Under normal circumstances, a DNSSEC key rollover is transparent to end users. The transition from one key to another is handled automatically by DNS and DNSSEC-validating resolvers, provided that the zone operator properly manages the rollover process and publishes the required key information in DNS.