DNS query volume from AS139693
Copy linkDNS queries to 1.1.1.1
Learn more...The traffic analysis presented here is based on anonymized DNS query logs, in accordance with Cloudflare's Privacy Policy, as well as our 1.1.1.1 Public DNS Resolver privacy commitments.
DNSSEC adds a signing layer to DNS, protecting responses from tampering
Posts tagged with "1.1.1.1" from the Cloudflare blog
1.1.1.1 now validates DNSSEC signatures using NIST’s post-quantum ML-DSA-44 algorithm. Here is how we manage 2,420-byte signatures and downgrade risks at scale.
Five Rust-level memory optimizations to the DNS cache layout of Big Pineapple cut per-entry memory by 56%, freeing approximately 100 TB of memory across Cloudflare's fleet.
When a failed DNSSEC key rollover took down the .al TLD, we deployed a Negative Trust Anchor to restore resolution. This time, though, clients didn't have to take our word for it: 1.1.1.1 returned EDE 33, a new DNS error code that signals directly in the response that DNSSEC validation was bypassed.