{"id":36655,"date":"2026-06-08T11:11:12","date_gmt":"2026-06-08T11:11:12","guid":{"rendered":"https:\/\/www.europesays.com\/spain\/36655\/"},"modified":"2026-06-08T11:11:12","modified_gmt":"2026-06-08T11:11:12","slug":"icann86-seville-new-gtld-window-closes-august-12-dnssec-root-key-rollover-due-in-october","status":"publish","type":"post","link":"https:\/\/www.europesays.com\/spain\/36655\/","title":{"rendered":"ICANN86 Seville: New gTLD Window Closes August 12, DNSSEC Root Key Rollover Due in October"},"content":{"rendered":"<p>The 86th Public Meeting of the Internet Corporation for Assigned Names and Numbers opened Monday at the FIBES Conference and Exhibition Centre in Seville, Spain, kicking off four days of policy sessions that carry two hard deadlines every DNS operator and domain applicant needs on their calendar: August 12, when the first new generic top-level domain application window in 14 years closes, and October 11, when ICANN will rotate the DNSSEC root Key Signing Key in the most consequential cryptographic update the global domain name system security chain has seen since the last rollover. Fail to meet either deadline and the cost is concrete \u2014 a missed application window means waiting for the next round, while an unprepared recursive resolver will begin returning SERVFAIL errors for every DNSSEC-validated domain it serves.<\/p>\n<p>The forum, which runs through June 11 in a hybrid format, <a href=\"https:\/\/www.prnewswire.com\/news-releases\/press-release-icann86-policy-forum-brings-global-internet-community-to-seville-302782364.html\" target=\"_blank\" rel=\"noopener nofollow\">was opened<\/a> by ICANN President and CEO Kurtis Lindqvist, who described the event as arriving &#8220;at a time of growing attention to how the Internet is coordinated and how key technical systems operate across borders.&#8221; Spain&#8217;s Secretary of State for Digitalization and Artificial Intelligence, Mar\u00eda Gonz\u00e1lez Veracruz, welcomed the gathering as ICANN&#8217;s second Public Meeting in Spain \u2014 the first was ICANN63 in Barcelona in 2018.<\/p>\n<p>New gTLD 2026 Application Window Closes August 12<\/p>\n<p>The gTLD application window for the 2026 Round opened April 30 and <a href=\"https:\/\/newgtldprogram.icann.org\/en\/application-rounds\/round2\" target=\"_blank\" rel=\"noopener nofollow\">will close at 23:59 UTC on August 12, 2026<\/a> \u2014 leaving organizations approximately ten weeks as of today. The 2026 Round is the first expansion of the domain namespace since the 2012 program, which ultimately produced more than 1,200 new delegated strings including .app, .shop, .bank, and hundreds of others.<\/p>\n<p>The structural mechanics of applying have changed significantly since 2012. Every applicant must now designate at least one pre-evaluated Registry Service Provider \u2014 an RSP, in ICANN&#8217;s terminology \u2014 that will supply the critical backend infrastructure for any TLD they successfully operate. That infrastructure layer covers DNS zone operations, DNSSEC implementation, SLA-compliant uptime guarantees, domain registration data delivered via the Registration Data Access Protocol (RDAP), and security and abuse-response obligations. <a href=\"https:\/\/newgtldprogram.icann.org\/en\/application-rounds\/round2\/rsp\" target=\"_blank\" rel=\"noopener nofollow\">The RSP Evaluation Program<\/a> separates technical infrastructure assessment from individual domain-label applications, meaning a qualified RSP is evaluated once and can then support multiple gTLD bids across applicants. ICANN published its initial list of cleared RSPs on January 30, 2026 and a second evaluation period running concurrently with the application window opened April 30.<\/p>\n<p>The Governmental Advisory Committee placed the new gTLD program among its primary discussion items for the week. The GAC is expected to weigh in on public interest protections, objection mechanisms, and whether proposed new strings adequately safeguard community interests \u2014 positions that ICANN&#8217;s board is formally obligated to consider before evaluating applications. The GAC&#8217;s communiqu\u00e9, expected June 11 at the forum&#8217;s close, will represent governments&#8217; collective stance entering the final stretch of the application window.