On 11 October 2026 the key that signs the root zone of the domain name system is replaced. It sits at the very top of the chain of trust: every check that a site’s name has not been forged begins there.
This is only the second time it has happened. The first was in 2018.
The new key is called KSK-2024, its tag is 38696, and it has been published in the root zone since 11 January 2025. That is a year and nine months of notice, not a surprise.
What happens to anyone who missed it? A resolver that validates signatures and does not hold the new key on 11 October does not fail on one site. It stops resolving names altogether, and the person using it sees a working network in which nothing opens.
ICANN says more than 95 per cent of the resolvers that report in already recognise the new key. The rest are the problem.
Who actually has to act? Three groups: anyone operating a validating resolver, the makers of DNS software, and anyone who configured a trust anchor by hand. A reader using whatever resolver arrives from their provider or their home router is the provider’s responsibility, not their own.
One exception is worth naming: if you have set up an ad-blocker or a name server at home and switched validation on, check its configuration before the date, because your machine will go dark while your neighbour’s keeps working.
ICANN published its preparation guidance on 11 August 2026, and IANA updated its rollover guide on 27 July 2026.
Photograph: an optical fibre patch panel at an internet exchange. By Fabienne Serriere, CC BY-SA 3.0 via Wikimedia Commons.
Source: ICANN’s own announcement and blog on the root zone KSK rollover · the IANA rollover guide.
Kuwait One, once a week.
The most useful stories we published this week, in your inbox.
No spam. Unsubscribe anytime.

