Our ongoing commitment to privacy for the 1.1.1.1 public DNS resolver
Key Points
- Independent Big 4 audit confirms privacy guarantees
- Source IPs anonymized and deleted within 25 hours
- Up to 0.05% packet sampling used only for troubleshooting
Summary
Cloudflare completed a new independent privacy examination of the 1.1.1.1 public DNS resolver (same Big 4 firm that reviewed the service in 2020). The auditors reviewed evidence gathered after 2024 and confirmed Cloudflare’s core privacy commitments: resolver data is not sold or shared for advertising, source IPs are anonymized and deleted within 25 hours, and resolver data is not combined with other datasets to identify users. The full auditor report and supporting details are published on Cloudflare’s Certifications & compliance page.
Key Points
- Independent Big 4 audit completed and publicly published; evidence collection spanned multiple Cloudflare teams following the 2024 year-end.
- Core guarantees affirmed: no sale/share of public resolver personal data, no advertising targeting from resolver data, and no combining resolver queries with other data to identify users.
- Source IP addresses are anonymized and deleted within 25 hours (retention limit confirmed).
- Random packet sampling (max 0.05% of traffic, may include querying IP) is used only for network troubleshooting and attack mitigation.
- The current examination focused specifically on privacy commitments; prior reviews covered broader representations including public resolver logs used for operational and research purposes (e.g., Cloudflare Radar).
- Report and compliance resources available on Cloudflare’s compliance/certifications pages; developers page (https://developers.cloudflare.com/1.1.1.1/) has setup and usage information.