Cloudflare adds post-quantum DNSSEC validation to 1.1.1.1
Cloudflare says its public DNS resolver can now verify ML-DSA-44 signatures, a step toward protecting DNS records against future quantum computers.
Cloudflare enabled ML-DSA-44 signature validation on its 1.1.1.1 DNS resolver. The signatures are 2,420 bytes, large enough to require different handling than typical DNS responses over UDP. Cloudflare says the rollout will help test larger responses and protections against falling back to conventional signatures. Authoritative DNS signing and registrar support are planned next.