Cloudflare Launches 1.1.1.1 Public DNS
Published:
Cloudflare launched its public DNS resolver at the IP address 1.1.1.1 on April 1, 2018 — deliberately choosing April Fool’s Day for a memorable launch date — in partnership with APNIC (Asia-Pacific Network Information Centre). APNIC had owned the 1.1.1.1 address for years but had been unable to use it productively because router firmware worldwide had hardcoded it as a test address, flooding it with junk traffic; the partnership gave Cloudflare access to the memorable address while APNIC gained research data on global DNS query patterns. Cloudflare’s anycast network (servers in 150+ cities at that time) delivered median global response times of ~14 ms according to independent tracking by DNSPerf.com, compared to ~20 ms for Google’s 8.8.8.8 (launched December 2009) and ~20 ms for OpenDNS’s 208.67.222.222 (launched 2005) — making Cloudflare’s claim of “the world’s fastest DNS resolver” defensible at launch. The secondary resolver address was 1.0.0.1.
The privacy commitments were more detailed than previous public resolvers: Cloudflare published a policy promising not to sell DNS query data to advertisers or use it for ad targeting, to purge all logs of IP addresses within 24 hours, and to retain only aggregate statistics. KPMG was contracted to audit Cloudflare’s actual practices against the stated policy. This was a direct response to the context of the launch: the US Congress had repealed FCC broadband privacy rules in March 2017, legally permitting ISPs to sell customers’ browsing histories (which DNS queries effectively reveal — every domain you visit generates a DNS lookup). By using a third-party resolver instead of the ISP-assigned default, users could prevent ISP-level logging of domain queries, though Cloudflare itself then became the logging party under its stated privacy constraints.
DNS over HTTPS (DoH) support was available from launch at https://cloudflare-dns.com/dns-query, and DNS over TLS (DoT) at port 853 on cloudflare-dns.com — both protocols wrapping DNS queries in encrypted transport to prevent observation or modification by network intermediaries (eavesdroppers, ISPs, or rogue routers). Traditional DNS operated on UDP port 53 in plaintext since 1983, meaning that even when a website used HTTPS, the domain name lookup that preceded the connection was visible to any network observer. Mozilla Firefox made Cloudflare’s DoH resolver the default DNS provider for US users in February 2020, the first time a major browser changed the DNS resolution path away from the operating system’s configured resolver — a decision that generated controversy from ISPs and enterprise network administrators who relied on DNS for content filtering and internal hostname resolution. Cloudflare later launched 1.1.1.1 for Families in April 2020 (1.1.1.2 blocking malware, 1.1.1.3 blocking malware and adult content) and the WARP VPN product in April 2019, both built on the 1.1.1.1 resolver infrastructure.
