DNS root changes its signing key on 11 October; Cloudflare publishes a test for validating resolvers
The DNS root is scheduled to change its key-signing key (KSK) on 11 October 2026, only the second time this has happened. Cloudflare published a guide and a readiness test on 6 October.
What changes. The new key, KSK-2024 with key tag 38696, replaces KSK-2017 (key tag 20326) as the signer of the root's DNSKEY set. A DNSSEC-validating resolver starts its chain of trust from a root key it already trusts. If it does not trust the new key after the switch, Cloudflare writes, its users may be unable to reach websites under any top-level domain, even though the sites themselves are working.

How resolvers learn it. Under RFC 5011 a resolver learns a new root trust anchor automatically, after waiting at least 30 days while the key stays published. KSK-2024 has been in the root's DNSKEY set since 11 January 2025. Cloudflare says that in 2018 some resolvers lost what they had learned during software upgrades or moves between machines, so it added KSK-2024 to its own resolver's built-in trust anchors in July 2024.
Who has to act. Most website operators need to do nothing, and users of 1.1.1.1 and Cloudflare Gateway DNS are covered, according to the post. Anyone running their own validating resolver should check that it trusts KSK-2024 and follow the vendor's instructions to update trust anchors if not.
The test. Cloudflare's readiness page asks the visitor's resolver whether it trusts the new key, using the root key trust anchor sentinel defined in RFC 8509: two specially named domains, is-ta-38696 and not-ta-38696, return an answer or SERVFAIL depending on whether the key is trusted. The resolver has to support the sentinel for the test to say anything.