ICANN publishes updated guide to prepare the Internet community for the next Root KSK rollover
ICANN has released an updated guide outlining what technical operators and the broader Internet community should expect during the next Root Key Signing Key rollover, a routine process designed to maintain the security of the Domain Name System.
The Internet Corporation for Assigned Names and Numbers (ICANN) has published an updated edition of What to Expect During the Root KSK Rollover, providing guidance to DNS operators, researchers, and other stakeholders on preparing for the next rollover of the Root Key Signing Key (KSK) used in the Domain Name System Security Extensions (DNSSEC).
The updated guide, released on 27 July 2026, reflects ICANN’s ongoing efforts to support the security and resilience of the Domain Name System (DNS). It explains the purpose of a Root KSK rollover, outlines the expected process, and identifies practical steps that technical operators should take to ensure their systems continue to function correctly.
The Root KSK is a critical component of DNSSEC, which helps verify the authenticity of DNS information and protects users from being redirected to fraudulent or manipulated websites. Periodically replacing the cryptographic key is considered an important security practice that helps maintain long-term trust in the DNS infrastructure.
The guidance is intended for a broad range of stakeholders, including operators of validating recursive resolvers, members of the technical community, researchers monitoring DNS performance, and journalists covering Internet infrastructure and cybersecurity.
According to ICANN, the rollover is expected to be transparent for most internet users. Systems that use validating recursive resolvers with updated trust anchors should continue to resolve domain names without interruption. However, operators of validating resolvers are advised to confirm that their trust anchors are updated to recognise the new Root KSK. Failure to do so could result in DNS resolution failures once the rollover takes place.
ICANN also highlighted that management of the Root KSK continues through the Internet Assigned Numbers Authority (IANA) functions and publicly conducted KSK ceremonies, which are designed to securely generate, protect, and manage the cryptographic keys. These ceremonies are carried out transparently with participation from the Internet technical community and form an important part of the DNSSEC trust model.
The updated guide is part of ICANN’s broader effort to improve awareness and preparedness across the Internet ecosystem ahead of the next Root KSK rollover.
Why does it matter?
Although Root KSK rollovers are routine and are generally invisible to Internet users, they are a critical component of maintaining the security and integrity of the global Domain Name System. The updated guidance helps ensure that DNS operators are prepared for the transition, reducing the risk of service disruptions while supporting continued trust in the infrastructure
