Payments are experiencing issues due to temporary restrictions in Russia. If your payment does not go through, please submit a support request.Our support team is available 24/7 — we are always here to help with hosting and server issues.We are now accepting requests for dedicated server rental and colocation services in our data center.Reminder: we recommend enabling backups for additional data protection.A new VPS/VDS lineup with NVMe storage and improved performance is now available.Maintenance work on some servers has been completed. All services are operating normally.
Article3 min read

Cloudflare Tests Post-Quantum DNSSEC: What Site Owners Need to Know About Domain Protection

New DNSSEC support in a public resolver does not automatically update domains. I explain what DNS signatures protect and why they matter when switching hosting providers.

Network cables in a switch cabinet
In this article

On September 10, 2026, Cloudflare announced that its public DNS resolver began validating DNSSEC signatures using the post-quantum ML-DSA-44 algorithm. Behind this complex name lies the evolution of DNS response authenticity checks—data that browsers use to identify a website's server address.

This news does not mean all domains have automatically received this new protection. The capabilities of the validating system and the configuration of a specific domain are separate links in the chain. For a store owner, the practical takeaway is simpler: DNS deserves separate attention during maintenance and site migration.

What DNSSEC Actually Validates

DNS maps domain names to technical addresses. DNSSEC adds signatures that allow verification of the response's origin and integrity. This is not a replacement for HTTPS, not an antivirus for a site, and not a tool to fix application errors.

Therefore, the phrase "the domain is protected" without clarification explains little. It is useful to understand where the DNS zone is managed, who controls the keys, and what actions the registrar performs. This information must be accessible to the team, not stored with a single specialist.

Post-quantum algorithms require additional compatibility checks and result in larger responses. A typical store owner does not need to experiment with them on a live domain just for the sake of a news update.

Moving a site is not the same as moving DNS

When changing servers, sometimes it is sufficient to update specific records. However, changing a DNS service alters a different part of the infrastructure. If signatures and associated data at the registrar stop matching, some users may encounter name resolution errors.

Before starting work, verify whether DNSSEC is enabled, who manages the zone, and what the agreed migration procedure looks like. Check the domain across several independent networks and account for cache propagation times. A site opening for one administrator does not confirm availability for everyone.

Email also relies on DNS. Do not lose your email records when migrating only the website. For a store, missing order notifications may be discovered later than a homepage error.

Maintain a clear responsibility framework

The registrar, DNS provider, and hosting provider may be different organizations. In the event of a failure, it is crucial to quickly identify where the issue occurred. This requires up-to-date access for responsible parties and a clear list of settings.

I would treat this news as an opportunity to review domain maintenance rather than an urgent call to change cryptography. Reliability begins with a consistent configuration of existing mechanisms and verifying that a migration does not break the path for customers to reach the site.

Discussion0

Share your experience and ask questions. Comments without links appear after editorial review.

No comments yet. Start the discussion.