1.1.1.1 now supports post-quantum DNSSEC, all 2,420 bytes of it

Cloudflare's 1.1.1.1 resolver now validates DNSSEC signatures using the post‑quantum ML‑DSA‑44 algorithm, adding 2,420‑byte signatures to DNS responses. The blog explains the implementation and notes the challenge of larger messages, marking the first large‑scale test of post‑quantum DNSSEC at Internet scale. Developers can observe the impact via the public resolver.

Cover image for 1.1.1.1 now supports post-quantum DNSSEC, all 2,420 bytes of it