ΕΛΠΙΣ DNS
Post-quantum DNSSEC

ML-DSA-44,
ready for the quantum age

DNSSEC proves a DNS answer is real. ML-DSA-44 is the new signature built to stay safe even against quantum computers, and ΕΛΠΙΣ Resolver already checks it: second in the world, after Cloudflare's 1.1.1.1.

18

its DNSSEC algorithm number, assigned by IANA

FIPS 204

the NIST standard it comes from, August 2024

2,420

bytes in every signature

2nd

resolver in the world to validate it

What it is

A signature quantum computers can't fake

Three ideas, and you know everything you need.

DNSSEC, in one line

Domains sign their DNS records. Your resolver checks the signature, so a fake answer gets thrown away instead of sending you to the wrong place.

The quantum problem

Today's signatures use RSA, ECDSA or Ed25519. A large enough quantum computer could forge all three. None exists yet, but DNS changes slowly, so the fix has to start early.

The lattice answer

ML-DSA is built on lattice maths that no known quantum attack breaks. NIST made it a standard, FIPS 204. The 44 is the smallest and fastest of its three sizes.

Why validators go first. A domain can only switch to a new signature once resolvers understand it, or its answers stop working. So resolvers have to learn it before anyone signs with it. IANA gave ML-DSA-44 algorithm number 18 in August 2026, Cloudflare switched it on in 1.1.1.1 on 10 September 2026, and ΕΛΠΙΣ Resolver is next.

How big

Safer, but much bigger

Signature size per DNSSEC algorithm, in bytes. ML-DSA-44 is almost 38 times an ECDSA signature, which is why signed answers now often travel over TCP instead of a single UDP packet.

DNSSEC algorithms compared: algorithm number, quantum safety, public key size and signature size in bytes.
Algorithm Quantum-safe Public key Signature
RSA/SHA-256 8 · 2048-bit No 260 B 256 B
ECDSA P-256 13 No 64 B 64 B
Ed25519 15 No 32 B 64 B
ML-DSA-44 18 Yes 1,312 B 2,420 B

How we check it

From the answer to the ad flag

What ΕΛΠΙΣ Resolver does when an answer arrives signed with ML-DSA-44.

  1. The answer arrives with a signature marked algorithm 18.
  2. We fetch the domain's DNSKEY: a 1,312-byte key. With its own signature the reply is about 3.8 KB, too big for one UDP packet, so it comes over TCP.
  3. The parent zone's DS record, signed the classic way, vouches for that key by its key tag and SHA-256 digest.
  4. We verify the signature with FIPS 204 ML-DSA-44, exactly as the IETF draft says: pure ML-DSA, empty context.
  5. It checks out, so you get the answer with the ad flag. It doesn't, so you get SERVFAIL and an Extended DNS Error saying why.

Written from scratch

ML-DSA lives in ΕΛΠΙΣ Resolver's own C99 code, next to RSA, ECDSA and Ed25519, with no outside crypto library. The draft's worked example, its key tag, DS digest and a real signature, is checked on every build.

ML-DSA-65 and ML-DSA-87 are in there too, ready for when they get algorithm numbers of their own.

Read the source

Try it yourself

Don't take our word for it

Cloudflare runs test zones signed with ML-DSA-44. Ask one of our public resolvers about them with dig.

A good signature

dig @151.158.198.47 valid.mldsa44.dnstest.dev +dnssec

Look for ad in the flags line. It means "authenticated data": the ML-DSA-44 signature checked out.

;; flags: qr rd ra ad; QUERY: 1, ANSWER: 3

A forged signature

dig @151.158.198.47 invalid.mldsa44.dnstest.dev +dnssec

This one is broken on purpose. A validating resolver must refuse it, and say why:

;; status: SERVFAIL
; EDE: 6 (DNSSEC Bogus)
Want to compare? Swap in @1.1.1.1. On IPv6, use @2402:4e20:c0de::b00b. And expired.mldsa44.dnstest.dev should fail with EDE: 7 (Signature Expired). Every address is on the resolver page.

FAQ

Good questions

Do I need to change anything to use ML-DSA-44?

No. If you use ΕΛΠΙΣ DNS or our public resolvers, ML-DSA-44 signatures are checked automatically, alongside every other DNSSEC algorithm.

Is my DNS quantum-safe now?

Only for zones signed with ML-DSA-44, and today those are mostly test zones. The root and most top-level domains still sign with RSA or ECDSA, and the encryption on DoH and DoT is a separate matter. Validators have to come first; zones follow once enough resolvers can check the new signatures.

Why is an ML-DSA-44 signature so big?

Lattice signatures trade size for safety. An ML-DSA-44 signature is 2,420 bytes, almost 38 times an ECDSA P-256 signature. A signed answer often no longer fits in one UDP packet, so it moves to TCP. The resolver does that for you.

Who else validates ML-DSA-44?

Cloudflare's 1.1.1.1 was first, from 10 September 2026. ΕΛΠΙΣ Resolver is the second resolver in the world to validate it, and other open-source resolvers are working on it too.

Which DNSSEC algorithms does ΕΛΠΙΣ Resolver check?

RSA from 1024 to 4096 bits, ECDSA P-256 and P-384, Ed25519, and ML-DSA-44, with ML-DSA-65 and ML-DSA-87 ready for when they are given algorithm numbers. All of it is implemented from scratch in C99.

What does algorithm number 18 mean?

Every DNSSEC signature says which algorithm made it, as a number from the IANA registry. ML-DSA-44 was given number 18 in August 2026, from the draft by Bas Westerbaan and Sophie Schmieg.

IANA DNSSEC algorithm numbers

Sources: NIST FIPS 204 · draft-westerbaan-dnssec-mldsa · IANA registry · Cloudflare: 1.1.1.1 and post-quantum DNSSEC

Get post-quantum DNSSEC today

Pick an encrypted ΕΛΠΙΣ DNS endpoint, or put our public resolvers behind your own AdGuard Home or Pi-hole. Either way, ML-DSA-44 is on.