<\/p>\n<p>One significant policy change since 2012 bears noting: the ICANN Board decided in January 2024 that &#8220;closed generic&#8221; TLD applications \u2014 single-registrant domains for generic terms like .search or .music \u2014 will not be permitted in the 2026 round unless an approved framework is first developed to assess their compatibility with the public interest. That decision emerged from a multi-year facilitated dialogue involving the GAC, GNSO, and At-Large Advisory Committee.<\/p>\n<p>How Does the DNSSEC Root Key Rollover Work, and Why Does It Matter?<\/p>\n<p>Every time a user visits a website, their device asks a recursive resolver \u2014 a DNS lookup service operated by their internet service provider, employer, or cloud platform \u2014 to translate a domain name into an IP address. If that resolver performs DNSSEC validation, it also verifies that every DNS response it receives hasn&#8217;t been forged or tampered with by an attacker. That verification traces a cryptographic chain of trust that starts at the root of the DNS hierarchy.<\/p>\n<p>The chain works through two interlocking key types at each zone level. The Zone Signing Key (ZSK) signs the actual DNS resource records within a zone \u2014 the A records, MX records, and CNAME records that direct traffic. The Key Signing Key (KSK) signs only the DNSKEY record set, which publishes both public keys for that zone, and its cryptographic fingerprint \u2014 called a Delegation Signer (DS) record \u2014 is stored in the parent zone above it. Validating resolvers hold the root zone&#8217;s KSK public key as a hardcoded trust anchor. When a resolver receives a DNS response, it traces signatures upward: the ZSK verifies zone records, the KSK verifies the ZSK&#8217;s identity, and the parent zone&#8217;s DS record verifies the child KSK&#8217;s legitimacy \u2014 all the way up to the root.<\/p>\n<p>The root KSK currently in use \u2014 KSK-2017 \u2014 is being replaced by KSK-2024, a new key pair that ICANN generated in April 2024 and formally published in the root zone on January 11, 2025, according to a <a href=\"https:\/\/blog.verisign.com\/security\/2024-2026-root-zone-ksk-rollover-initial-observations\/\" target=\"_blank\" rel=\"noopener nofollow\">Verisign analysis<\/a> by Duane Wessels, a Verisign fellow specializing in DNS security. On October 11, 2026, KSK-2024 will begin signing the root zone. The old key will remain valid during a parallel operation window until January 2027, giving resolver operators time to complete updates before the retirement date.<\/p>\n<p>Operators have two primary paths to compliance. Resolvers running software that supports <a href=\"https:\/\/www.icann.org\/dns-resolvers-checking-current-trust-anchors\" target=\"_blank\" rel=\"noopener nofollow\">RFC 5011<\/a> \u2014 the IETF-standardized automated trust anchor update mechanism \u2014 will update their trust anchor stores automatically once the new key has been present in the DNSKEY RRset for at least 30 days. Modern versions of BIND (9.9 and later), Knot Resolver, and Unbound 1.6.2+ all support RFC 5011. Operators running older software, or those who manually configured their trust anchors rather than relying on automated updates, must act directly. According to <a href=\"https:\/\/www.prnewswire.com\/news-releases\/press-release-icann-announces-next-major-internet-security-update-302776784.html\" target=\"_blank\" rel=\"noopener nofollow\">ICANN&#8217;s official announcement<\/a>, failure to update will produce DNS resolution failures after the rollover \u2014 specifically, DNSSEC-validated domains will return SERVFAIL errors for end users served by unready resolvers.<\/p>\n<p>Kim Davies, ICANN&#8217;s Vice President for Internet Assigned Numbers Authority Services and President of Public Technical Identifiers, said operators should act now: &#8220;While most internet users will not notice any change, operators of DNS software should confirm that their systems are properly configured to trust the new key ahead of the rollover.