Lars-Johan Liman
DNSSEC key rollover

Preparing for the DNS root KSK rollover October 2026

On 11 October 2026, an important change will take place at the heart of the Domain Name System (DNS): the DNSSEC key-signing key (KSK) for the DNS root zone will be rolled over.

For most operators, the change should happen automatically. But because the root KSK provides the starting point for DNSSEC validation across the public DNS, resolver operators should make sure their systems are ready.

As the operator of i-root, one of the Internet’s 13 root name servers, Netnod has more than two decades of experience operating critical DNS infrastructure. Here, we explain what is changing, what the KSK rollover means for DNS operators, and how to check that your resolvers are prepared.
 

What will change on 11 October?

Starting on 11 October  2026, the DNS root zone DNSKEY record set will be signed with a new KSK. This is referred to as a periodic key rollover, and it affects all DNS resolver systems that perform DNSSEC validation on the public Internet. These servers will have to put trust in a new trust anchor – the starting point for all validations. The new key (key tag 38696) is widely published and available in the DNS system, and it has been so since February 2025. Following 11 October 2026, the old key (key tag 20326) will be withdrawn from use and eventually also from publication in the DNS.

How to check whether your resolver is ready?

The new KSK has key tag 38696.

The current-but-soon-to-be-old KSK has key tag 20326.

With some types of resolver software you can already now check whether your server is aware of, and is prepared to trust, the new incoming KSK. Two prevalent types of software are named (from the BIND package) and Unbound. Here are examples of how to check your resolver systems to see the status of their trust anchors:

For named/BIND, use the following command (as root, so you probably have to prefix it with sudo, and keyid in the output denotes the key tag):

Code block 1

Good trusted keys are indicated with "trusted since:".

For Unbound, it's all different. You need to check the root.key file and the word you need to look for is "VALID" in the output (see below). Note that the file name to look in ("/var/lib/unbound/root.key" in the example) may vary between different distributions of Unix/Linux. The command below filters out the interesting lines in that file, but it can easily be inspected with the eye, using other commands. The resulting lines will be very long, so expect line breaks. (id in the output denotes the key tag.)

Code block 2

If you don't see "trusted since:" or "VALID" (or some corresponding assuring signal from other types of software), "now" is a good time to start looking into why your resolver hasn't picked this up.

Should DNS resolver operators expect problems?

Modern DNS resolver software handles KSK rollovers automatically, as long as the new key is properly signed by the old key (which it is). This is in line with the procedures outlined in the Internet Standards document RFC 5011.

Mind you, 11 October happens to be a Sunday. I will put an extra reminder in my calendar!

What will happen at the root servers?

Surprisingly, the DNS root servers themselves are not affected by KSK rollovers, since they neither perform DNSSEC signing, nor validation. They only provide access to the public keys, but they don't use them for anything. That said, Netnod and the other 11 operators of Internet's root servers are well coordinated and remain in close contact with each other, with the IANA, and with the Root Zone Maintainer during this event. This is not so much in anticipation of problems with the performance of the root servers per se (we've been through this before), but more to be vigilant and to be able to notice changes in resolver behaviour on the Internet which may affect end user experiences, and thus to swiftly be able offer expertise and assistance in addressing any such issues.

Lars-Johan Liman
Sr. Systems Specialist and responsible for Netnod DNS root services

Further information

More information about the KSK rollover and the DNS trust anchors can be found at ICANN's and the IANA's web pages:

https://www.icann.org/resources/pages/ksk-rollover-en

https://www.iana.org/dnssec/files

 

Related blog articles

Show all blog articles