← DNS Providers
C

Cloudflare DNS (1.1.1.1)

Notable issues
Cloudflare · 🇺🇸 United States
PolicyApp PermissionsNetwork TrafficFirmwareRegulatory
Technical details
App: com.cloudflare.onedotonedotonedotone
Manufacturer: Cloudflare Inc.

The bottom line

Cloudflare says it will "never sell your data." Technically true -- they don't sell it. They trade it. The 1.1.1.1 address came from APNIC, the Asia-Pacific internet registry, under a research deal: Cloudflare gets the memorable IP address, APNIC gets DNS query data including every domain name resolved, query type, and resolver location. Cloudflare strips your IP address before sharing. But the entire service exists because of a data-for-infrastructure swap. "Privacy-first" has a footnote, and the footnote is a research agreement. Cloudflare told the world: no IP addresses are ever written to disk. An independent auditor found otherwise. KPMG discovered that Cloudflare's network monitoring samples 0.05% of all packets -- and those samples include the IP addresses of DNS queries. Written to disk. Cloudflare also said logs are wiped within 24 hours. Actually 25 hours. And some "anonymized" data? Kept forever. The audit passed because the overall system was privacy-respecting. But Cloudflare's specific claims -- "never" and "24 hours" -- were both wrong.

Legal jurisdiction
🇺🇸 United States (headquarters)
CLOUD Act read more →
US govt can demand your data from this company even if stored overseas
FISA §702 / PRISM read more →
NSA collects stored emails, photos, messages without individual warrants
Geofence warrants read more →
Police can demand location data for everyone near a crime scene
Audited by: Unknown (SOC 2 Type II, Jun 2024)
An audit is a snapshot, not a guarantee. How reliable are these auditors?
Spying
3/4 HIGH
Is someone spying on me?
Data Sharing
3/4 HIGH
Who gets my data?
Security
1/4 LOW
Is it actually secure?
Honesty
2/4 MODERATE
Can I trust what they say?
CONFIGURE High-risk areas that can be partially mitigated with settings changes.
7Contradictions
0Critical
3High
4Medium
5Sources
Findings by concern
Spying 3/4 HIGH 3 findings
⚡ highmarketing claims vs third party research
Cloudflare says it will "never sell your data." Technically true -- they don't sell it. They trade it. The 1.1.1.1 address came from APNIC, the Asia-Pacific internet registry, under a research deal: Cloudflare gets the memorable IP address, APNIC gets DNS query data including every domain name resolved, query type, and resolver location. Cloudflare strips your IP address before sharing. But the entire service exists because of a data-for-infrastructure swap. "Privacy-first" has a footnote, and the footnote is a research agreement.

What they claim: Cloudflare markets 1.1.1.1 as "the Internet's fastest, privacy-first consumer DNS service" that "will never sell your data."

What we found: Cloudflare obtained the 1.1.1.1 IP address from APNIC under a research agreement in which Cloudflare shares DNS query data -- including query names, query types, resolver location, and other metadata -- with APNIC Labs for "non-profit operational research." The agreement has an initial five-year term with renewal. APNIC may publish aggregated analysis at any time and share research data 12 months after receipt. Cloudflare strips client IPs before sharing, but the foundation of the "privacy-first" DNS service is a data-sharing arrangement. The address itself was the price for the data.

⚡ highmarketing claims vs third party research
Cloudflare told the world: no IP addresses are ever written to disk. An independent auditor found otherwise. KPMG discovered that Cloudflare's network monitoring samples 0.05% of all packets -- and those samples include the IP addresses of DNS queries. Written to disk. Cloudflare also said logs are wiped within 24 hours. Actually 25 hours. And some "anonymized" data? Kept forever. The audit passed because the overall system was privacy-respecting. But Cloudflare's specific claims -- "never" and "24 hours" -- were both wrong.

What they claim: Cloudflare stated that "no querying IP addresses are ever written to disk" and that "all logs are wiped within 24 hours."

What we found: The KPMG privacy audit discovered that Cloudflare's Netflow/Sflow network-wide monitoring retains 0.05% of all packets passing through their network, including the IP addresses of DNS queries -- contradicting the claim that no IPs are written to disk. The audit also found that logs are actually wiped within 25 hours, not 24, and that some anonymized data is retained indefinitely with no expiration date. The audit passed overall, but the specific discrepancies between marketing claims and observed practice were documented in the public report.

⚫ mediummarketing claims vs third party research
Cloudflare encrypts your DNS queries so nobody can intercept them. For 18 months, a certificate authority called Fina was issuing certificates for 1.1.1.1 without Cloudflare's permission -- 12 certificates in total. A security researcher had to find and report it. Meanwhile, the 1.1.1.1 address was BGP-hijacked twice, in 2024 and 2025, briefly sending DNS queries through networks Cloudflare doesn't control. The encryption protects you from eavesdroppers. It doesn't protect you when someone else has the keys or redirects the traffic.

What they claim: Cloudflare positions 1.1.1.1 as secure and trustworthy, supporting DNS-over-HTTPS and DNS-over-TLS to prevent query interception.

