- Sources: primary, discussion
- Summary: Cloudflare states that 1.1.1.1 validates post-quantum DNSSEC signatures using ML-DSA-44, and that once a parent DS record signals a post-quantum path the resolver requires it rather than accepting conventional signatures. An ML-DSA-44 signature is 2,420 bytes against 64 bytes for ECDSA P-256. The no-fallback behaviour is Cloudflare's local resolver policy.
- Why it matters: Operators moving a zone to ML-DSA-44 should expect DNSKEY responses to spill past common UDP limits onto TCP, and resolvers without the same no-downgrade rule leave the migration strippable.
- Follow-up: Whether other resolvers adopt the same no-downgrade policy, and how zones handle the TCP fallback the larger responses force.
send feedback on this story