NewsLayer.com
NewsLayer PulseLIVEBTC$81,241+4.16%ETH$2,639+5.30%SOL$111.87+5.90%XRP$1.43+8.00%DOGE$0.0881+3.39%ADA$0.226+5.61%Total Cap$2.91T+3.84%Layer Index68 Greed

Cloudflare Post-Quantum DNSSEC: 2,420-Byte Signatures

Cloudflare spent the second week of September 2026 rewriting two pieces of internet plumbing that most engineers never think about: the TLS handshake between its edge and origin servers, and the DNSSEC signatures that back DNS lookups…

shattered.io

Publisher

Sep 19, 2026 at 8:15 AM UTC · 16 min de lecture

Cloudflare Post-Quantum DNSSEC: 2,420-Byte Signatures
Image via shattered.io
Traduction…

Cloudflare spent the second week of September 2026 rewriting two pieces of internet plumbing that most engineers never think about: the TLS handshake between its edge and origin servers, and the DNSSEC signatures that back DNS lookups on its 1.1.1.1 resolver. On September 8, the company rolled out Automatic Key Exchange, a system that pushes post-quantum TLS 1.3 handshakes to origin servers across what it describes as 45 billion daily connections. Two days later, on September 10, it flipped on post-quantum DNSSEC validation using NIST’s ML-DSA-44 signature scheme, becoming one of the first major resolver operators to validate quantum-resistant DNS signatures at scale.

Neither announcement reads like a headline-grabbing product launch. There is no new dashboard, no pricing tier, no press conference. But together they mark a quiet inflection point: the plumbing that secures a meaningful share of the web’s traffic and DNS lookups is being rebuilt around cryptography designed to survive a quantum computer that does not exist yet. Understanding what changed, why the signatures ballooned to 2,420 bytes, and what NIST’s 2030 deadline means for everyone else is the subject of this analysis.