DNS Root Shifts to KSK-2024 on Oct. 11, Requiring Trust in Key 38696
Updated
Updated · The Cloudflare Blog · Oct 6
DNS Root Shifts to KSK-2024 on Oct. 11, Requiring Trust in Key 38696
3 articles · Updated · The Cloudflare Blog · Oct 6
Summary
October 11, 2026 marks the DNS root’s second-ever key-signing key rollover, when KSK-2024 will replace KSK-2017 as the signer of the root DNSKEY set.
KSK-2024, key tag 38696, has been published since January 11, 2025 so validating resolvers could learn it before the switch; resolvers that do not trust it may fail DNSSEC checks and make otherwise healthy sites unreachable.
Cloudflare said most website operators need take no action, but operators of DNSSEC-validating resolvers should confirm their trust anchors include the new key and follow vendor guidance if it is missing.
1.1.1.1 and Gateway DNS already trust KSK-2024, and Cloudflare has added an RFC 8509 readiness test at dnstest.dev to let users check whether their resolver accepts the new root key.
The rollover keeps the same RSA/SHA-256 algorithm, while ICANN plans to revoke KSK-2017 in 2027 and is separately considering a future move to ECDSA P-256.