Cloudflare spent the second week of September 2026 rewriting two pieces of internet plumbing that most engineers never think about: the TLS handshake between its edge and origin servers, and the DNSSEC signatures that back DNS lookups on its 1.1.1.1 resolver. On September 8, the company rolled out Automatic Key Exchange, a system that pushes post-quantum TLS 1.3 handshakes to origin servers across what it describes as 45 billion daily connections. Two days later, on September 10, it flipped on post-quantum DNSSEC validation using NIST’s ML-DSA-44 signature scheme, becoming one of the first major resolver operators to validate quantum-resistant DNS signatures at scale.
Cloudflare Post-Quantum DNSSEC: 2,420-Byte Signatures
Cloudflare spent the second week of September 2026 rewriting two pieces of internet plumbing that most engineers never think about: the TLS handshake between its edge and origin servers, and the DNSSEC signatures that back DNS lookups…
shattered.io
Publisher
Sep 19, 2026 at 8:15 AM UTC · 16 min de lecture

Neither announcement reads like a headline-grabbing product launch. There is no new dashboard, no pricing tier, no press conference. But together they mark a quiet inflection point: the plumbing that secures a meaningful share of the web’s traffic and DNS lookups is being rebuilt around cryptography designed to survive a quantum computer that does not exist yet. Understanding what changed, why the signatures ballooned to 2,420 bytes, and what NIST’s 2030 deadline means for everyone else is the subject of this analysis.
Article Intelligence
Topics
Regulation Signal
in progressUpdated il y a un mois
SEC Crypto Asset Market Structure RulemakingRelated Coverage
Sponsored
AdNewsLayer Premium
Unlock deeper intelligence.
Ad-free reading, exclusive research, and real-time onchain insights.
Go Premium
