Post-Quantum DNSSEC: Cloudflare Takes a Giant Leap
Alps Wang
Sep 11, 2026 · 1 views
Securing DNS in the Quantum Era
Cloudflare's proactive implementation of post-quantum DNSSEC validation for ML-DSA-44 on 1.1.1.1 is a commendable and forward-thinking move. The article clearly articulates the looming threat of quantum computers to current cryptographic algorithms and the necessity of preparing critical internet infrastructure like DNSSEC. The technical depth, explaining the challenges of large signature sizes and the downgrade risk, is particularly valuable. The solution of using DS records as an authenticated signal for post-quantum validation is an innovative approach to mitigate the immediate compatibility issues and security risks. The focus on testing at internet scale is crucial for identifying real-world operational challenges before widespread adoption.
However, the article, while excellent, highlights that this is just the 'first step.' The true impact and security will only be realized when this migration extends to the entire DNS hierarchy, including authoritative servers, registrars, and registries, all the way to the root zone. The article acknowledges this lengthy and complex adoption process, which is estimated to take years. The reliance on other ecosystem players to adopt these changes means that the complete post-quantum security for DNSSEC is still a distant goal. Furthermore, while 1.1.1.1 is now validating, the practical implications for users are minimal in the short term, as they don't need to change anything. The immediate benefit is for the DNS ecosystem to gain operational experience and for Cloudflare to gather data on performance impacts, which is essential but not a direct user-facing enhancement yet. The mention of 'additional bandwidth' and 'increased TCP use' hints at potential performance overheads that will need careful monitoring as adoption grows.
Key Points
- Cloudflare's 1.1.1.1 now supports validating DNSSEC signatures using ML-DSA-44, a post-quantum cryptographic algorithm.
- This is a crucial first step towards securing DNSSEC against future quantum computer threats.
- The primary challenge is the significantly larger size of post-quantum signatures (2,420 bytes for ML-DSA-44) compared to current ones (e.g., 64 bytes for ECDSA P-256), impacting DNS over UDP limits.
- A key innovation is the use of DS records to signal to resolvers that a zone should be validated with post-quantum algorithms, preventing downgrade attacks when older algorithms become insecure.
- Cloudflare aims for full post-quantum DNSSEC security by 2029, but this requires widespread adoption across the entire DNS ecosystem.
- Users of 1.1.1.1 do not need to take any action; validation is automatic.
- Cloudflare plans to introduce ML-DSA-44 signing support for their Authoritative DNS and Registrar services next.

📖 Source: 1.1.1.1 now supports post-quantum DNSSEC, all 2,420 bytes of it
Related Articles
Comments (0)
No comments yet. Be the first to comment!
