Mahdi RajaeeJournal
Back to the journalSecurity

1.1.1.1 now supports post-quantum DNSSEC, all 2,420 bytes of it

ML-DSA-44 validation for DNSSEC is enabled on 1.1.1.1 to test post-quantum signatures at scale.

The change

Previously

DNSSEC validation on 1.1.1.1 used conventional algorithms; ML-DSA-44 was not validated.

With this change

1.1.1.1 now validates ML-DSA-44 signatures and applies a downgrade protection policy via DS records.

What it means

Measurable increase in DNSSEC signature verification load.

My take

This is an incremental ecosystem-wide test to gather operational data before full deployment.

At the source

Each ML-DSA-44 signature is 2,420 bytes, exceeding common DNS-over- UDP limits before the response includes anything else.

1.1.1.1 deliberately applies a more restrictive local validation policy.

Cloudflare Engineeringblog.cloudflare.com