&#8221;<\/p>\n<p>The Verisign analysis found that trust anchor adoption of KSK-2024 had reached near-100% among monitored resolvers, but noted that a small population of manually configured resolvers remains a risk category, since the RFC 5011 automatic update process requires the new key to have been continuously observed for at least 30 days. ICANN&#8217;s DNSSEC Security Workshop, one of the week&#8217;s highlighted technical sessions at ICANN86, is expected to address rollover readiness, validator adoption rates, and what the community can do to reduce the chance of resolution failures when October arrives.<\/p>\n<p>DNS Abuse, RDAP Access, and Universal Acceptance<\/p>\n<p>Three secondary policy tracks will run through the working sessions in Seville all week.<\/p>\n<p>On DNS abuse, ICANN&#8217;s enforcement data illustrates both the progress and the remaining gap. Between April 2024 and August 2025, ICANN Contractual Compliance initiated 400 investigations under the DNS abuse mitigation requirements that took effect in April 2024, resulting in the suspension of 2,528 domain names and the disabling of 328 phishing websites. The GNSO&#8217;s newly launched Policy Development Process on DNS Abuse Mitigation is active and meets in Seville \u2014 it is examining whether registrars should face requirements to conduct associated domain checks when one domain in a related cluster is confirmed abusive. A new dimension the forum must also address: AI tools that generate convincing phishing sites at scale, automate registrations across thousands of accounts, and outpace human review cycles. ICANN&#8217;s existing framework was designed for abuse operating at human scale, and the gap between that assumption and current reality is on the plenary agenda.<\/p>\n<p>On registration data access, the formal transition from WHOIS to RDAP \u2014 the <a href=\"https:\/\/www.ionos.com\/digitalguide\/domains\/domain-news\/whois-sunset\/\" target=\"_blank\" rel=\"noopener nofollow\">Registration Data Access Protocol<\/a> \u2014 became mandatory for gTLD registries on January 28, 2025. RDAP returns machine-readable JSON rather than WHOIS&#8217;s unstructured text, enforces tiered access controls, and integrates with GDPR-compliant data minimization. The forum&#8217;s agenda includes continuation of the GNSO&#8217;s Supplemental Recommendations on the System for Standardized Access and Disclosure \u2014 the framework intended to give law enforcement, intellectual property holders, and cybersecurity researchers structured access to non-public registrant data that GDPR restrictions removed from public WHOIS queries.<\/p>\n<p>On Universal Acceptance, millions of domain names using non-Latin scripts or new TLD strings are still mishandled by applications, email systems, and authentication services that haven&#8217;t been updated. As the 2026 gTLD round is expected to introduce more Internationalized Domain Names in Arabic, Chinese, Cyrillic, and other scripts, the software ecosystem&#8217;s readiness becomes urgent for the communities those new domains are meant to serve.<\/p>\n<p>ICANN Multistakeholder Model Convenes on Policy Development<\/p>\n<p>ICANN&#8217;s governance structure is distinctive: unlike treaty-based intergovernmental organizations, it coordinates through a multistakeholder process where technical experts, civil society, commercial interests, and governments each hold formal roles without any single party holding unilateral authority. Policy Forum meetings are explicitly designed for working-group-level policy development rather than high-ceremony announcements, meaning much of the consequential work in Seville will happen in committee rooms \u2014 in GNSO stakeholder sessions, advisory committee deliberations, and the fine-grained drafting of rule language that will govern who receives a new TLD, under what conditions, and with what ongoing obligations attached.<\/p>\n<p>ICANN has extended invitations through its NextGen@ICANN and Fellowship programs to students and early-career professionals, part of a sustained effort to build internet governance expertise in regions historically underrepresented in global policy processes.