ML-DSA-44 DNSSEC test zones

These zones test resolver support for DNSSEC signatures with ML-DSA-44, the post-quantum signature scheme, using DNSSEC algorithm number 18, as specified in draft-westerbaan-dnssec-mldsa.

only.alg18.westerbaan.name
Signed only with ML-DSA-44 (alg 18). Secure for resolvers that support it; insecure (unknown algorithm) for the rest.
dual.alg18.westerbaan.name
Dual-signed with ML-DSA-44 (alg 18) and ECDSAP256SHA256 (alg 13). Validates everywhere.
downgrade.alg18.westerbaan.name
DS and DNSKEY records announce algorithms 18 and 13, but the alg 18 RRSIGs are deliberately stripped: only alg 13 signatures are served. Tests whether ML-DSA-44-capable validators implement the algorithm-downgrade protection suggested in the draft (if they do, this zone is bogus for them).

Try, e.g.: dig +dnssec only.alg18.westerbaan.name A