DNS Root KSK-2024 Rollover and Readiness Test
π On October 11, 2026 the DNS root will replace its key-signing key (KSK) with KSK-2024 (key tag 38696). Most site operators need take no action, but operators of DNSSEC-validating resolvers must ensure their trust anchors include KSK-2024 before the switch to avoid service outages. Cloudflareβs resolvers already include the new key and offer a RFC 8509-based readiness test at dnstest.dev to check whether the resolver your browser uses trusts the new root key. The post explains KSK vs ZSK roles, RFC 5011 automatic updates, and why embedding the new anchor in resolver software helps avoid issues seen during the 2018 rollover.
