Back to blog
dns Published: AEU DNS Newsroom

Cloudflare renews privacy pledge for its public 1.1.1.1 DNS resolver

Cloudflare renews privacy pledge for its public 1.1.1.1 DNS resolver

Cloudflare's April 2026 update on 1.1.1.1 explains why encrypted DNS and limited logging remain essential for everyday internet users.

On April 1, 2026, Cloudflare published a new blog post titled 'Our ongoing commitment to privacy for the 1.1.1.1 public DNS resolver,' written by Rory Malone, Hannes Gerhart, and Leah Romm. The announcement is a clear signal that the company continues to treat privacy as a core requirement for its widely used public DNS service, not a one-time marketing promise. DNS, or the Domain Name System, acts as the internet's address book: it translates the website names people type into their browsers into the numerical IP addresses computers need to communicate.

Every time you visit a website, your device first sends a DNS query to a resolver. If that query travels over an unencrypted connection, anyone on the same network, including your internet service provider, can see exactly which sites you are trying to reach. The 1.1.1.1 resolver was launched in 2018 to offer a faster, more private alternative to the default resolvers operated by many internet providers. It supports encrypted DNS protocols such as DNS over HTTPS (DoH), DNS over TLS (DoT), and DNS over QUIC (DoQ). DoH places DNS queries inside regular HTTPS web traffic, DoT uses a dedicated secure channel, and DoQ runs DNS over QUIC, a modern transport protocol built for speed and resilience. All three hide DNS lookups from eavesdroppers on the network path.

Encryption alone does not make a resolver private, however. A truly privacy-first operator must also limit what data it records about its users. Many DNS providers keep detailed logs of every domain requested, often for advertising or profiling. A no-logs or minimal-logs policy means the resolver does not retain the full history of your browsing activity for longer than needed to operate the service. Cloudflare has previously published transparency reports and committed to independent privacy audits, and this April 2026 update is part of that ongoing accountability. The post does not announce a specific new feature, but it reinforces the practical steps that users and businesses should expect from any DNS provider they trust.

For everyday internet users and small business owners, the main takeaway is that switching to a privacy-conscious encrypted DNS resolver is one of the simplest and most effective privacy improvements available. It takes only a few minutes and can be done on a single device, such as a phone or laptop, or on a home router to cover every smart TV, game console, and computer on the network. Before choosing a resolver, check whether it publishes a clear privacy policy, has undergone independent audits, and supports modern encrypted protocols. Because DNS is the first step in every connection, a resolver that respects privacy removes a significant source of tracking and data collection.

The Cloudflare post also highlights the importance of continuous commitment. Privacy standards and threats change over time, so a resolver must be willing to be held accountable long after launch. For readers who want a comparable privacy-first option based in Europe, AEU DNS offers encrypted DNS over HTTPS, TLS, and QUIC with a no-logs policy, giving individuals and businesses a way to reduce exposure through their network settings. No matter which trusted resolver you choose, the key is to move away from unencrypted, data-hungry defaults and take control of the first step of your internet journey.

Terms explained

DNS
The Domain Name System, which translates website names like example.com into the numerical IP addresses that computers use to find each other on the internet.
DoH
DNS over HTTPS, a method of sending DNS requests inside regular secure web traffic so that others on the network cannot see which sites you are looking up.
DoT
DNS over TLS, a way to encrypt DNS requests using a dedicated secure channel, protecting them from eavesdroppers.
DoQ
DNS over QUIC, a modern encrypted DNS method that uses the fast and reliable QUIC transport protocol to hide DNS lookups.
no-logs policy
A promise by a service provider not to keep a permanent record of your activity, so your browsing history cannot be stored or shared.

How to protect yourself

  1. Check which DNS resolver your device is currently using, and switch to a trusted encrypted DNS service such as 1.1.1.1 or AEU DNS in your network settings or browser.
  2. Turn on DNS over HTTPS (DoH) in your web browser if it is supported, so your DNS requests are hidden from your internet provider's view.
  3. Change the DNS settings on your home router to a privacy-first encrypted resolver, which protects every device on your Wi-Fi network at once.
  4. Before choosing a DNS provider, read its privacy policy to confirm it has a no-logs or minimal-logs policy and has undergone independent privacy audits.
  5. Enable DNSSEC validation in your device or router settings if available, because it helps block forged DNS responses that could send you to fake websites.

Source: blog.cloudflare.com

Get private, encrypted DNS