1.1.1.1 now supports post-quantum DNSSEC, all 2,420 bytes of it
ML-DSA-44 validation for DNSSEC is enabled on 1.1.1.1 to test post-quantum signatures at scale.
The change
Previously
DNSSEC validation on 1.1.1.1 used conventional algorithms; ML-DSA-44 was not validated.
With this change
1.1.1.1 now validates ML-DSA-44 signatures and applies a downgrade protection policy via DS records.
What it means
Measurable increase in DNSSEC signature verification load.
My take
This is an incremental ecosystem-wide test to gather operational data before full deployment.
At the source
“Each ML-DSA-44 signature is 2,420 bytes, exceeding common DNS-over- UDP limits before the response includes anything else.”
“1.1.1.1 deliberately applies a more restrictive local validation policy.”
Cloudflare Engineeringblog.cloudflare.com