On October 11, 2026, the DNS root will perform its second-ever key-signing key (KSK) rollover. This KSK is crucial as it anchors DNSSEC's chain of trust, enabling DNS resolvers to authenticate responses using cryptographic signatures. The change requires validating resolvers to trust the new key before the scheduled date to ensure continued accessibility of websites.
Operators of DNSSEC-validating resolvers need to confirm that their systems trust the new root key, KSK-2024. Failure to do so could result in healthy websites becoming unreachable after the rollover. Software vendors' instructions should be followed to update trust anchors if the key is not present.
Most website operators are not required to make any changes for this rollover. Users relying on services like Cloudflare for domain DNS or 1.1.1.1 and Gateway DNS do not need to take action, as these systems already trust KSK-2024. A rollover readiness test is available for users to check if their browser's resolver trusts the new key, utilizing RFC 8509.
DNSSEC allows resolvers to verify digital signatures on DNS records, ensuring their authenticity and integrity. This process relies on a chain of trust, starting from a root public key, or its fingerprint, which the resolver already trusts. This trusted key is known as a trust anchor. The root's signing keys include a zone-signing key (ZSK) for signing DNS records and a key-signing key (KSK) for signing the ZSK.
✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →
One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.
One email a day. Unsubscribe in one click, any time.
Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.
▶ Play today's briefNew every morning, and the back catalogue is archived by date.
The DNS root's key-signing key (KSK) will undergo its second-ever rollover on October 11, 2026, impacting DNSSEC's chain of trust. DNSSEC-validating resolvers must trust the new key, KSK-2024, before the switch to prevent websites from becoming unreachable. Most website operators do not need to take action, but resolver operators should verify their systems trust the new key.