---
id: "trust-anchor"
kind: "glossary-term"
title: "trust anchor"
language: "en"
category: "DNS and technical foundations"
updated: "2026-10-04T14:01:23Z"
canonical: "https://tldlog.com/glossary/trust-anchor/"
translations:
  es: "https://tldlog.com/es/glosario/anclaje-confianza/"
  de: "https://tldlog.com/de/glossar/vertrauensanker/"
  fr: "https://tldlog.com/fr/glossaire/ancre-confiance/"
  it: "https://tldlog.com/it/glossario/trust-anchor/"
  pt-BR: "https://tldlog.com/pt/glossario/ancora-confianca/"
  ru: "https://tldlog.com/ru/glossariy/yakor-doveriya/"
  zh-Hans: "https://tldlog.com/zh/cihui/xinren-mao/"
---

# trust anchor

A public key that a DNSSEC-checking resolver is set up to trust from the start, without needing proof from anywhere else. In practice this is the key of the root zone, published by IANA. Every DNSSEC check ends at this key, so resolvers must hold the current one.

## related terms

- [KSK](https://tldlog.com/glossary/ksk/)
- [chain of trust](https://tldlog.com/glossary/chain-of-trust/)
- [DNSSEC validation](https://tldlog.com/glossary/dnssec-validation/)
- [key rollover](https://tldlog.com/glossary/key-rollover/)
- [root zone](https://tldlog.com/glossary/root-zone/)
