Cloudflare has enabled validation of NIST-standardized ML-DSA-44 post-quantum DNSSEC signatures on its 1.1.1.1 public resolver. Where an authenticated parent DS record advertises the algorithm, the resolver requires a valid ML-DSA-44 chain of trust rather than falling back to conventional signatures, protecting dual-signed migrations against downgrade attacks.
The rollout provides Internet-scale testing of major operational constraints: ML-DSA-44 signatures are about 2,420 bytes, often exceeding standard DNS-over-UDP payload limits and triggering truncated responses and TCP fallback. End-to-end post-quantum DNSSEC remains dependent on adoption across authoritative DNS operators, registrars, registries, TLDs, the DNS root, and other validating resolvers; Cloudflare has stated a goal of full post-quantum security by 2029.

Track how attackers are adapting to this technology.
4 events from the most recent confirmed update back to the earliest known activity.
Cloudflare enabled validation of NIST-standardized ML-DSA-44 post-quantum DNSSEC signatures on its 1.1.1.1 public resolver. The resolver applies a stricter local policy requiring a valid ML-DSA-44 chain when an authenticated parent DS record advertises the algorithm, preventing fallback to a conventional signature alone.
IANA assigned ML-DSA-44 DNSSEC algorithm number 18 and listed its signing and validation status as MAY.
RFC 9210 reinforced TCP as a DNS best current practice, supporting the TCP fallback needed when ML-DSA-44 DNSSEC responses exceed UDP payload limits.
RFC 7766 made TCP support mandatory for general-purpose DNS implementations, establishing a transport requirement relevant to oversized post-quantum DNSSEC responses.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Follow how adversaries are adapting to this technology, and where it touches your stack today.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.