Cloudflare Tests Post-Quantum DNSSEC: What Site Owners Need to Know About Domain Protection
New DNSSEC support in a public resolver does not automatically update domains. I explain what DNS signatures protect and why they matter when switching hosting providers.

In this article
10 сентября 2026 года Cloudflare сообщила, что её публичный DNS-резолвер начал проверять подписи DNSSEC с постквантовым алгоритмом ML-DSA-44. За сложным названием стоит развитие проверки подлинности DNS-ответов — данных, по которым браузер узнаёт адрес сервера сайта.
Новость не означает, что все домены автоматически получили новую защиту. Возможности проверяющей системы и настройки конкретного домена — разные части цепочки. Для владельца магазина практический вывод проще: DNS заслуживает отдельного внимания при обслуживании и переезде сайта.
Что именно проверяет DNSSEC
DNS помогает связать доменное имя с техническим адресом. DNSSEC добавляет подписи, позволяющие проверить происхождение и целостность ответа. Это не замена HTTPS, не антивирус для сайта и не средство исправить ошибки приложения.
Поэтому фраза «домен защищён» без уточнений мало что объясняет. Полезно понимать, где обслуживается DNS-зона, кто управляет ключами и какие действия выполняет регистратор. Эти сведения должны быть доступны команде, а не храниться только у одного специалиста.
Постквантовые алгоритмы требуют дополнительной проверки совместимости и передачи более крупных ответов. Владельцу обычного магазина не нужно самостоятельно экспериментировать с ними на рабочем домене ради свежей новости.
Переезд сайта и переезд DNS — не одно и то же
При смене сервера иногда достаточно изменить отдельные записи. При смене сервиса DNS меняется другая часть инфраструктуры. Если подписи и связанные данные у регистратора перестанут согласовываться, часть пользователей может столкнуться с ошибками разрешения имени.
До работ уточните, включён ли DNSSEC, кто обслуживает зону и как выглядит согласованный порядок перехода. Проверяйте домен через несколько независимых сетей и учитывайте время обновления кешей. Открытие сайта у одного администратора не подтверждает доступность для всех.
Почта тоже использует DNS. Не потеряйте её записи, когда переносите только веб-сайт. Для магазина исчезнувшие уведомления о заказах могут обнаружиться позже, чем ошибка главной страницы.
Сохраните понятную схему ответственности
Регистратор, DNS-провайдер и хостинг могут быть разными организациями. При сбое важно быстро определить, на каком участке он возник. Для этого нужны актуальные доступы ответственных лиц и понятный список настроек.
Я бы использовала эту новость как повод проверить обслуживание домена, а не как срочный призыв менять криптографию. Надёжность начинается с согласованной настройки уже используемых механизмов и проверки того, что переезд не разрывает путь покупателя к сайту.
On September 10, 2026, Cloudflare announced that its public DNS resolver began validating DNSSEC signatures using the post-quantum ML-DSA-44 algorithm. Behind this complex name lies the evolution of DNS response authenticity checks—data that browsers use to identify a website's server address.
This news does not mean all domains have automatically received this new protection. The capabilities of the validating system and the configuration of a specific domain are separate links in the chain. For a store owner, the practical takeaway is simpler: DNS deserves separate attention during maintenance and site migration.
What DNSSEC Actually Validates
DNS maps domain names to technical addresses. DNSSEC adds signatures that allow verification of the response's origin and integrity. This is not a replacement for HTTPS, not an antivirus for a site, and not a tool to fix application errors.
Therefore, the phrase "the domain is protected" without clarification explains little. It is useful to understand where the DNS zone is managed, who controls the keys, and what actions the registrar performs. This information must be accessible to the team, not stored with a single specialist.
Post-quantum algorithms require additional compatibility checks and result in larger responses. A typical store owner does not need to experiment with them on a live domain just for the sake of a news update.
Moving a site is not the same as moving DNS
When changing servers, sometimes it is sufficient to update specific records. However, changing a DNS service alters a different part of the infrastructure. If signatures and associated data at the registrar stop matching, some users may encounter name resolution errors.
Before starting work, verify whether DNSSEC is enabled, who manages the zone, and what the agreed migration procedure looks like. Check the domain across several independent networks and account for cache propagation times. A site opening for one administrator does not confirm availability for everyone.
Email also relies on DNS. Do not lose your email records when migrating only the website. For a store, missing order notifications may be discovered later than a homepage error.
Maintain a clear responsibility framework
The registrar, DNS provider, and hosting provider may be different organizations. In the event of a failure, it is crucial to quickly identify where the issue occurred. This requires up-to-date access for responsible parties and a clear list of settings.
I would treat this news as an opportunity to review domain maintenance rather than an urgent call to change cryptography. Reliability begins with a consistent configuration of existing mechanisms and verifying that a migration does not break the path for customers to reach the site.

Discussion0
Share your experience and ask questions. Comments without links appear after editorial review.
No comments yet. Start the discussion.