DNS root key-signing key to roll over on October 11, 2026, only the second such change
The root's key-signing key, which anchors DNSSEC's chain of trust, will be replaced by KSK-2024 (key tag 38696), succeeding KSK-2017 (key tag 20326). The first rollover occurred in 2018, and the new key has been visible in the root's DNSKEY record set since January 11, 2025.
The DNS root is scheduled to perform a key-signing key rollover on this date, only the second time the root key has been changed.1
The incoming root key-signing key is designated KSK-2024 and carries key tag 38696; it will replace KSK-2017, which has key tag 20326.1
Under RFC 5011, a resolver must observe a new key continuously in the signed DNSKEY records for at least 30 days before trusting it.1
Story
The DNS root's second key-signing key rollover: what changes and why it mattersThe DNS root is set to perform a key-signing key rollover on October 11, 2026, an event that has occurred only once before.1 This operation, known as a KSK rollover, replaces the cryptographic key that serves as the foundation of DNSSEC's chain of trust.1 The key-signing key allows validating resolvers to verify the authenticity of DNS answers through cryptographic signatures.1 The first such rollover took place in 2018, making the upcoming change the second in the root's history.1
The incoming key is designated KSK-2024 and carries key tag 38696.1 It will take the place of the current root signer, KSK-2017, which is identified by key tag 20326.1 At the root level, two types of keys are used: the zone-signing key signs DNS records, while the key-signing key signs the DNSKEY record set that contains the public keys.1 This division of labor means the key-signing key does not sign individual records but instead validates the set of keys used for signing.1
The root's DNSKEY record set has included KSK-2024 since January 11, 2025.1 This early publication gives resolvers that rely on automatic updates under RFC 5011 a long period to observe and trust the new key before the changeover.1 RFC 5011 defines a specification that enables DNS resolvers to discover and trust a new root anchor automatically.1 Under that process, a resolver must observe a new key continuously in the signed DNSKEY records for at least 30 days before trusting it.1 Because KSK-2024 has been in the DNSKEY record set since January 2025, resolvers following RFC 5011 have had well over the required 30 days to establish trust.1
Cloudflare incorporated KSK-2024 directly into its software's default trust anchors in July 2024.1 As a result, resolvers running Cloudflare's 1.1.1.1 and Gateway DNS already possess trust in the incoming KSK-2024 key.1 This means users of those services do not need to take any action for the rollover, as their resolvers are pre-configured to trust the new key.1
For operators of other validating resolvers, RFC 8509 provides a sentinel protocol that allows users to test whether a DNS resolver trusts an identified root key.1 Under the sentinel testing mechanism, querying is-ta-38696 evaluates if key 38696 is trusted, whereas querying not-ta-38696 evaluates if it is untrusted.1 A sentinel-compliant validating resolver that trusts KSK-2024 is designed to respond with a SERVFAIL error when queried for not-ta-38696.1 This test can help administrators confirm that their resolvers have correctly adopted the new key before the rollover date.1
The key-signing key is the anchor for DNSSEC's chain of trust, enabling validating resolvers to confirm the authenticity of answers using cryptographic signatures.1 Without a trusted key-signing key, DNSSEC validation cannot succeed, and resolvers may treat responses as insecure or bogus.1 The rollover therefore affects the entire DNS ecosystem, from root server operators to end-user resolvers.1
The process of updating the root key-signing key is known as a KSK rollover.1 The first such rollover occurred in 2018, and the upcoming one in 2026 will be the second.1 The long gap between rollovers reflects the critical nature of the key and the need for careful coordination.1
The root's DNSKEY record set has contained KSK-2024 since January 11, 2025, giving resolvers that follow RFC 5011 ample time to observe and trust it.1 RFC 5011 requires a resolver to see a new key continuously for at least 30 days before trusting it.1 Because the key has been published for well over a year, the 30-day requirement is easily met for resolvers that have been online and updating.1
Cloudflare's early adoption of KSK-2024 in July 2024 means its 1.1.1.1 and Gateway DNS resolvers already trust the new key.1 This pre-emptive action ensures that users of those services will not experience validation failures when the rollover occurs.1 Other resolver operators can use the RFC 8509 sentinel tests to verify their own readiness.1
The sentinel protocol defined in RFC 8509 allows users to test whether a DNS resolver trusts an identified root key.1 Querying is-ta-38696 checks if key 38696 is trusted, while querying not-ta-38696 checks if it is untrusted.1 A sentinel-compliant validating resolver that trusts KSK-2024 should return a SERVFAIL error for not-ta-38696.1 These tests provide a practical way for administrators to confirm that their resolvers have adopted the new key.1
The upcoming rollover is a significant event because the root key-signing key is the ultimate trust anchor for DNSSEC.1 Only one previous rollover has occurred, in 2018, so the 2026 change is only the second in the root's history.1 The new key, KSK-2024, with key tag 38696, will replace KSK-2017, with key tag 20326.1 Resolvers that have not yet adopted the new key may face validation issues after the rollover, but tools like the sentinel tests can help identify such cases.1
Structure
Who is connected to whom- 1Cloudflare
- partners with →Fact
- uses →Fact
- produces →Fact
- supplies →Fact
- ← customer ofFact
History
How it came to this- 2018First root KSK rolloverThe initial root key-signing key rollover took place in 2018.
- July 2024Cloudflare incorporates KSK-2024 into default trust anchorsCloudflare incorporated KSK-2024 directly into its software's default trust anchors in July 2024.
- January 11, 2025KSK-2024 added to root DNSKEY record setThe root's DNSKEY record set has included KSK-2024 since January 11, 2025.
- NowOctober 11, 2026 Scheduled DNS root key-signing key rollover
- October 11, 2026The DNS root is scheduled to execute the key-signing key rollover, replacing KSK-2017 with KSK-2024.
Impact
Spreading outward, level by level- Level 1DNSSEC chain of trust
The key-signing key functions as the anchor for DNSSEC's chain of trust, enabling validating resolvers to confirm the authenticity of answers using cryptographic signatures.1
Fact - Level 2Resolvers using Cloudflare 1.1.1.1 and Gateway DNS
Resolvers running Cloudflare's 1.1.1.1 and Gateway DNS already possess trust in the incoming KSK-2024 key, so users of those services do not need to take action for the rollover.1
Fact - Level 3Other validating resolver operators
Operators of other validating resolvers can use the RFC 8509 sentinel protocol to test whether their resolver trusts KSK-2024 before the rollover date.
Analysis - Level 4Entire DNS ecosystem
The rollover affects the entire DNS ecosystem, from root server operators to end-user resolvers, because without a trusted key-signing key DNSSEC validation cannot succeed.
Analysis
Ahead
Checked automatically when due; the result goes to the track recordThe DNS root is scheduled to execute the key-signing key rollover, replacing KSK-2017 with KSK-2024.
Sources
What each source supportsWritten by AI from the sources listed below: every fact was checked word for word against its source, and inference is marked apart. How we write