The cryptographic key securing the DNS root zone is set to change for only the second time in history, with a hard cutover planned for 11 October 2026. Verisign and ICANN have spent the past two years rolling out KSK-2024, the successor to the 2017 key that currently anchors DNSSEC validation worldwide. The transition has proceeded smoothly, but any resolver that has not added the new key by the October deadline will fail to validate signed responses, breaking DNS resolution for end users behind it.
How the rollover works
The root zone Key Signing Key (KSK) is the top-level cryptographic anchor for DNSSEC. When a resolver validates a signed response, it traces the chain of trust back to the KSK. To replace the key, ICANN and Verisign follow a multi-year process governed by RFC 5011. The new key is first published in the root zone, and resolvers that support RFC 5011 automatically add it to their trust store after observing it for 30 consecutive days. Operators who manage their own trust anchors must update them manually.
KSK-2024 was generated in 2023 after a hardware refresh. The original HSMs used to protect the key material had reached end-of-support, so the operation migrated to new hardware from a different vendor before generating the key. The public component of KSK-2024 was first published in the root zone in January 2025. Since then, Verisign and ICANN have monitored adoption via RFC 8145 trust-anchor signals sent by resolvers to the root name servers.
Adoption trends and lessons from 2018
The data show that adoption of KSK-2024 has followed a nearly identical curve to the 2018 rollover. By July 2026, over 95 % of resolvers that send trust-anchor signals were using the new key. The sharp increase in February 2025 corresponds to the 30-day RFC 5011 hold-down period: once resolvers had observed the key for 30 days, they added it to their trust store. A small fraction—about 3.5 %—still retain the 2010 key, which was revoked in 2019, while essentially 100 % continue to use the 2017 key until the cutover.
The 2018 rollover offered a cautionary tale. That rollover was originally scheduled for October 2017 but was postponed for a year after operators discovered that some resolvers were sending noisy or contradictory trust-anchor signals. The delay gave software vendors and resolver operators time to update their configurations. The final rollover in October 2018 went smoothly, but the experience underscored the importance of early monitoring and outreach.
- New root zone KSK (KSK-2024) was generated in 2023 after a hardware refresh.
- Public component published in the root zone in January 2025.
- Over 95 % of resolvers now use KSK-2024, per RFC 8145 signals.
- Final cutover: 11 October 2026, when the root zone will sign exclusively with KSK-2024.
- Resolvers that have not added KSK-2024 will fail DNSSEC validation after that date.
What operators need to do
Most resolvers running current software have already added KSK-2024 automatically. However, operators should verify their configurations now. The correct key has a keytag of 38696. Common resolver software stores the trust anchor in these files:
- ISC BIND:
bind.keys - Unbound:
root.key - PowerDNS Recursor:
root.key - Knot Resolver:
root.keys
If KSK-2024 is missing, operators should check whether automatic updates are enabled and whether the resolver process has write access to the key storage directory. Manual intervention may be required for resolvers that do not support RFC 5011 or that have disabled automatic updates.
For professionals:
Verify your resolver’s trust anchor now. A single misconfigured resolver can break DNS resolution for an entire network. Test with dig +dnssec . DNSKEY and confirm that the response includes KSK-2024 (keytag 38696). If it does not, update your configuration before 11 October.
Automated pipeline · Domains
Synthesized from 1 industry feed on 28 Jul 2026. Passed independent editor verification (score 95/100) before publication. Style guide v1.4.
Sources
Decision trail
- Checking for duplicates — New story No recent or in-pipeline article covers the Root Zone KSK Rollover updates and observations.
- Checking for duplicates — New story pre_write:; No previously published or in-pipeline article covers the Root Zone KSK rollover process.
- Writing the article — Draft created article_id=369 slug=root-zone-ksk-rollover-nears-october-2026-completion
-
Editor review — Approved
- Score: 95/100
- Style compliance: Headline exceeds 90-character limit (92 characters). Shorten to meet style guide.
- Factual grounding: Source states the cutover date as 'Oct. 11, 2026', but the draft uses '11 October 2026'. While the date is correct, the formatting differs from the verbatim source. This is minor as the date itself is accurate.
- Generating reader Q&A — Generated 4 items
- Assigning hero image — Reused library image reused image #21
- Linking related stories — Linked 1 relations from 312 candidates
- Linking related stories — Linked 1 relations from 313 candidates
- Publishing — Published root-zone-ksk-rollover-nears-october-2026-completion
- Mastodon — Posted https://mstdn.social/@hostingpaper/116998463902278336


Discussion · coming soon
Be the first to join the thread when community discussion launches.