its DNSSEC algorithm number, assigned by IANA
the NIST standard it comes from, August 2024
bytes in every signature
resolver in the world to validate it
What it is
A signature quantum computers can't fake
Three ideas, and you know everything you need.
DNSSEC, in one line
Domains sign their DNS records. Your resolver checks the signature, so a fake answer gets thrown away instead of sending you to the wrong place.
The quantum problem
Today's signatures use RSA, ECDSA or Ed25519. A large enough quantum computer could forge all three. None exists yet, but DNS changes slowly, so the fix has to start early.
The lattice answer
ML-DSA is built on lattice maths that no known quantum attack breaks. NIST made it a standard, FIPS 204. The 44 is the smallest and fastest of its three sizes.
How big
Safer, but much bigger
Signature size per DNSSEC algorithm, in bytes. ML-DSA-44 is almost 38 times an ECDSA signature, which is why signed answers now often travel over TCP instead of a single UDP packet.
| Algorithm | Quantum-safe | Public key | Signature |
|---|---|---|---|
| RSA/SHA-256 8 · 2048-bit | No | 260 B | 256 B |
| ECDSA P-256 13 | No | 64 B | 64 B |
| Ed25519 15 | No | 32 B | 64 B |
| ML-DSA-44 18 | Yes | 1,312 B | 2,420 B |
How we check it
From the answer to the ad flag
What ΕΛΠΙΣ Resolver does when an answer arrives signed with ML-DSA-44.
- The answer arrives with a signature marked algorithm 18.
- We fetch the domain's DNSKEY: a 1,312-byte key. With its own signature the reply is about 3.8 KB, too big for one UDP packet, so it comes over TCP.
- The parent zone's DS record, signed the classic way, vouches for that key by its key tag and SHA-256 digest.
- We verify the signature with FIPS 204 ML-DSA-44, exactly as the IETF draft says: pure ML-DSA, empty context.
- It checks out, so you get the answer with the ad flag. It doesn't, so you get SERVFAIL and an Extended DNS Error saying why.
Written from scratch
ML-DSA lives in ΕΛΠΙΣ Resolver's own C99 code, next to RSA, ECDSA and Ed25519, with no outside crypto library. The draft's worked example, its key tag, DS digest and a real signature, is checked on every build.
ML-DSA-65 and ML-DSA-87 are in there too, ready for when they get algorithm numbers of their own.
Read the sourceTry it yourself
Don't take our word for it
Cloudflare runs test zones signed with ML-DSA-44. Ask one of our
public resolvers about them with dig.
A good signature
dig @151.158.198.47 valid.mldsa44.dnstest.dev +dnssec
Look for ad in the flags line. It means "authenticated
data": the ML-DSA-44 signature checked out.
;; flags: qr rd ra ad; QUERY: 1, ANSWER: 3
A forged signature
dig @151.158.198.47 invalid.mldsa44.dnstest.dev +dnssec
This one is broken on purpose. A validating resolver must refuse it, and say why:
;; status: SERVFAIL ; EDE: 6 (DNSSEC Bogus)
@1.1.1.1. On IPv6, use
@2402:4e20:c0de::b00b. And
expired.mldsa44.dnstest.dev should fail with
EDE: 7 (Signature Expired). Every address is on the
resolver page.
FAQ
Good questions
Do I need to change anything to use ML-DSA-44?
No. If you use ΕΛΠΙΣ DNS or our public resolvers, ML-DSA-44 signatures are checked automatically, alongside every other DNSSEC algorithm.
Is my DNS quantum-safe now?
Only for zones signed with ML-DSA-44, and today those are mostly test zones. The root and most top-level domains still sign with RSA or ECDSA, and the encryption on DoH and DoT is a separate matter. Validators have to come first; zones follow once enough resolvers can check the new signatures.
Why is an ML-DSA-44 signature so big?
Lattice signatures trade size for safety. An ML-DSA-44 signature is 2,420 bytes, almost 38 times an ECDSA P-256 signature. A signed answer often no longer fits in one UDP packet, so it moves to TCP. The resolver does that for you.
Who else validates ML-DSA-44?
Cloudflare's 1.1.1.1 was first, from 10 September 2026. ΕΛΠΙΣ Resolver is the second resolver in the world to validate it, and other open-source resolvers are working on it too.
Which DNSSEC algorithms does ΕΛΠΙΣ Resolver check?
RSA from 1024 to 4096 bits, ECDSA P-256 and P-384, Ed25519, and ML-DSA-44, with ML-DSA-65 and ML-DSA-87 ready for when they are given algorithm numbers. All of it is implemented from scratch in C99.
What does algorithm number 18 mean?
Every DNSSEC signature says which algorithm made it, as a number from the IANA registry. ML-DSA-44 was given number 18 in August 2026, from the draft by Bas Westerbaan and Sophie Schmieg.
IANA DNSSEC algorithm numbersSources: NIST FIPS 204 · draft-westerbaan-dnssec-mldsa · IANA registry · Cloudflare: 1.1.1.1 and post-quantum DNSSEC
Pick an encrypted ΕΛΠΙΣ DNS endpoint, or put our public resolvers behind your own AdGuard Home or Pi-hole. Either way, ML-DSA-44 is on.