← NewsNews

Root Zone KSK Rollover Completes on 11 October 2026

From 11 October 2026 the DNS root zone is signed only with KSK-2024 (key tag 38696). Validating resolvers without the new trust anchor will stop resolving. What to check.

Published: · 2 min read

Effective date: 2026-10-11 · Source: ICANN Publishes Guidance to Help Prepare for the October 2026 Root KSK Rollover, published 2026-08-11.

What happened

On 11 August 2026 ICANN published updated guidance, "What to Expect During the Root KSK Rollover", for the change of the DNS root zone's key signing key. On 11 October 2026 the root zone will be signed only with the new key, KSK-2024. The key has been visible for a long time: according to ICANN's blog post of 27 July 2026, KSK-2024 was first published in the root zone on 11 January 2025, and more than 95 percent of the resolvers that report their trust anchors already use it. The previous rollover happened in October 2018.

Who is affected

Only operators of DNSSEC-validating recursive resolvers. Domain owners, authoritative DNS operators and people who use their ISP's or a public resolver have nothing to do. If a validating resolver still trusts only the old key after 11 October, it cannot validate the root zone any more, and because everything hangs off the root, it will fail every lookup, not just DNSSEC-signed names.

What to do

  1. Check the trust anchor, do not assume. The key to look for has key tag 38696. ICANN's blog names the files: bind.keys for ISC BIND, root.key for Unbound and PowerDNS Recursor, root.keys for Knot Resolver.
  2. Automatic updates (RFC 5011) need the resolver to have been running and observing the root for at least 30 days to accept the new key on its own. A resolver installed from an old image and never updated may still be missing it.
  3. Manually configured trust anchors must be edited by hand; update them before 11 October and restart or reload the resolver.
  4. Complete testing before the date. ICANN's guidance is available in the six UN languages and Portuguese.

How to check

Our DNSSEC checker validates a domain's chain from the root down, which tells you whether the zone and its signatures are in order; it does not tell you which trust anchor your own resolver holds. That check has to be done on the resolver itself.

Background

DNSSEC explained covers keys, DS records and the chain of trust; the glossary entry for DS record is the short version.

Sources