Cloudflare Offers DNS Readiness Test Ahead of Root Key Change

Cloudflare is offering a browser test ahead of the DNS root key change scheduled for October 11. Resolvers that lack trust in the replacement could leave users unable to reach otherwise working…

Oct 6, 2026
•
3 min read
Technobezz
Cloudflare Offers DNS Readiness Test Ahead of Root Key Change

Don't Miss the Good Stuff

Get tech news that matters delivered to your inbox.

Cloudflare is offering a browser readiness test ahead of the DNS root’s scheduled key-signing key replacement on October 11, 2026, only its second such change. DNSSEC-validating resolvers must trust the replacement, KSK-2024, before the switch or their users could lose access to websites that are otherwise operating normally. The test checks whether the resolver handling a browser’s requests already trusts that key.

Most people running websites need to make no changes, according to Cloudflare. The company says customers using its domain DNS service, 1.1.1.1 or Gateway DNS need no intervention because those systems already trust KSK-2024. Operators of DNSSEC-validating resolvers should verify that trust themselves and use their software vendor’s instructions to update trust anchors if necessary.

A DNS resolver finds the addresses devices need to connect to websites and other services, while DNSSEC checks signatures to establish that DNS records are authentic and unaltered. Those checks depend on a trusted root key as their starting point; without trust in its replacement, access could fail across any top-level domain. KSK-2024 has key tag 38696 and is due to take over signing the root’s DNSKEY set from KSK-2017, identified by tag 20326.

Cloudflare’s test uses the RFC 8509 sentinel protocol, which the company has implemented in 1.1.1.1, to ask about trust in a particular root key. It also checks responses to ordinary signed records, deliberately invalid records and a query about the existing root key to help establish whether the result is meaningful. A result remains inconclusive when sentinel support cannot be confirmed, rather than establishing that the replacement key is absent. The browser’s resolver choice can depend on Secure DNS or a VPN, so the result reflects the path handling those particular requests.

Resolvers using RFC 5011 can automatically learn replacement trust anchors, but must observe and verify the new key over a waiting period of at least 30 days before accepting it. KSK-2024 has appeared in the root’s DNSKEY set since January 11, 2025. Cloudflare instead included it among its resolver software’s built-in trust anchors in July 2024, after upgrades and machine moves had caused some resolvers to lose learned trust during preparations for the first rollover in 2018.

The replacement changes the key pair while retaining RSA/SHA-256, the algorithm used by both keys. Cloudflare says replacing keys limits the duration of private-key use and tests the work of distributing trust anchors and retiring predecessors. The Internet Assigned Numbers Authority plans an idealized rollover cadence of three years, balancing practice against the effort and risk involved.