What we found: From February 2024 to August 2025, Fina CA issued 12 TLS certificates for the 1.1.1.1 IP address without Cloudflare's authorization. Security researcher Youfu Zhang reported the issue publicly on Mozilla's dev-security-policy mailing list in September 2025. An attacker with both an unauthorized certificate and its private key could have impersonated Cloudflare's resolver. Mozilla, Google, and Apple confirmed their browsers do not trust Fina's certificates, but Microsoft acknowledged the misissuance was valid in its trust store and began revocation. Separately, 1.1.1.1 was BGP-hijacked in July 2024 and July 2025, briefly routing queries through unauthorized networks.

Data Sharing 3/4 HIGH 3 findings
⚫ mediumpolicy claims vs third party research
Cloudflare says it shouldn't have the power to decide what's on the internet. Then it uses that power. Three times. The Daily Stormer in 2017. 8chan in 2019, after 23 people were murdered in El Paso -- and after CEO Matthew Prince first said he had a "moral obligation" to keep 8chan online. Kiwi Farms in 2022, three days after publicly refusing -- and after at least three suicides were linked to harassment on the site. Each time, Cloudflare apologized for acting. Each time, authoritarian governments quoted Cloudflare's own words back to demand takedowns of human rights sites. The company that processes 20% of internet traffic says it shouldn't have this power. It keeps using it anyway.

What they claim: Cloudflare has repeatedly stated it is a neutral infrastructure provider and should not make content moderation decisions: "The power to terminate security services for sites was not a power Cloudflare should hold."

What we found: Cloudflare terminated services for the Daily Stormer (2017), 8chan (2019, after the El Paso shooting that killed 23 people), and Kiwi Farms (2022, after trans streamer Clara Sorrenti's #DropKiwiFarms campaign and at least three suicides linked to Kiwi Farms harassment). CEO Matthew Prince initially defended 8chan, saying he had a "moral obligation" to keep it online. Cloudflare defended Kiwi Farms for three days before reversing. After each termination, Cloudflare published what critics called an "apology to the internet" and reported that authoritarian regimes began citing Cloudflare's own language to demand removal of human rights websites.

⚫ mediumpolicy claims vs third party research
Cloudflare will never sell your DNS data. They will keep anonymized versions of it forever. Research from MIT shows that just 4 data points can re-identify 95% of people in an "anonymized" dataset. Your DNS queries -- which sites you visit, when, how often -- are a fingerprint. And Cloudflare's DNS privacy policy is the strict one. The company also processes 20% of all web traffic through its CDN, governed by a more permissive corporate privacy policy. "Never sell your data" covers the DNS resolver. It doesn't cover the company.

What they claim: Cloudflare commits to "never sell your data" and states data retention is minimal and time-limited.

What we found: Cloudflare's privacy policy permits indefinite retention of "anonymized" DNS query data with no expiration. Research has repeatedly shown that anonymized datasets can be re-identified -- MIT researchers demonstrated that 4 data points can uniquely identify 95% of people in an anonymized dataset. DNS query patterns (which sites you visit, when, how often) are among the most fingerprint-able data types. Cloudflare also processes approximately 20% of all HTTP requests on the internet through its CDN and security services, governed by a separate, less restrictive corporate privacy policy. The DNS privacy promise applies to one product line within a company that sees a fifth of the internet.

⚫ mediumpolicy vs regulatory
Cloudflare told AI crawlers: separate your search indexing from your training data scraping by September, or get blocked. Sounds protective. But Cloudflare's own data shows the damage: more than half of all web traffic is now bots, and human visits to websites dropped 40% in one year. Cloudflare sits at the chokepoint of the internet — it sees the traffic, sets the rules, and decides who gets through.

What they claim: Cloudflare positions itself as a protector of the open internet and website operators

What we found: Cloudflare issued a September 2026 deadline requiring AI crawlers to separate search indexing from training data collection or face blocking. Cloudflare also reported more than 50% of web traffic is now non-human, and that human traffic to websites in finance, publishing, and retail dropped nearly 40% between June 2025 and April 2026. While protective of publishers, Cloudflare itself sits at the chokepoint — routing and inspecting traffic for millions of sites.

Honesty 2/4 MODERATE 1 finding
⚡ highmarketing claims vs app permissions
You download the 1.1.1.1 app because Cloudflare passed a KPMG privacy audit. The app asks you to turn on WARP for "a better Internet." You do. Now all your traffic -- not just DNS -- routes through Cloudflare. WARP collects your installation ID, how much data you transfer, your connection speed, and aggregate traffic by website. None of this was covered by the KPMG audit. The privacy reputation you trusted was earned by the DNS resolver. The product you're actually using is a VPN that was never independently examined.

What they claim: The 1.1.1.1 app's privacy reputation is built on KPMG-audited DNS resolver commitments. The app prominently features WARP, encouraging users to enable it for "a better Internet."

What we found: When users enable WARP in the 1.1.1.1 app, all device traffic is routed through Cloudflare's network -- not just DNS queries. WARP collects installation IDs, data transfer volumes, average connection speed, and aggregate traffic by website and by region. The KPMG privacy audit covered only the DNS resolver, not WARP. The separate 1.1.1.1 Application Privacy Policy (which covers WARP) permits collection of metadata that the DNS-only policy does not. Users who trust WARP based on the DNS audit are trusting a product that was never audited.

Sources