The DNS root changes its master key on 11 October. Your resolver has to know it.
By Lior AharonovFounder, 7IT Solutions ·
On Sunday 11 October 2026, the DNS root is scheduled to change the key-signing key that anchors DNSSEC, only the second time ever. KSK-2024 (key tag 38696) replaces KSK-2017 (key tag 20326). Cloudflare warned on Tuesday 6 October that users of a validating resolver that does not trust the new key may be unable to reach sites under any top-level domain.
Picture Monday morning: your site is up, your API is up, and the office network or the container running its own validating resolver can't reach either one. Healthy sites, unreachable. The clock runs out on Sunday.
If you run your own DNSSEC-validating resolver, in an office, a VPC or a container image, check today that it trusts key tag 38696 with the RFC 8509 sentinel test Cloudflare describes. If it does not, update its trust anchors per your vendor's instructions.
DNS changes nobody watches are the ones that page you on a weekend. Ten minutes with dig today beats a Monday of tickets.
Lior Aharonov · my takeSources
- Cloudflare: The keys to the Internet change on October 11. Are you ready? blog.cloudflare.com
Researched with AI tools; every fact is checked against the linked sources.