<\/p>\n<p>The GAC&#8217;s communiqu\u00e9, expected June 11, will carry governments&#8217; collective positions on the 2026 gTLD round and DNS abuse policy \u2014 formal advice the ICANN board is obligated to consider before proceeding. Sessions are open to remote participants at icann86.sched.com. Organizations that have not yet begun DNSSEC trust anchor readiness checks face a four-month window before October 11 resolvers with manual configurations or outdated software start failing. For domain applicants, the window is shorter: the August 12 deadline is absolute, and the next opportunity will not come for years.<\/p>\n<p>Frequently Asked Questions<\/p>\n<p>What is the ICANN new gTLD 2026 application deadline?<\/p>\n<p>The application window for the New gTLD Program 2026 Round opened on April 30, 2026 and will close at 23:59 UTC on August 12, 2026. This is the first expansion of generic top-level domains since the 2012 round, which produced more than 1,200 new domain strings. Organizations that miss the August 12 deadline will need to wait for a future ICANN round.<\/p>\n<p>How do I prepare for the DNSSEC trust anchor rollover in 2026?<\/p>\n<p>Resolver operators should verify their software supports RFC 5011 automated trust anchor updates \u2014 modern BIND, Knot Resolver, and Unbound installations handle this automatically. Operators using manually configured trust anchors or older DNS software must update their trust anchor stores before October 11, 2026, when KSK-2024 begins signing the root zone; failure to do so will result in DNS resolution failures (SERVFAIL errors) for DNSSEC-validated domains.<\/p>\n<p>What is DNSSEC and why does the root Key Signing Key matter?<\/p>\n<p>DNSSEC adds cryptographic signatures to DNS responses, allowing validating resolvers to confirm that records haven&#8217;t been forged in transit. The root Key Signing Key (KSK) sits at the top of this verification chain; it signs the DNSKEY record set for the entire root zone, and its public key is hardcoded as a trust anchor in all DNSSEC-validating resolver software. When ICANN rotates the root KSK, every validating resolver that hasn&#8217;t adopted the new key loses the ability to verify DNS signatures, making domain names unreachable for users on those resolvers.<\/p>\n<p>What decisions is the ICANN86 Seville forum expected to produce?<\/p>\n<p>The forum will not finalize TLD applications \u2014 it is a policy development meeting, not an approval event. The most significant expected output is the Governmental Advisory Committee communiqu\u00e9 on June 11, which will state governments&#8217; collective positions on the 2026 gTLD round and DNS abuse policy. ICANN&#8217;s board is formally obligated to consider those positions before proceeding with the evaluation cycle.<\/p>\n","protected":false},"excerpt":{"rendered":"The 86th Public Meeting of the Internet Corporation for Assigned Names and Numbers opened Monday at the FIBES&hellip;\n","protected":false},"author":2,"featured_media":36656,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[7],"tags":[439,17679,17680,17682,17681,15347,1477,109,17683],"class_list":["post-36655","post","type-post","status-publish","format-standard","has-post-thumbnail","category-seville","tag-cybersecurity","tag-dns","tag-dnssec","tag-domain-registration","tag-gtld","tag-icann","tag-internet","tag-seville","tag-verisign"],"_links":{"self":[{"href":"https:\/\/www.europesays.com\/spain\/wp-json\/wp\/v2\/posts\/36655","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.europesays.com\/spain\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.europesays.com\/spain\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/spain\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/spain\/wp-json\/wp\/v2\/comments?post=36655"}],"version-history":[{"count":0,"href":"https:\/\/www.europesays.com\/spain\/wp-json\/wp\/v2\/posts\/36655\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/spain\/wp-json\/wp\/v2\/media\/36656"}],"wp:attachment":[{"href":"https:\/\/www.europesays.com\/spain\/wp-json\/wp\/v2\/media?parent=36655"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.europesays.com\/spain\/wp-json\/wp\/v2\/categories?post=36655"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.europesays.com\/spain\/wp-json\/wp\/v2\/tags?post=36655"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}