Cloudflare 1.1.1.1 adds post-quantum DNSSEC validation
Cloudflare's 10 September 2026 engineering blog says 1.1.1.1 now validates ML-DSA-44 DNSSEC signatures. Each signature is 2,420 bytes, so answers may truncate on UDP and retry over TCP. When a parent DS advertises the algorithm, a conventional path alone fails.

Cloudflare engineers Sebastiaan Neuteboom and Bas Westerbaan, in a 10 September 2026 company blog post, said the 1.1.1.1 public resolver now validates DNSSEC signatures made with ML-DSA-44. That is a NIST-standardized post-quantum signature algorithm.
This is a Cloudflare engineering blog on resolver-side validation. It is not a root-zone change, and it is not a CISA advisory.
Each ML-DSA-44 signature is 2,420 bytes, against 64 bytes for ECDSA P-256. That size can exceed common DNS-over-UDP limits before the rest of the answer is counted, so nameservers may return a truncated UDP reply and the resolver retries over TCP. Users of 1.1.1.1 need no configuration change. Validation is automatic when a zone publishes the needed records.
The downgrade rule is the part most one-line takes skip. When an authenticated parent DS RRset signals ML-DSA-44 support, Cloudflare's local policy requires a valid post-quantum validation path. A conventional path alone is no longer enough. RFC 4035 allows that local policy.
The work covers the resolver side only. Cloudflare's next step, not live for all customers yet, is ML-DSA-44 signing on Cloudflare Authoritative DNS and matching DS support via Cloudflare Registrar, offered free to customers. The company says it wants full post-quantum security by 2029. Broad deployment still needs the rest of the DNS hierarchy, including parent zones and eventually the root.
To see the oversized path, Cloudflare points operators at dig @1.1.1.1 valid.mldsa44.dnstest.dev +dnssec on the dnstest.dev test zone.
Resolver and patch notes this week also include GitLab's commits API file-read flaw, Check Point VPN certificate flaws at 9.8, WatchGuard Firebox RCE in CISA's catalog, and LiteLLM's exploited MCP auth bypass.
If you already send queries to 1.1.1.1, treat ML-DSA-44 validation as on when zones publish the records. If you run authoritative DNS or a registrar, do not assume you are post-quantum signed yet. Plan signing and parent DS publication against Cloudflare's 2029 goal, and use the dnstest.dev query if you need to watch the 2,420-byte TCP retry on your path.
Cyberpresso: daily cyber & AI brief
Free daily newsletter, read in 5 minutes.
Subscribe free