.
Checked on7 October 2026Responsible editorTsvetelin IvanovHow we workMethod · Corrections

On Monday we entered a DS record for our site and DNSSEC went live here. On Sunday the key under the whole chain above us changes.

The root has no parent to vouch for it. So the resolver, the program that looks up a site's address for your device, starts its check from a key it trusts in advance, and that very key is being replaced.

The facts: on 11 October 2026 the DNS root's new key-signing key (KSK), KSK-2024 with key tag 38696, is scheduled to take over from KSK-2017 (key tag 20326) the signing of the root's set of public keys. It is the second root key rollover after the first in 2018; per IANA, KSK-2017 has been signing since 11 October 2018. KSK-2024 was generated on 26 April 2024 and has been published in the root since 11 January 2025; per IANA, resolvers that follow RFC 5011 automatic updates should have begun to trust it from 10 February 2025. ICANN reminds operators of DNSSEC-validating resolvers to verify that KSK-2024 is in their configuration and not to assume automatic updates succeeded; if the key is missing, to confirm automatic updates are enabled and follow the resolver vendor's guidance. Cloudflare says most website operators need to do nothing. Customers of its DNS, 1.1.1.1 and Gateway DNS need not either, because its systems already trust KSK-2024.

The cost of a miss is clear. If a resolver does not trust the new key, its users may be unable to reach websites under any top-level domain, Cloudflare writes, even though the sites work normally.

The fault will not be in the site. It will be in the resolver that did not trust the new key in time.

Most people do nothing. If you just run a website or use someone else's resolver, this is not about you. That leaves those who run their own resolver with DNSSEC validation. The new key has sat in the root since January 2025, and a resolver waits at least 30 days before it trusts it. ICANN still wants you not to assume that worked.

The readiness test is at dnstest.dev/ksk-2024. It asks the resolver your browser uses whether it trusts KSK-2024. An inconclusive result does not mean the key is missing: it means the test could not establish whether the resolver supports the check. Secure DNS or a VPN in the browser can also change which resolver you are checking.

The old key does not vanish on Sunday. Under ICANN's plan it is revoked and removed from the root in the first quarter of 2027, and deleted from the two key management facilities in the second and third quarters.

Run a resolver with DNSSEC? Check it before Sunday, 11 October. After that, other people will feel the mistake.

The visual is generated code art. No third-party images.
Follow usFacebookLinkedIn
Official primary sources
→Cloudflare - The keys to the Internet change on October 11. Are you ready?, 06.10.2026→ICANN - Root Zone KSK Rollover 11.10.2026: Reminder for Resolver Operators→IANA - DNSSEC Trust Anchors and Rollovers→ICANN - Root Zone KSK Rollover FAQ (2026)
Original: https://wearecoded.com/en/articles/koren-dns-smenya-klyucha-11-oktomvri-ksk-2024.html
ShareFacebookXLinkedInTelegramWhatsApp
← Back to all news