1.1.1.1 now supports post-quantum DNSSEC, all 2,420 bytes of it
- ID
- 23166
- Status
- summarized
- Published
- 10 Sep 2026, 9:00 PM
- Fetched
- 10 Sep 2026, 10:16 PM
- Provider
- Cloudflare Blog
- Category
- infrastructure
- Original URL
- https://blog.cloudflare.com/post-quantum-dnssec-1111/
- Source URL
- https://blog.cloudflare.com/rss/
Summary
- Score
- 5.5
- Created
- 10 Sep 2026, 10:17 PM
- Tags
- Audience
- developerssaas_founders
What happened
Cloudflare's 1.1.1.1 resolver now validates DNSSEC signatures using ML-DSA-44, a NIST-standardized post-quantum algorithm. This tests internet-scale handling of 2,420-byte signatures that exceed standard DNS-over-UDP limits and helps prevent downgrade attacks to older algorithms.
Why it matters
Builders running custom DNS infrastructure or resolvers should anticipate the impact of 2,420-byte post-quantum signatures on UDP packet limits and start planning for similar migrations, as Cloudflare targets full post-quantum security by 2029.
Discussion angle
How will the 2,420-byte signature size break existing DNS-over-UDP assumptions in your own infrastructure, and what engineering work is needed to handle it?