Skip to content

How to Check DNS Resolvers Before the Root KSK Rollover

Check the KSK-2024 trust anchor on DNS resolvers using sentinel, interpret SERVFAIL results correctly, and determine when a key update is needed.

•3 min read
Share:
How to Check DNS Resolvers Before the Root KSK Rollover

This guide is for DNS resolver administrators who need to check the DNSSEC root key. Most website owners do not need to change their domain configuration.

Clarify who is responsible

The DNSSEC chain of trust from the root zone to a website

According to Cloudflare’s explanation of the KSK rollover, the planned rollover date is 11 October 2026. KSK-2024, with key tag 38696, will replace KSK-2017 in signing the root zone DNSKEY record set.

DNSSEC-validating resolvers must trust the new key; otherwise, even an operational website may fail to resolve. A trust anchor is a trusted key used to begin validation.

If you are only installing WordPress on cPanel, do not confuse the root key with an administrator password or an HTTPS certificate.

Run checks on the resolver actually in use

Record the address of the resolver serving the client. The browser’s encrypted DNS may use a different resolver from the operating system.

Use dig, replacing IP_RESOLVER with the address you want to check:

``bash dig @IP_RESOLVER root-key-sentinel-is-ta-38696.dnstest.dev. A +noall +comments +answer dig @IP_RESOLVER root-key-sentinel-not-ta-38696.dnstest.dev. A +noall +comments +answer ``

The two queries use RFC 8509 sentinel. The table applies only when the resolver validates DNSSEC and supports sentinel.

Query

Trusts KSK-2024

Does not yet trust KSK-2024

is-ta-38696

Valid response

SERVFAIL

not-ta-38696

SERVFAIL

Valid response

SERVFAIL for not-ta is the expected result when the key is already trusted, not a fault.

Two sentinel queries return opposite results depending on whether the key is trusted

Handle unclear results

If both queries return normal responses, the resolver may not support sentinel. If both fail, check connectivity and DNSSEC validation.

If the key is missing, update the trust anchor according to the software vendor’s instructions. RFC 5011 allows keys to be learned automatically but requires at least 30 days of monitoring. Seeing the key in DNSKEY does not prove that it has been accepted.

Pre-rollover checklist

  • Check every resolver actually in use.

  • Confirm that the key is trusted, not merely present.

  • Check again after an upgrade or server migration: trust anchor state may be lost.

  • When reading a service SLA, identify the party responsible for DNS.

Frequently asked questions

Do I need to update the key if I use 1.1.1.1?

Cloudflare says that 1.1.1.1 and Gateway DNS already trust KSK-2024; users do not need to update it.

Does sentinel check DNSSEC for my own domain?

No. The domain’s DS, DNSKEY, and signatures need to be checked separately.

Further reading

Share: