---
id: "942bf74e-7b5b-4ca2-9b50-8f526bb718fd"
kind: "link"
title: "ICANN reminds resolver operators to check new DNSSEC root key ahead of rollover"
language: "en"
section: "security"
date: "2026-10-11T07:26:48Z"
updated: "2026-10-11T15:35:47Z"
canonical: "https://tldlog.com/l/icann-reminds-resolver-operators-check-new-dnssec-root-key/"
origin: "master"
translations:
  es: "https://tldlog.com/es/l/icann-recuerda-operadores-resolutores-verificar-nueva-clave/"
  de: "https://tldlog.com/de/l/icann-erinnert-resolver-betreiber-neuer-dnssec/"
  fr: "https://tldlog.com/fr/l/icann-rappelle-verifier-nouvelle-cle-racine-dnssec-avant/"
  it: "https://tldlog.com/it/l/icann-invita-gestori-resolver-verificare-nuovo-trust-anchor/"
  pt-BR: "https://tldlog.com/pt/l/icann-lembra-operadores-resolvedores-nova-chave-raiz-dnssec/"
  ru: "https://tldlog.com/ru/l/icann-napominaet-operatoram-rezolverov-proverit-novyy-yakor/"
  zh-Hans: "https://tldlog.com/zh/l/icann-dnssec-genyaoshi-lunzhuan/"
source:
  name: "icann.org"
  url: "https://www.icann.org/resources/pages/ksk-rollover-en"
  language: "en"
  date: "2026-10-01T09:25:00Z"
---

# ICANN reminds resolver operators to check new DNSSEC root key ahead of rollover

## in plain words

ICANN looks after a special security key system called DNSSEC that helps keep the internet’s address book safe from tampering. A new key, called KSK-2024, is being rolled out, and ICANN is telling the operators of systems that check this security to make sure their computers have already picked up the new key. If not, they need to fix their settings before the switch happens on 11 October 2026.

ICANN has issued a reminder to operators running DNSSEC-validating resolvers, the servers that check the cryptographic signatures used to confirm that domain name system responses have not been tampered with. The reminder concerns the upcoming Root Zone Key Signing Key (KSK) rollover, scheduled for 11 October 2026, during which the cryptographic key used to sign the root of the domain name system will change to a new key, KSK-2024, identified by Key Tag 38696.

ICANN advised resolver operators to verify directly that KSK-2024 is already present in their trust anchor configuration rather than assuming that automatic trust-anchor update mechanisms have already installed it. Trust anchors are the cryptographic reference points that validating resolvers use to confirm the authenticity of DNSSEC signatures; if a resolver does not have the correct current key in its trust anchor store, it may fail to validate DNS responses once the rollover takes effect, potentially causing validation failures for the domains it serves.

Operators who find that KSK-2024 is missing from their configuration were told to check whether their resolver software has automatic trust-anchor updates enabled, a mechanism defined to allow resolvers to pick up new root keys without manual intervention. Where automatic updates are not functioning or enabled, ICANN said operators should consult guidance from their specific resolver software vendor to manually update their trust anchors ahead of the rollover date.

The root zone KSK rollover is a periodic security maintenance process for the domain name system, ensuring that the cryptographic key securing the root zone can be refreshed over time. ICANN has previously carried out such rollovers and published technical resources and guidance for the process, with this reminder aimed specifically at ensuring resolver operators are prepared well before the October 2026 changeover to avoid disruption to DNSSEC validation for internet users relying on their systems.

Source: [icann.org](https://www.icann.org/resources/pages/ksk-rollover-en)

## also covered by

- [sidn.nl](https://www.sidn.nl/en/news-and-blogs/important-heads-up-for-dnssec-operators-root-zone-ksk-rollover-is-11-october) (in Dutch)
- [blog.nic.cz](https://blog.nic.cz/2026/10/09/rotace-klice-korenove-zony-jiz-11-rijna-zkontrolujte-si-sve-resolvery/) (in Czech)
- [blog.cloudflare.com](https://blog.cloudflare.com/root-ksk-2024-rollover/) (in English)
- [bortzmeyer.org](https://www.bortzmeyer.org/remplacement-cle-dnssec-2026.html) (in French)
