> You publish TLSA RRs for the new one and after the switch you delete the ones for the old one. You can have more than one TLSA RR in a TLSA RRset. Thanks for the explanation. I don't know enough DNSSEC to know if that's actually deployable, but okay