The internet’s paperwork is getting bulkier.
Cloudflare announced on September 10 that its 1.1.1.1 resolver now validates DNSSEC signatures made with ML-DSA-44. DNSSEC checks the authenticity of DNS answers; it does not encrypt the contents of your browsing.
ML-DSA belongs to the digital-signature standard NIST published in August 2024. NIST describes it as believed secure even against an adversary with a large-scale quantum computer. That wording matters: this is preparation for a future threat, not a promise that cryptography is solved forever.
The practical snag is size. Cloudflare says each ML-DSA-44 signature occupies 2,420 bytes, enough to exceed common DNS-over-UDP limits before the rest of the answer is included. Larger replies can require a retry over TCP, another network transport.
For existing 1.1.1.1 users, Cloudflare says validation happens automatically when a zone supplies the required records. But this covers the resolver side. Its announcement describes signing support for Cloudflare’s authoritative DNS and corresponding registrar support as next steps.
A complete post-quantum chain also needs adoption through parent zones up to the DNS root. So: a useful new signature checker, with plenty of envelopes still to replace.
