DNS root gets a new master key on October 11, while some resolvers still keep a 2010 one
The root KSK rollover swaps in KSK-2024. Verisign data shows about 3.5% of reporting resolvers still hold a key revoked in 2019.
OddBrief EditorialAI-assisted, human-reviewed
InternetKey facts
- When
- October 11, 2026, the root zone starts signing with KSK-2024 only
- Keys
- KSK-2024 (key tag 38696) replaces KSK-2017 (key tag 20326)
- Lag
- about 3.5% of reporting resolvers still keep KSK-2010, revoked in 2019, per Verisign
- Next
- KSK-2017 to be revoked and its private key deleted in 2027
On October 11, 2026, the DNS root zone switches to a new key-signing key, KSK-2024, only the second such change since the root was signed in 2010. Any DNSSEC-validating resolver that does not trust the new key could cut its users off from sites across every top-level domain, Cloudflare warned in a guide published October 6.
Two details sit under the headline. Data from Verisign shows that about 3.5% of resolvers that report their keys still hold KSK-2010, a key revoked in 2019. And the new key uses the same RSA algorithm as before, so this rollover is mostly a rehearsal for a harder one.
What actually changes
The key-signing key is the anchor of DNSSEC's chain of trust. A resolver starts from a root key it already trusts, uses it to verify the root's list of public keys, and works down through top-level domains such as .com to individual sites.
From that date the list is signed by the new key (key tag 38696) instead of KSK-2017 (key tag 20326). It has been published in the root zone since January 11, 2025, so resolvers that update automatically under RFC 5011 have had well over a year to accept it after the required 30-day wait.
Most website owners do not need to do anything, according to Cloudflare. Operators who run their own validating resolver should check that key tag 38696 is in their trust anchor file and follow their software vendor's instructions if it is missing.
Old keys linger
Verisign fellow Duane Wessels wrote that more than 95% of signalling resolvers had adopted KSK-2024 after about 500 days, a curve almost identical to the 2018 rollover. The same data shows the long tail: roughly 3.5% still retain KSK-2010, which was created in 2010 and revoked in 2019.
Cloudflare's own lesson from 2018 was that resolvers sometimes lost a key they had learned during software upgrades or moves between machines. This time it built KSK-2024 directly into its resolver software in July 2024, and it now supports RFC 8509 sentinel queries, which let anyone ask a resolver whether it trusts a given root key.
Still RSA, and not post-quantum
The rollover was meant to happen every three years. ICANN attributes the longer gap to pandemic disruption and new hardware for protecting the private key; a key generated in 2023 had to be retired because its hardware security modules reached end of support, Verisign said.
KSK-2024 keeps RSA/SHA-256. ICANN has proposed a later move to ECDSA P-256, which Cloudflare notes is not post-quantum either. A quantum-safe root would need yet another rollover, which is why the company calls this one practice for that step.
The old key stops signing on October 11 but is not gone. ICANN plans to revoke KSK-2017 and delete its private key in 2027.
Sources
- The keys to the Internet change on October 11, 2026. Are you ready?Cloudflareprimary source
- The 2024-2026 Root Zone KSK Rollover: Updates and ObservationsCircleID (Verisign)