Cloudflare plans to expand its DNS cache using memory recovered from a redesign of its 1.1.1.1 resolver. The company freed roughly 100 TB of working-set memory by changing how cached records are represented.
The work reduced the benchmarked memory footprint per entry by 56%. It also increased cache insertion throughput by 43% and reduced lookup latency by 19%. Those gains came from five successive changes to the cache representation in Rust.
The central improvement concerns storage within individual entries, rather than a new division of cache types. Cloudflare’s Big Pineapple DNS platform holds more than 250 billion cache entries at any given time. At that scale, changes to each entry produced substantial fleetwide savings.

Production Results Put the Memory Savings in Context
Cloudflare rolled out the optimization across production between May 18 and July 6, 2026. According to InfoQ’s account of the redesign, p99 resident memory per instance fell from 9.3 GB to 5.3 GB. At p90, memory declined from 6.5 GB to 3.8 GB.
Benchmarks measured the per-entry footprint falling from 953 to 420 bytes. Allocations decreased from 1.1 KB to 461 bytes. These measurements describe separate aspects of the change, alongside the reported improvements in insertion throughput and lookup latency.
Cloudflare intends to use the recovered memory to increase cache capacity without increasing overall memory consumption. That remains the company’s stated plan for the savings. The reported production rollout establishes the reduced memory use, rather than a completed expansion of cache capacity.
Smaller Representations Removed Repeated Overhead
One early change replaced Rust’s Vec and String with Box<[T]> and Box for data fixed after insertion. This saved 64 bytes per entry and more than 15 TB across the fleet. It addressed storage for information that would remain unchanged after entering the cache.
Cloudflare also combined answer, authority, and additional records into one list with compact offsets. It packed Booleans into bitflags. Owner names matching the queried domain could be omitted and reconstructed from the cache key.
Rust enums presented the largest challenge. Cloudflare initially boxed larger variants, but separate allocations introduced overhead and reduced memory locality. That intermediate approach exposed a tradeoff within the effort to reduce each entry’s footprint.
A Contiguous Buffer Became the Final Design
The final design stores record data in a contiguous byte buffer using DNS wire format. This removes enum overhead and per-record allocations, while improving locality. Frequently used record types can also be copied directly into responses.
The copying benefit has a qualification: records containing domain names still require parsing for DNS name compression. The final representation therefore does not remove every processing step. It changes the storage layout while retaining that requirement for those records.
Other recursive resolvers organize caches differently. Unbound maintains separate message, RRset, key, and negative caches, with configurable sizes and slab settings. PowerDNS Recursor also uses multiple cache types, including packet and record caches.
Cloudflare’s reported work focuses instead on representation and allocation overhead inside individual entries. With the production rollout complete, its intended next use for the freed memory is specific: more cache capacity within overall memory consumption.
