Cloudflare says its 1.1.1.1 public resolver has begun validating DNSSEC signatures made with ML-DSA-44, a NIST-standardized post-quantum signature algorithm, giving the DNS ecosystem an early large-scale test of how quantum-resistant DNSSEC might behave in production.
The change is narrow but important for site operators, registrars and DNS providers because DNSSEC sits in the trust path for domain lookups. Today’s common DNSSEC algorithms, including RSA and ECDSA, are not expected to withstand a sufficiently capable future quantum computer. Cloudflare stresses that such machines do not exist today, and DNSSEC does not face the same “harvest now, decrypt later” problem as encrypted traffic, but DNS changes tend to take years because they involve resolvers, registries, registrars and authoritative DNS operators.
The operational catch is size. Cloudflare says each ML-DSA-44 signature is 2,420 bytes, far larger than a 64-byte ECDSA P-256 signature and already bigger than many conservative DNS-over-UDP payload limits before any other DNS records are included. In practice, that means resolvers and authoritative servers will need to handle more truncation and retries over TCP, DNS over TLS or DNS over HTTPS as post-quantum DNSSEC testing expands.
Cloudflare also points to a migration problem: zones will likely need to publish conventional and post-quantum signatures side by side for years so older validators can continue to resolve signed domains. That compatibility can create downgrade risks unless newer validators are careful about preferring the post-quantum validation path when it is available.
For hosting companies and managed DNS providers, the takeaway is that post-quantum DNSSEC is moving from theory into interoperability work. Operators should expect future testing to expose assumptions around UDP size, fragmented responses, TCP fallback, resolver behavior and DNSSEC key rollover processes. Those are not urgent customer-facing changes today, but they are exactly the sort of plumbing issues that can become reliability problems if the industry waits until a standards migration is already underway.
Source: Cloudflare Blog — 1.1.1.1 now supports post-quantum DNSSEC.
