Redson Dev brief · PRIMARY SOURCE
1.1.1.1 now supports post-quantum DNSSEC, all 2,420 bytes of it
Cloudflare Blog · September 10, 2026

The imminent threat of quantum computing rendering current encryption obsolete is being directly addressed, offering a crucial layer of future-proof security for your digital infrastructure. This piece details how Cloudflare's 1.1.1.1 public DNS resolver now integrates post-quantum cryptography (PQC) for DNSSEC, specifically employing the NIST-selected ML-DSA-44 algorithm. The core innovation lies in managing the significantly larger signature sizes—up to 2,420 bytes—and mitigating downgrade risks at a global scale, ensuring DNS query integrity against future quantum attacks without sacrificing performance or introducing vulnerabilities. For working professionals, this development fundamentally shifts the landscape of long-term digital trust. Consider a mid-sized e-commerce platform based in Seattle, Washington, handling sensitive customer data. By leveraging a DNS resolver like 1.1.1.1, they gain an immediate, transparent uplift in their DNS security posture, protecting their domain’s authenticity against sophisticated, state-sponsored or quantum-assisted attackers attempting to redirect traffic to malicious sites. An independent SaaS founder in Austin, Texas, developing a critical financial tool, can now assure clients that even the foundational DNS lookups for their service are protected against cryptographic breaks decades in the future, enhancing their offering’s perceived reliability. Similarly, an internal IT team at a manufacturing plant in Detroit, Michigan, overseeing critical operational technology, benefits from this underlying security improvement, ensuring their intranet services and external cloud applications maintain verifiable domain integrity, reducing the attack surface for supply chain disruptions or intellectual property theft. The practical impact is a silent upgrade to foundational internet security, requiring no direct action from most users beyond using a PQC-enabled resolver, but providing immense long-term protection. This isn't about deploying new code but understanding a critical layer of defense is now active. It offers peace of mind and reduces future technical debt associated with migrating cryptographic systems. To capitalize on this now, ensure your DNS infrastructure, where possible, defaults to or utilizes resolvers that have implemented post-quantum DNSSEC, such as Cloudflare's 1.1.1.1. For instance, you could update the DNS settings on a non-production development server this week to use 1.1.1.1 as its primary resolver and observe its performance under normal load, ensuring compatibility and baseline operational integrity.
Source / further reading
Learn more at Cloudflare Blog →