ALEXKRI.NET
Resume Contact
← Back

1.1.1.1 now supports post-quantum DNSSEC, all 2,420 bytes of it

Post-quantum crypto is coming to DNS, and it’s large. Cloudflare’s 1.1.1.1 now validates DNSSEC signatures made with ML-DSA-44. Each one is 2,420 bytes, about 38x an ECDSA P-256 signature, so responses outgrow UDP and fall back to TCP. If your resolvers, firewalls or middleboxes assume DNS is small UDP packets, now is a good time to check.

Read the source ↗