1.1.1.1 now supports post-quantum DNSSEC, all 2,420 bytes of it
Requested translation is not available. Showing the stored EN version.
What happened
A validating resolver such as 1.1.1.1 follows a chain of signed records from the DNS root to the requested domain, checking that the answer is authentic and has not been modified. This is a first step toward preparing DNSSEC for a future in which todayβs signature algorithms are no longer secure.
Much of the work so far has focused on TLS, but public-key cryptography is used in many other systems, including DNSSEC. Each ML-DSA-44 signature is 2,420 bytes, exceeding common DNS-over- UDP limits before the response contains anything else.
The challenge is carrying these much larger responses reliably, without allowing compatibility with older resolvers to weaken protection for newer ones. Why post-quantum DNSSEC matters DNS responses are not authenticated by default.
Key facts
- Each ML-DSA-44 signature is 2,420 bytes, exceeding common DNS-over- UDP limits before the response β includes: anything else
Sources & evidence
- Cloudflare Blog Primary / official
1.1.1.1 now supports post-quantum DNSSEC, all 2,420 bytes of it β
https://blog.cloudflare.com/post-quantum-dnssec-1111/