1.1.1.1 now supports post-quantum DNSSEC, all 2,420 bytes of it

1.1.1.1 now supports post-quantum DNSSEC, all 2,420 bytes of it

What Happened

Cloudflare’s 1.1.1.1 DNS resolver now validates DNSSEC signatures made with the post‑quantum algorithm ML‑DSA‑44, which produces 2,420‑byte signatures. This is the first large‑scale deployment of a post‑quantum signature in DNSSEC, allowing Cloudflare to test handling of large DNS responses and preventing fallback to legacy signatures. Cloudflare plans to achieve full post‑quantum security by 2029 and has already enabled post‑quantum key agreement in TLS since 2019.

Why It Matters

Enterprise architects should note that DNSSEC will soon require larger packet sizes and more robust resolver infrastructure to support post‑quantum signatures, impacting network design and performance budgets. The move signals a shift toward quantum‑resistant cryptography across core internet protocols, necessitating updates to security governance and compliance frameworks. Failure to adopt compatible resolvers could expose organizations to future quantum‑based DNS spoofing attacks.

The Limitation

The current deployment is limited to Cloudflare’s public resolver; widespread adoption depends on resolver vendors and DNS infrastructure upgrades, which may take several years to mature.

What You Can Do

Update your DNS resolver stack to support ML‑DSA‑44 or equivalent post‑quantum signatures and validate that your network can handle 2,420‑byte DNS responses without fragmentation.

Source

Read original source
← Back to all articles