What happened

On September 10, 2026, Cloudflare revealed that its 1.1.1.1 DNS resolver now supports post-quantum DNSSEC validation using the ML-DSA-44 algorithm, which has been approved by NIST. This development is a key step in preparing cryptographic systems to withstand potential threats from quantum computing. DNSSEC, the protocol that verifies DNS responses, has traditionally relied on algorithms vulnerable to quantum attacks. By adopting ML-DSA-44, Cloudflare aims to safeguard its DNS infrastructure against these emerging risks.

Deploying ML-DSA-44 presented challenges, particularly due to its large signature size of 2,420 bytes. Despite these obstacles, Cloudflare has successfully scaled the system while addressing risks such as potential downgrade attacks.

Why it matters

Quantum computing poses a serious threat to many cryptographic systems that secure the internet, including DNSSEC. If compromised, DNSSEC could allow attackers to redirect users to malicious sites or intercept sensitive data. Post-quantum cryptography, like ML-DSA-44, is designed to counteract these risks.

Cloudflare’s integration of ML-DSA-44 into its widely used 1.1.1.1 resolver strengthens the DNS ecosystem and sets an example for other providers. This move could accelerate the adoption of quantum-resistant standards, helping to secure internet infrastructure against future vulnerabilities.

Technical details

ML-DSA-44, approved by NIST for post-quantum cryptographic applications, generates signatures significantly larger than traditional algorithms—2,420 bytes. These larger signatures pose challenges related to bandwidth and storage.

Cloudflare’s implementation addresses these issues while maintaining scalability and performance. Large signature sizes can strain DNS infrastructure, especially when handling millions of queries. Additionally, mitigating downgrade attacks, where systems are forced to revert to less secure algorithms, requires careful planning. While Cloudflare has acknowledged these risks, it has not disclosed specific measures taken to manage them.

What changes now

For users of Cloudflare’s 1.1.1.1 DNS resolver, the adoption of ML-DSA-44 enhances security against quantum computing threats without affecting everyday usage. More broadly, this deployment signals a shift in the DNS ecosystem toward post-quantum cryptographic standards.

Cloudflare’s actions may encourage other DNS providers to prioritize quantum-resistant security measures. However, widespread adoption will depend on overcoming technical hurdles, such as handling large signature sizes and ensuring compatibility across diverse systems.

What remains unknown

While Cloudflare has successfully deployed ML-DSA-44, several details remain unclear. The company has not shared specifics on how it mitigates downgrade risks or provided performance benchmarks related to latency or system efficiency.

These gaps highlight areas for further investigation, particularly as other providers consider adopting similar technologies. Transparency regarding implementation challenges and performance metrics will be essential for fostering trust and encouraging broader adoption of post-quantum cryptography.