Cloudflare’s 1.1.1.1 resolver now validates signatures created using ML-DSA-44, a NIST-standardized post-quantum signature scheme, marking one of the first major public DNS resolvers to adopt this technology in a live environment. The change addresses a looming threat to internet security. Powerful quantum computers could eventually undermine current cryptographic algorithms used to verify DNS information.
This implementation presents an immediate engineering challenge, as an ML-DSA-44 signature reaches 2,420 bytes, almost 38 times larger than the 64 bytes of a commonly used ECDSA P-256 signature. Cloudflare notes that full quantum safety for the DNS ecosystem will require support from authoritative DNS servers, registrars, registries, resolvers and the DNS root itself.
ML-DSA-44 Validates DNSSEC Signatures on Cloudflare’s 1.1.1.1 Resolver
Cloudflare’s implementation of ML-DSA-44 signature validation on its 1.1.1.1 resolver presents a significant engineering shift, requiring systems to process data packets substantially larger than those previously used for DNSSEC. This change is not merely an algorithmic upgrade. It’s a practical test of network infrastructure’s ability to handle the demands of post-quantum cryptography. The move to validate these signatures does not immediately secure the entire internet infrastructure, but rather demonstrates an early step in adoption.
“For that to happen, post-quantum cryptography will eventually have to be supported across the full chain,” Cloudflare notes, highlighting the systemic changes required for complete protection. This phased approach allows for coexistence between classical and post-quantum cryptographic methods during the transition period. This implementation provides a valuable opportunity to assess the real-world performance of post-quantum algorithms, specifically regarding bandwidth consumption and network handling of larger message sizes.
The company intends to learn how networks respond to these increased demands and identify necessary modifications as adoption expands. Cloudflare emphasizes the importance of proactive testing, stating, “Developments like this one therefore create an opportunity to learn how post-quantum algorithms behave in real-world infrastructure.” The effort to build quantum-safe systems is a proactive strategy to ensure future resilience, not a reactive measure taken in response to an immediate threat.




See today’s quantum computing news on Quantum Zeitgeist for the latest breakthroughs in qubits, hardware, algorithms, and industry deals.
