Important heads-up for DNSSEC operators: root zone KSK rollover is 11 October

Check that your systems are ready

Digital padlock behind binary code

On 11 October, the root zone will roll over to a new KSK pair. In other words, ICANN is replacing the root zone's cryptographic key pair, which underpins the entire DNSSEC infrastructure. Therefore, before 11 October, organisations that operate DNSSEC-validating recursive resolvers, DNS software suppliers and operators that have manually configured trust anchors need to check that their systems are ready for the switch.

Rollover is a standard security measure, but entails risk

The root KSK is the cryptographic key that secures the root zone of the Domain Name System (DNS) by means of DNSSEC. Periodically changing the key is a standard security measure that helps to safeguard the long-term security and resilience of the DNS. Nevertheless, the rollover does entail certain significant risks. Although it’s very unlikely that anything will go wrong, an error could potentially render all internet domains (including unsigned domains) unreachable for all users and applications that rely on validating resolvers.

The situation is similar at the local level. Validating resolver operators need to first add the new (public) key to the trust anchors on their servers, and subsequently remove the old key from their systems. If an operator fails to act, it won't be possible to validate any digital signatures beneath the top-level domains (TLDs) in the root zone. Then all internet domains will become unreachable for everyone relying on the resolver in question.

Check that your systems are ready

We advise organisations that operate DNSSEC-validating recursive resolvers to read ICANN’s guide, check their system configurations and perform all the necessary tests before 11 October 2026. The guide and supporting technical information are available on ICANN’s web page about the root zone KSK rollover.