Root DNSSEC key rollover comes on October 11
The internet's root DNSSEC key changes on October 11, 2026, replacing KSK-2017 with KSK-2024. Here's what it means and how to check your resolver.
On October 11, 2026, one of the most important security keys on the internet will change. The Domain Name System Security Extensions, or DNSSEC, is the system that digitally signs DNS records to prove they have not been tampered with. At the very top of that system sits the root key, a master cryptographic key that validates the entire chain of trust. Cloudflare's blog post, written by Sebastiaan Neuteboom and James Godlewski, explains what is about to happen: the root key signing key, known as KSK-2017, will be replaced by a new one called KSK-2024.
The rollover replaces the key pair but keeps the same signing algorithm, RSA/SHA-256. That means the way signatures are created and verified stays the same; only the actual cryptographic keys change. KSK-2024 has the key tag 38696. A key tag is a short numerical label that helps identify a specific key. Replacing the key is still important because it limits how long a single private key stays in use and exercises the process of distributing new trust anchors, updating resolvers, and retiring old keys. Those steps can fail even when the cryptography itself works correctly.
The Internet Assigned Numbers Authority, or IANA, plans an idealized three-year rollover interval. The gap since the last rollover in 2018 has been longer, which the Internet Corporation for Assigned Names and Numbers, ICANN, attributes to pandemic disruption and upgrades to the hardware that protects the private signing keys. After October 11, KSK-2024 will sign the root's DNSKEY set. The rollover continues into 2027, when ICANN plans to revoke KSK-2017, remove it from the root zone, and delete its private key. Stopping a key from signing and removing trust in that key are separate steps.
Looking further ahead, ICANN has proposed a future root algorithm rollover to ECDSA P-256. ECDSA produces smaller keys and signatures than RSA, but it is not a post-quantum algorithm. Cloudflare's public DNS resolver, 1.1.1.1, now validates ML-DSA-44 signatures, which are designed to remain secure against attacks using quantum computers. For DNSSEC's whole chain of trust to become post-quantum secure, signed domains, their parent zones, and the root must adopt post-quantum cryptography too. That would require another root key rollover, and this October's rollover, while keeping RSA, exercises the trust-anchor updates needed for that future move.
To help operators check readiness, Cloudflare points to a test at https://dnstest.dev/ksk-2024. The browser test checks the resolver your browser uses, which may be affected by Secure DNS or a VPN. Dig commands can explicitly query 1.1.1.1. Both provide a snapshot of the resolver path answering those requests. The test also checks that an ordinary signed name resolves, that a deliberately invalid DNSSEC name is rejected, and that the resolver responds to a sentinel query for the current root key. Sentinel queries, defined in RFC 8509, let operators check whether resolvers have accepted a new trust anchor. If sentinel support cannot be established, the result is inconclusive; it does not mean the new key is missing. Cloudflare encourages DNS providers and resolver developers to support RFC 8509 sentinels, and users should be able to check whether their resolver trusts the next root key before a rollover.
For everyday internet users, this is a reminder that the DNS resolver you choose matters. A privacy-first encrypted DNS service such as AEU DNS (aeu-dns.com) gives you control over your DNS queries and lets you verify that your resolver is correctly validating DNSSEC, including new trust anchors. If you operate a DNSSEC-validating resolver, confirm that it trusts KSK-2024, key tag 38696, and follow ICANN's guidance and your software vendor's instructions if the key is missing.
Terms explained
- DNSSEC
- Domain Name System Security Extensions, a set of security measures that digitally sign DNS records so you can trust they have not been altered.
- KSK
- Key Signing Key, a special cryptographic key used to sign other DNS keys and establish a chain of trust.
- Trust anchor
- A trusted public key that resolvers use as a starting point to verify the authenticity of other DNS signatures.
- Root zone
- The top level of the DNS hierarchy, holding the master records for all top-level domains like .com and .org.
- Resolver
- A server that receives your DNS queries and looks up the internet address for a domain name.
- RSA/SHA-256
- A widely used cryptographic algorithm for creating and verifying digital signatures, based on large prime numbers and a secure hash function.
- ECDSA P-256
- An elliptic curve digital signature algorithm that produces smaller keys and signatures than RSA, used for efficient public key cryptography.
- ML-DSA-44
- A post-quantum digital signature algorithm designed to remain secure even against attacks from quantum computers.
How to protect yourself
- Visit https://dnstest.dev/ksk-2024 in your browser to check if your current DNS resolver is ready for the new root key.
- If you run your own DNSSEC-validating resolver, update its trust anchor to include KSK-2024 with key tag 38696 according to your software vendor's instructions.
- Use an encrypted DNS service such as DNS over HTTPS or DNS over TLS to prevent your DNS queries from being tampered with on the network.
- Keep your operating system, browser, and DNS software updated so they receive the latest trust anchor lists and security fixes automatically.
- If you are not sure whether your ISP or DNS provider supports the new root key, contact them and ask about their DNSSEC validation readiness.
