The DNS root changes its key on 11 October and will silence frozen resolvers
On 11 October 2026 the DNS root zone replaces its key-signing key KSK-2017 with KSK-2024, the second rollover since the root was first signed in 2010. Any DNSSEC-validating resolver that does not already trust the new key will stop resolving every name: the job is to find, before Sunday, the resolvers whose trust anchor has been frozen.