Skip to content
OddBrief
Internet2 minPrimary source linked

DNS root gets a new master key on October 11, while some resolvers still keep a 2010 one

The root KSK rollover swaps in KSK-2024. Verisign data shows about 3.5% of reporting resolvers still hold a key revoked in 2019.

AI-assisted, human-reviewed

Illustration of a brass key handed over above a table, with glowing lines spreading out from itInternet
AI-generated illustration

Key facts

When
October 11, 2026, the root zone starts signing with KSK-2024 only
Keys
KSK-2024 (key tag 38696) replaces KSK-2017 (key tag 20326)
Lag
about 3.5% of reporting resolvers still keep KSK-2010, revoked in 2019, per Verisign
Next
KSK-2017 to be revoked and its private key deleted in 2027

On October 11, 2026, the DNS root zone switches to a new key-signing key, KSK-2024, only the second such change since the root was signed in 2010. Any DNSSEC-validating resolver that does not trust the new key could cut its users off from sites across every top-level domain, Cloudflare warned in a guide published October 6.

Two details sit under the headline. Data from Verisign shows that about 3.5% of resolvers that report their keys still hold KSK-2010, a key revoked in 2019. And the new key uses the same RSA algorithm as before, so this rollover is mostly a rehearsal for a harder one.

What actually changes

The key-signing key is the anchor of DNSSEC's chain of trust. A resolver starts from a root key it already trusts, uses it to verify the root's list of public keys, and works down through top-level domains such as .com to individual sites.

From that date the list is signed by the new key (key tag 38696) instead of KSK-2017 (key tag 20326). It has been published in the root zone since January 11, 2025, so resolvers that update automatically under RFC 5011 have had well over a year to accept it after the required 30-day wait.

Most website owners do not need to do anything, according to Cloudflare. Operators who run their own validating resolver should check that key tag 38696 is in their trust anchor file and follow their software vendor's instructions if it is missing.

Old keys linger

Verisign fellow Duane Wessels wrote that more than 95% of signalling resolvers had adopted KSK-2024 after about 500 days, a curve almost identical to the 2018 rollover. The same data shows the long tail: roughly 3.5% still retain KSK-2010, which was created in 2010 and revoked in 2019.

Cloudflare's own lesson from 2018 was that resolvers sometimes lost a key they had learned during software upgrades or moves between machines. This time it built KSK-2024 directly into its resolver software in July 2024, and it now supports RFC 8509 sentinel queries, which let anyone ask a resolver whether it trusts a given root key.

Still RSA, and not post-quantum

The rollover was meant to happen every three years. ICANN attributes the longer gap to pandemic disruption and new hardware for protecting the private key; a key generated in 2023 had to be retired because its hardware security modules reached end of support, Verisign said.

KSK-2024 keeps RSA/SHA-256. ICANN has proposed a later move to ECDSA P-256, which Cloudflare notes is not post-quantum either. A quantum-safe root would need yet another rollover, which is why the company calls this one practice for that step.

The old key stops signing on October 11 but is not gone. ICANN plans to revoke KSK-2017 and delete its private key in 2027.

Sources