7IT · News

The DNS root changes its master key on 11 October. Your resolver has to know it.

By Lior AharonovFounder, 7IT Solutions ·

What happened

On Sunday 11 October 2026, the DNS root is scheduled to change the key-signing key that anchors DNSSEC, only the second time ever. KSK-2024 (key tag 38696) replaces KSK-2017 (key tag 20326). Cloudflare warned on Tuesday 6 October that users of a validating resolver that does not trust the new key may be unable to reach sites under any top-level domain.

Why it matters

Picture Monday morning: your site is up, your API is up, and the office network or the container running its own validating resolver can't reach either one. Healthy sites, unreachable. The clock runs out on Sunday.

What to do

If you run your own DNSSEC-validating resolver, in an office, a VPC or a container image, check today that it trusts key tag 38696 with the RFC 8509 sentinel test Cloudflare describes. If it does not, update its trust anchors per your vendor's instructions.

DNS changes nobody watches are the ones that page you on a weekend. Ten minutes with dig today beats a Monday of tickets.

Lior Aharonov · my take

Sources

dnsdnssecinfrastructureoutage-risk

Researched with AI tools; every fact is checked against the linked sources.

All 7IT news · Atom feed

Need a hand with something like this? Talk to 7IT.