If your trading bot runs on a separate server, checking its DNS readiness starts with finding which resolver that server uses. That's the service that looks up website and service addresses for it.
The DNS root is scheduled to switch signing keys on October 11, 2026. Resolvers that check DNS security signatures need to trust the replacement key. Without it, they could leave users unable to reach otherwise healthy websites.
Cloudflare's browser test at https://dnstest.dev/ksk-2024/ checks whether the resolver your browser uses trusts that key. Run it on your laptop and you're checking the laptop browser's route, potentially affected by Secure DNS or a VPN. A successful result doesn't establish readiness for the bot's server. An inconclusive result can mean the resolver doesn't support the test, rather than that the key is missing.
A past update isn't conclusive either. In its October 6 article, Cloudflare recalls preparations for the 2018 rollover: some resolvers learned to trust the new key, then lost that stored trust during software upgrades or moves between machines. That history explains why ICANN is asking resolver operators to verify the key is present, rather than assume automatic updates succeeded.
Most website owners don't need to change anything. For the bot's server, the question belongs with whoever operates its DNS resolver: does it check those signatures, and if so, does it currently trust the new root key?
Sources:
https://blog.cloudflare.com/root-ksk-2024-rollover/
https://www.icann.org/resources/pages/ksk-rollover-en
Image: AI-generated editorial illustration, not a photograph of an actual provider's facility.
The DNS root is scheduled to switch signing keys on October 11, 2026. Resolvers that check DNS security signatures need to trust the replacement key. Without it, they could leave users unable to reach otherwise healthy websites.
Cloudflare's browser test at https://dnstest.dev/ksk-2024/ checks whether the resolver your browser uses trusts that key. Run it on your laptop and you're checking the laptop browser's route, potentially affected by Secure DNS or a VPN. A successful result doesn't establish readiness for the bot's server. An inconclusive result can mean the resolver doesn't support the test, rather than that the key is missing.
A past update isn't conclusive either. In its October 6 article, Cloudflare recalls preparations for the 2018 rollover: some resolvers learned to trust the new key, then lost that stored trust during software upgrades or moves between machines. That history explains why ICANN is asking resolver operators to verify the key is present, rather than assume automatic updates succeeded.
Most website owners don't need to change anything. For the bot's server, the question belongs with whoever operates its DNS resolver: does it check those signatures, and if so, does it currently trust the new root key?
Sources:
https://blog.cloudflare.com/root-ksk-2024-rollover/
https://www.icann.org/resources/pages/ksk-rollover-en
Image: AI-generated editorial illustration, not a photograph of an actual provider's facility.