IANA rotates the DNSSEC root key from KSK-2017 to KSK-2024 on October 11
On October 11, 2026, the DNSSEC root key KSK-2017 (key tag 20326), which has signed the DNS root zone since 2018, stops signing and KSK-2024 (key tag 38696) takes over. Resolvers that missed the RFC 5011 automated trust-anchor update may fail to validate names: strict validation returns SERVFAIL, opportunistic validation silently drops DNSSEC.
- KSK-2024 (key tag 38696) has been published in the root DNSKEY RRset since January 11, 2025
- RFC 5011 needs roughly 30 days of resolver uptime to promote the new trust anchor
- Check with dig . DNSKEY +dnssec — both key tags 20326 and 38696 must appear
- Public resolvers are ready; risk sits with self-hosted Unbound, BIND, Knot and PowerDNS
Read next
Security