The internet's master trust key is about to change for only the second time ever.
On October 11, 2026, the DNS root will swap its key-signing key, the cryptographic anchor of DNSSEC's chain of trust, replacing KSK-2017 with a new key called KSK-2024. Resolvers that validate DNSSEC need to already trust the new key, identified by key tag 38696, or some websites could become unreachable even though they are working fine. The replacement key has been published alongside the old one since January 2025, giving resolvers time to pick it up automatically under the internet standard that governs trust-anchor updates. Cloudflare says its own 1.1.1.1 and Gateway DNS resolvers already trust KSK-2024, because the company built the new key into its software back in July 2024 instead of waiting for resolvers to learn it on their own.
This is not a routine update. The last rollover, in 2018, ran into trouble when Cloudflare found resolvers losing their learned trust anchors during software upgrades or server moves. A botched rollover does not break the cryptography, it just makes parts of the internet quietly vanish for anyone whose resolver missed the update, which is why Cloudflare is also offering a public test, built on a standard called RFC 8509, so operators can check their resolver's trust before the switch instead of after.
Eight years after the first rollover, the root is still signing with the same RSA method it started with, so the hard part here is logistics, not cryptography.