The Root KSK Rollover scheduled for October 11, 2026, will introduce an important change to the security infrastructure behind the global Domain Name System (DNS). ICANN plans to activate KSK-2024 during the rollover as part of its ongoing DNSSEC security management.
Most domain owners and internet users should not notice any visible change. However, organizations that operate DNSSEC-validating resolvers need to check their systems before the scheduled rollover.
ICANN has published the new KSK in advance so DNS operators can update their trust-anchor configurations and test their systems before the change takes place.
Why Is ICANN Changing the Root KSK?
ICANN periodically replaces the Root KSK as part of its cryptographic key-management process.
The first Root KSK rollover occurred in October 2018. The 2026 event will mark the second major Root KSK rollover.
ICANN has spent several years preparing for the upcoming change. The organization published KSK-2024 in the DNS well before the October 2026 rollover. This approach gives DNS resolver operators time to recognize the new key and update their trust-anchor configurations.
The phased process also gives operators an opportunity to test their systems and identify configuration problems before the rollover date.
What Will Happen on October 11, 2026?
On October 11, 2026, KSK-2024 will begin signing the DNS root zone.
The existing KSK will continue through the transition before ICANN revokes the old key in January 2027.
The change will happen at the DNS root level. ICANN will not replace the individual DNSSEC keys for every domain on the internet.
Instead, DNSSEC-validating recursive resolvers will need to recognize KSK-2024 as a valid trust anchor. These resolvers will then continue validating DNS information after the rollover.
Will Normal Domain Owners Notice the Change?
Most domain owners and internet users should not notice any difference.
ICANN expects the rollover to happen without disruption for users whose DNS resolvers correctly recognize the new key.
A domain owner who uses a standard registrar and managed DNS service will usually not need to change anything.
However, businesses that operate their own DNS infrastructure should check their systems before October 11. Their IT teams should confirm that their DNS software can recognize KSK-2024 and update trust-anchor information correctly.
Who Needs to Pay Attention?
The Root KSK rollover matters most to organizations that operate DNS infrastructure.
These organizations include:
- Internet service providers
- Enterprise network administrators
- DNS resolver operators
- Managed DNS providers
- Organizations that operate recursive resolvers
- DNS software developers
- System administrators
- Organizations that manually configure DNSSEC trust anchors
ICANN recommends that DNSSEC-validating resolver operators verify that KSK-2024 exists in their trust-anchor configuration.
Organizations should not assume that their systems will automatically update correctly. They should verify the configuration and test DNSSEC validation before the rollover.
What Happens If a Resolver Does Not Recognize KSK-2024?
A DNSSEC-validating resolver that does not recognize the new KSK could reject valid DNS responses after the rollover.
When this happens, users who rely on that resolver could experience DNS resolution problems. Websites and online services could become difficult or impossible to reach from affected networks.
The problem would not necessarily come from the domain itself. Instead, the resolver could fail because it does not trust the new Root KSK.
This situation makes preparation particularly important for organizations that operate their own DNS resolvers.
What Should DNS Operators Check?
DNS operators should start by checking their trust-anchor configuration and confirming that it contains KSK-2024.
ICANN identifies KSK-2024 with Key Tag 38696.
DNS operators should also complete the following checks:
- Confirm that their DNS software supports automatic trust-anchor updates.
- Check whether automatic updates work correctly.
- Look for manually configured trust anchors.
- Confirm that the system can store the new trust-anchor information.
- Test DNSSEC validation before the rollover.
- Review technical guidance from their DNS software vendor.
- Monitor DNS resolution during and after the rollover.
These checks can help organizations identify configuration problems before they affect users.
What About Registrars and Domain Owners?
The Root KSK rollover does not require registrars to replace individual domain names, nameservers or domain-level DNSSEC keys.
The Root KSK operates at the DNS root level, while individual domains can use their own DNSSEC keys.
Domain owners who use DNSSEC should still make sure that their registrar and DNS provider maintain the correct configuration.
Businesses should also identify the company or IT team responsible for their recursive DNS infrastructure. This step becomes particularly important when a company operates internal DNS resolvers.
If an organization manually manages DNSSEC trust anchors, its technical team should review the configuration before October 11, 2026.
KSK Rollover vs. KSK Algorithm Rollover
Domain professionals should distinguish the 2026 Root KSK rollover from ICANN’s separate Root KSK algorithm rollover project.
The October 2026 event will replace the active Root KSK while the current cryptographic algorithm remains in use.
ICANN is separately studying a future change to the algorithm used by the Root KSK. That project could eventually move the DNSSEC root from RSA/SHA-256 to another cryptographic algorithm.
Therefore, the October 2026 event does not represent the Root KSK algorithm change.
Keeping these two projects separate will help domain owners, DNS operators and technology writers avoid confusion when discussing ICANN’s DNSSEC plans.
Why the 2026 Rollover Matters for the Domain Industry
The DNS provides one of the internet’s most important infrastructure layers. Every day, DNS helps users connect domain names with the servers that host websites, applications and online services.
The Root KSK provides an important security foundation for DNSSEC validation.
The 2026 rollover therefore demonstrates how ICANN and DNS operators maintain the security infrastructure behind domain names.
For the domain industry, the event also highlights the importance of DNS security. Registering a domain represents only one part of operating a reliable online service. DNS hosting, authoritative nameservers, recursive resolvers and DNSSEC all play important roles.
Businesses that depend on their websites should understand which organizations manage each part of their DNS infrastructure.
What Should Domain Owners Do Now?
Most individual domain owners do not need to make major changes.
However, businesses can take a few simple steps before the rollover.
Domain owners should:
- Identify their DNS provider.
- Ask their DNS provider whether it has prepared for the Root KSK rollover.
- Confirm that DNSSEC works correctly if they use it.
- Identify who operates their recursive DNS resolvers.
- Ask their IT team whether any systems use manually configured trust anchors.
- Keep registrar and DNS-provider contact information updated.
- Monitor important websites and online services around October 11.
- Follow official ICANN guidance as the rollover approaches.
Organizations that operate their own recursive resolvers should follow ICANN’s technical documentation and test their systems rather than relying on assumptions.
Final Thoughts
The ICANN 2026 Root KSK rollover represents an important update to the security infrastructure behind the global DNS.
ICANN plans to activate KSK-2024 on October 11, 2026, while the organization expects the old key to remain part of the transition until January 2027.
Most domain owners and internet users should experience no visible change. DNSSEC-validating recursive resolver operators, however, need to verify their configurations and confirm that their systems recognize the new key.
KSK-2024 carries Key Tag 38696, which operators can use when checking their trust-anchor configuration.
The 2026 Root KSK rollover also differs from ICANN’s separate proposal to change the DNSSEC Root KSK algorithm in the future.
For domain owners, hosting companies, registrars and DNS administrators, the key message is simple: check your DNS infrastructure before October 11, 2026, and follow ICANN’s official technical guidance.
To know more on ICANN News click herehttps://domainera.net/icann-dns-abuse-registrar-terminated-phishing/
DNS Security DNSSEC ICANN Root KSK Rollover
Last modified: September 16, 2026
