DNS root key-signing key scheduled for second-ever rollover on October 11, 2026
The DNS root zone's key-signing key (KSK) is set to change on October 11, 2026, replacing KSK-2017 with KSK-2024 (key tag 38696) as part of a KSK rollover. This cryptographic key anchors DNSSEC's chain of trust, and validating resolvers must trust the new key beforehand to avoid potential resolution failures. Cloudflare and 1.1.1.1 users are unaffected as their systems already trust the new key.
Why it matters. DNSSEC validation failures could disrupt website accessibility globally if resolvers do not update their trust anchors, affecting internet reliability for users and operators relying on secure DNS resolution.