Internet's root zone DNSSEC key rotates October 11
in plain words
The internet uses a special security key to prove that DNS Domain Name System The internet's directory that links domain names to computer addresses. Full definition of DNS answers, the system that turns website names into addresses, are genuine. On October 11, 2026 this key changes for the second time ever. People who run resolver The DNS server that looks up domain names on behalf of users. Full definition of resolver need to check their systems support the new key, or their service could break. Cloudflare made an online tool to test this.
The cryptographic key used to sign the root zone The top of the DNS, listing every TLD and its name servers. Full definition of root zone, part of the DNSSEC Domain Name System Security Extensions Digital signatures that prove DNS answers are genuine and unchanged. Full definition of DNSSEC security system, is set to rotate on October 11, 2026, according to Ondřej Filip of CZ.NIC. This will be only the second such rotation in the history of the domain name A readable internet name made of labels separated by dots. Full definition of domain name system. The current key, ID 20326, known as KSK-2017, has been in use since October 11, 2018, when it replaced the original KSK-2010. It will be replaced by a new key, ID 38696, known as KSK-2024.
Filip explains that KSK-2024 was not originally meant to be the next key. The plan had been to use KSK-2023, generated during the 49th KSK Key Signing Key The DNSSEC key that signs a zone's key set and is referenced by the parent zone. Full definition of KSK ceremony, but the hardware security module then in use, the AEP Keyper made by Ultra Electronics, was discontinued. IANA Internet Assigned Numbers Authority The functions that coordinate the root zone, IP addresses and protocol numbers. Full definition of IANA and PTI Public Technical Identifiers The ICANN affiliate that performs the IANA functions, including root zone changes. Full definition of PTI staff switched to a Luna USB 7 module from Thales, but could not transfer KSK-2023 to the new hardware, so that key was never deployed. Running two hardware security modules during the transition required new access tokens for community trusted community representatives and lengthened ceremony procedures. The replacement key, KSK-2024, was generated during the 53rd KSK ceremony and published in the root zone on January 11, 2025, starting a waiting period for resolver operators to adopt it before this weekend's cutover.
Operators running DNS resolvers are advised to confirm they already use KSK-2024/38696 so the rotation causes no disruption. Filip points to a testing mechanism defined in RFC Request for Comments A numbered document in the series recording the internet's technical standards and practices. Full definition of RFC 8509: querying the label One dot-separated part of a domain name, up to 63 characters long. Full definition of label root-key-sentinel-is-ta-38696 should return NXDOMAIN Non-Existent Domain The DNS answer meaning the requested name does not exist. Full definition of NXDOMAIN, while querying root-key-sentinel-not-ta-38696 should return SERVFAIL Server Failure The DNS answer meaning the lookup failed, often due to broken name servers or DNSSEC. Full definition of SERVFAIL. He demonstrates this using CZ.NIC's own public resolver, odvr.nic.cz, showing the expected responses. Any other result suggests a resolver either lacks RFC 8509 support, has not loaded KSK-2024, or is not validating DNSSEC at all, all of which Filip calls bad signs. Cloudflare has also published an online tool allowing network and resolver operators to check their configuration for the rotation, flagging problems with red warning indicators.