WORLDTECH NEWS Global technology intelligence.
← Back to WORLDTECH
Cybersecurity

1.1.1.1 now supports post-quantum DNSSEC, all 2,420 bytes of it

Padlock on the floor of a server room beside cabled switchesAI illustration
WORLDTECH illustration Β· AI-generated (Canva)

What happened

A validating resolver such as 1.1.1.1 follows a chain of signed records from the DNS root to the requested domain, checking that the answer is authentic and has not been modified. This is a first step toward preparing DNSSEC for a future in which today’s signature algorithms are no longer secure.

Much of the work so far has focused on TLS, but public-key cryptography is used in many other systems, including DNSSEC. Each ML-DSA-44 signature is 2,420 bytes, exceeding common DNS-over- UDP limits before the response contains anything else.

The challenge is carrying these much larger responses reliably, without allowing compatibility with older resolvers to weaken protection for newer ones. Why post-quantum DNSSEC matters DNS responses are not authenticated by default.

Key facts

  • Each ML-DSA-44 signature is 2,420 bytes, exceeding common DNS-over- UDP limits before the response β€” includes: anything else

Sources & evidence