Skip to content
Sign in

Trust anchors

A validating resolver starts from this key: the key that signs the DNSKEY set of the GOpenCDR root.

Root KSK 46714

Algorithm 13, published 28 September 2026
DS
. IN DS 46714 13 2 1519B9AC6BF0DB14F467EB33E46384AE170EFA9D66660D5B01C141049592B89C
DNSKEY
. IN DNSKEY 257 3 13 qXdp/XtrE70h5TPf26nvTSW8db6hVd4VFAicBWLYgn7PvKlY+Nk5lUrioM7bqUQbuISbqep5xdDuvzZnHn8/rg==
root-anchors.xmlroot-anchors.jsonSignature

Check it yourself

The same key is on this page, in transparency log entry 21, and in the root zone itself. With BIND's tools, from any computer:

dig @ns1.cdr.gplatform.org . DNSKEY +noall +answer | dnssec-dsfromkey -f - .
Expected output
. IN DS 46714 13 2 1519B9AC6BF0DB14F467EB33E46384AE170EFA9D66660D5B01C141049592B89C

The files are signed with the anchor bundle key cdr.gplatform.org/anchors+128b735b+AT1Opgaqy4oVJDHakR6OlSVHxZcOpD3Xe/Kh9NAs88Jt. They name the transparency log cdr.gplatform.org/tlog, whose checkpoints are signed with cdr.gplatform.org/tlog+4fa558fc+AYRwZ0KSEaaWcNsS6rExAM3aGE4Ru5wIqtRxReRWnptA.

Rollover schedule

None scheduled. The root KSK rolls every two years under the timers of RFC 5011, the first time within 12 months of launch, as P-2 sets out.