The DNS root key rollover is scheduled for October 11, 2026. ICANN and IANA are asking operators of DNSSEC-validating resolvers to check that their systems trust the successor key. For most website owners, the practical step is to confirm who manages DNS resolution for their network, rather than change their domain’s records.
What changes on October 11
The root key-signing key is a trusted starting point for checking signed DNS data. During this rollover, KSK-2024 is scheduled to replace KSK-2017 as the key that signs the root zone’s key set. This is planned cryptographic maintenance, not a change of domain ownership, registrar or website hosting.
ICANN published preparation guidance on August 11, following its July 27 operational guide. The October date is the scheduled transition; it is not an event that has already happened.
Who needs to check readiness
The preparation work belongs to organizations operating recursive resolvers that validate DNSSEC, including Internet service providers and enterprise network teams. IANA identifies KSK-2024 with key tag 38696. Operators should verify that it is present in their trust-anchor configuration and follow their resolver vendor’s update instructions if it is missing.
Software updates and automated trust-anchor updates can provide the new key, but enabling automation is not proof that an update succeeded. This article does not verify any particular provider’s configuration.
What website owners should expect
ICANN expects the vast majority of users to be unaffected. Prepared resolvers should continue working normally. An unprepared validating resolver can fail to resolve domain names after the transition; caching and configuration affect when problems appear. That can make a website seem unavailable to one visitor while another can still reach it.
- If another company manages your network’s DNS resolution, ask that provider or your IT team about readiness.
- If your organization runs its own validating resolvers, have their operator check the trust anchors before October 11.
- Do not change nameservers, website addresses or mail records merely because of this root-key notice. Those settings do not update a recursive resolver’s root trust anchor.
Keep the two DNS roles separate
Publishing your domain’s DNS records and validating DNS answers for network users are different jobs. The rollover notice concerns the latter. Our earlier coverage of community oversight of root DNSSEC key ceremonies provides background on how this infrastructure is supervised.
For questions about your NicNames domain or services, contact NicNames support. Questions about a third-party network’s recursive resolvers belong with that network’s operator.


