Cloudflare Adopts Post-Quantum ML-DSA-44 for DNSSEC Validation

Cloudflare has announced that its 1.1.1.1 public DNS resolver now validates DNSSEC signatures using the post-quantum ML-DSA-44 algorithm. This step, revealed on September 10, 2026, represents one of the first practical applications of a NIST-approved post-quantum cryptographic standard in DNS infrastructure.

What Happened

Cloudflare’s 1.1.1.1 DNS resolver, a popular service for secure and private internet browsing, has integrated the ML-DSA-44 algorithm for DNSSEC validation. DNSSEC (Domain Name System Security Extensions) ensures the authenticity of DNS data, protecting users from threats like DNS spoofing. By adopting ML-DSA-44, a post-quantum cryptographic algorithm approved by the National Institute of Standards and Technology (NIST), Cloudflare is preparing its infrastructure for the challenges posed by quantum computing.

In its announcement, Cloudflare stated, "1.1.1.1 now validates DNSSEC signatures using NIST’s post-quantum ML-DSA-44 algorithm." This implementation is fully operational, securing DNSSEC transactions with the new algorithm.

Why It Matters

Quantum computing could eventually break many existing cryptographic systems, including those used by DNSSEC. By adopting ML-DSA-44, Cloudflare is addressing this potential vulnerability, ensuring its DNS infrastructure is resistant to future quantum-enabled attacks.

This move also demonstrates the feasibility of integrating post-quantum cryptographic methods into existing systems. As one of the first major deployments of a NIST-approved post-quantum algorithm, it may encourage broader adoption of these standards across the internet.

Technical Details

ML-DSA-44 is a post-quantum digital signature algorithm designed to resist quantum computing threats. Its signature size—2,420 bytes—is notably larger than those of traditional algorithms, creating unique implementation challenges.

Cloudflare has taken steps to address issues related to these larger signature sizes. Larger DNSSEC signatures can increase the risk of fragmentation in DNS responses, potentially leading to performance problems or downgrade vulnerabilities. While Cloudflare has indicated it has strategies in place to mitigate these risks, it has not disclosed specific details.

Deploying post-quantum cryptography at scale requires balancing compatibility with existing systems, maintaining performance, and ensuring security. These challenges are particularly significant for a widely used service like 1.1.1.1.

What Changes Now

Cloudflare’s 1.1.1.1 DNS resolver is now one of the first public DNS services to use a post-quantum cryptographic algorithm for DNSSEC validation. For users, this means improved security against future quantum threats, though the change is unlikely to affect their immediate experience.

For the internet at large, this development signals a shift toward quantum-resistant cryptography. Cloudflare’s implementation could inspire other organizations to adopt similar standards, accelerating the transition to a more secure internet infrastructure.

What Remains Unknown

Despite the significance of this milestone, some details remain unclear. Cloudflare has not shared specifics about how it mitigates the risks associated with ML-DSA-44’s larger signature sizes. Understanding these measures could help other organizations considering similar transitions.

It is also uncertain whether other public DNS resolvers plan to adopt ML-DSA-44 or comparable post-quantum algorithms. Broader adoption will be key to securing the global DNS infrastructure against quantum threats.

As quantum computing advances, securing internet protocols becomes increasingly urgent. Cloudflare’s integration of ML-DSA-44 is a notable step forward, but it is part of a larger effort to build a quantum-resistant internet.