1.1.1.1 now supports post-quantum DNSSEC, all 2,420 bytes of it
Cloudflare's 1.1.1.1 resolver now supports DNSSEC signature validation using the NIST-standardized ML-DSA-44 post-quantum algorithm. This implementation handles 2,420-byte signature payloads to ensure compatibility with quantum-resistant cryptographic standards.
Verified State Diff
Impact & Verification Analysis
Network administrators, security engineers, and users relying on DNSSEC-validated resolution.
This is a critical step in 'harvest now, decrypt later' defense, ensuring DNS infrastructure remains secure against future quantum-capable adversaries while solving the technical challenge of handling large cryptographic payloads in DNS.
Full Fact Overview
Cloudflare has integrated ML-DSA-44 (Module-Lattice-Based Digital Signature Algorithm) into its 1.1.1.1 DNS resolver to validate DNSSEC signatures. This addresses the vulnerability of traditional RSA and ECDSA signatures to future quantum computing threats. The implementation specifically accounts for the significantly larger 2,420-byte signature size, which exceeds standard DNS packet constraints, by managing fragmentation and potential downgrade attacks to maintain security integrity during the transition period.