Live Feed/Cloudflare/Fact Record
Cloudflare logo
Cloudflare
security 96% Confidence Gate September 10, 2026

1.1.1.1 now supports post-quantum DNSSEC, all 2,420 bytes of it

Cloudflare's 1.1.1.1 resolver now supports DNSSEC signature validation using the NIST-standardized ML-DSA-44 post-quantum algorithm. This implementation handles 2,420-byte signature payloads to ensure compatibility with quantum-resistant cryptographic standards.

Verified State Diff

Comparison Mode:
- Previous State
1.1.1.1 only supported classical DNSSEC validation using RSA and ECDSA algorithms.
+ Verified New State
1.1.1.1 supports post-quantum DNSSEC validation using the ML-DSA-44 algorithm with 2,420-byte signature handling.

Impact & Verification Analysis

WHO IS AFFECTED

Network administrators, security engineers, and users relying on DNSSEC-validated resolution.

WHY IT MATTERS

This is a critical step in 'harvest now, decrypt later' defense, ensuring DNS infrastructure remains secure against future quantum-capable adversaries while solving the technical challenge of handling large cryptographic payloads in DNS.

Full Fact Overview

Cloudflare has integrated ML-DSA-44 (Module-Lattice-Based Digital Signature Algorithm) into its 1.1.1.1 DNS resolver to validate DNSSEC signatures. This addresses the vulnerability of traditional RSA and ECDSA signatures to future quantum computing threats. The implementation specifically accounts for the significantly larger 2,420-byte signature size, which exceeds standard DNS packet constraints, by managing fragmentation and potential downgrade attacks to maintain security integrity during the transition period.

Multi-Source Evidence Chain (1)

1.1.1.1 now supports post-quantum DNSSEC, all 2,420 bytes of itCloudflare
TRACKED ENTITY
Explore all historical Cloudflare changes
View Cloudflare Hub ➔