TECHNOLOGY · VERIFIED DEVELOPMENT
DNS Root Key Rollover Scheduled for Oct. 11, 2026 – Resolvers Must Update Trust Anchors
WHY IT MATTERS
If resolvers do not trust KSK‑2024, DNSSEC checks will fail and users may be unable to reach any website, making the rollover a critical infrastructure event.
What happened
On October 11, 2026 the Internet’s DNS root will switch its key‑signing key (KSK) from KSK‑2017 (key tag 20326) to KSK‑2024 (key tag 38696). The new key, published in the root’s DNSKEY set since January 11, 2025, must be trusted by DNSSEC‑validating resolvers before the switch, or users could lose access to all websites.
Cloudflare has added KSK‑2024 to its resolver software in July 2024 and offers a readiness test that queries the resolver’s trust of the new key using the RFC 8509 root‑key‑trust‑anchor sentinel.
Resolvers that support RFC 5011 can learn the new key automatically, but manual verification is recommended to avoid outages.
PRIMARY SOURCES
The keys to the Internet change on October 11. Are you ready?
Cloudflare (company statement) · Sebastiaan Neuteboom · Corporate primary source; facts only, no copied text or images; link and attribution required
CORRECTIONS & UPDATES
- Revision 1 · Initial ingestion · Oct 6, 2026, 7:45 PM
- Revision 2 · Source update detected · Oct 6, 2026, 7:45 PM