Cloudflare has launched new tools that give its customers detailed visibility into the use of post-quantum encryption in TLS 1.3 connections, rather than limiting them to aggregated statistics at the internet level. The new data appears in the HTTP Traffic Analytics dashboard and can also be exported to Log Explorer and Logpush to inspect individual connections between domain visitors and the Cloudflare platform, as well as between Cloudflare and origin servers.
The tools record the key-exchange algorithm negotiated for each incoming connection. This enables security administrators to determine the percentage of traffic using the hybrid X25519MLKEM768 algorithm, identify connections that rely on traditional algorithms or do not use TLS encryption, and then correlate these results with compliance requirements and plans to transition to encryption resistant to quantum computing.
What has changed in practice?
Cloudflare previously provided broad metrics through Cloudflare Radar, indicating that about 70% of browser traffic heading to its network was protected by post-quantum encryption using hybrid ML-KEM, compared with only about 15% of origin servers connecting to Cloudflare. However, those percentages did not reveal the status of a specific domain. The new update moves measurement to the domain and connection levels, making it possible to answer questions such as what percentage of traffic to a specific domain uses post-quantum encryption.
TLS key-exchange-group statistics appear in a dedicated card within HTTP Traffic Analytics and can also be used as a filter to isolate traffic that does not use X25519MLKEM768. In logs, the customer adds the ClientTLSKeyExchangeGroup field within the HTTP requests dataset, while the OriginTLSKeyExchangeGroup field displays the key-exchange algorithm used in the Cloudflare connection to the origin server.
Why does this news matter?
The importance of monitoring is based on the risks of “harvest now, decrypt later” attacks, in which encrypted data can be collected today and decrypted in the future when powerful quantum computers become available. Cloudflare notes that in 2024 the U.S. National Institute of Standards and Technology (NIST) recommended gradually moving away from RSA and elliptic-curve cryptography by 2030, a deadline adopted by several governments and regulatory bodies.
In TLS 1.3, X25519MLKEM768 combines ECDHE key exchange through X25519 with the quantum-resistant ML-KEM mechanism. The hybrid approach allows protection to continue if one of the two exchange components remains secure. TLS 1.2 and earlier versions do not provide post-quantum encryption under the mechanism described by Cloudflare.
Measurement limitations and available steps
If no use of X25519MLKEM768 appears, Cloudflare recommends checking that TLS 1.3 is enabled; there is no separate switch for enabling post-quantum encryption, as it is negotiated automatically when the browser supports the algorithm. Low percentages may also reflect visitors relying on non-browser clients that do not support TLS 1.3 or the hybrid algorithm.
Cloudflare also allows legacy origin servers to be placed behind Cloudflare Tunnel, so that the channel between the server and the platform uses TLS 1.3 with X25519MLKEM768 without upgrading the server itself. However, the update currently focuses on key exchange rather than post-quantum authentication; certificates and signatures based on RSA and ECC have not yet been widely replaced. The company says it will add visibility into authentication algorithms, including Merkle Tree certificates, when their deployment becomes more widespread.