Resource Review12 min read

Cloudflare 1.1.1.1 for Families

4.5App Store rating · 216K ratings

Two numbers in a router and every device on the network stops resolving malware and adult-content domains, free, with no account and no device limit. The catch is everything DNS cannot see - and Cloudflare's own developer documentation is where you find it.

Starting price
Free
Free tier
Yes
Platforms
Router - iOS - Android - Windows - macOS - Linux - Consoles
Developer
Cloudflare Inc.
Launched
2020
Updated
Jul 26, 2026
Free - no account requiredPrice
1.1.1.2 / 1.0.0.2 and 1.1.1.3 / 1.0.0.3Resolver pairs
4.5 from 215,920 ratings (1.1.1.1 / WARP app)App Store rating
Anonymised and deleted within 25 hoursSource IP retention
6.31.5, released 7 July 2026App version

The verdict

Cloudflare 1.1.1.1 for Families is the best free network-level content filter available, and it is not an accountability tool. Point a router at 1.1.1.3 in two minutes as a baseline layer for a household with young children. If you need reporting, per-child policy, or anything a motivated teenager cannot switch off in thirty seconds, this is the wrong product and no amount of configuration will make it the right one.

Try Cloudflare 1.1.1.1 for Families

Opens one.one.one.one

Cloudflare runs one of the largest public DNS resolvers in the world, and in April 2020 it pointed a few spare addresses at a filtered version of it. 1.1.1.2 and its backup 1.0.0.2 decline to resolve domains Cloudflare associates with malware and phishing. 1.1.1.3 and 1.0.0.3 do the same and add adult content. There is no signup, no dashboard, no card on file and no per-device install: you type four numbers into a router and the whole house sits behind a filter in, as the official page puts it, less than two minutes.

That is genuinely useful, and it is also where the product is most widely misunderstood. DNS is a phone book. A filtered resolver can refuse to look up a number; it cannot listen to the call. Cloudflare implements the block by returning 0.0.0.0 for a flagged domain, per its own setup documentation, so the browser simply fails to connect - no block page, no explanation, no record. Nothing in that mechanism produces a log a parent can read, a policy that separates a seven-year-old from an adult, or a notification when someone tries.

The App Store figure attached to this listing needs a caveat stated plainly. The 4.5 from 215,920 ratings belongs to 1.1.1.1: Faster Internet, Cloudflare's consumer WARP app, which is primarily a privacy and speed product. 1.1.1.1 for Families is a toggle inside its DNS settings, and the resolvers themselves have no store listing at all because they are IP addresses. The rating says nothing about how well the family filter catches what a parent hopes it will.

Cloudflare is unusually candid about the ceiling, though you find it in the developer documentation rather than on the marketing page. The page for network operators tells anyone wanting customisable DNS policies, analytics, additional filtering categories or custom rate limiting to use Cloudflare Zero Trust instead. Read that as an inventory of what 1.1.1.1 for Families lacks.

✓ The good

  • Free with no account and no expiry - neither resolver pair costs anything and Cloudflare does not ask for an email address, so there is no trial clock and no subscription to cancel.
  • Two-minute router change covers every device - a games console, a smart television, a guest laptop and a visiting relative's phone all inherit the filter, and none of them would accept a filtering agent.
  • Encrypted transport is documented and free - DNS-over-HTTPS at security.cloudflare-dns.com/dns-query and family.cloudflare-dns.com/dns-query, plus DNS-over-TLS at the same hostnames, so filtered lookups need not travel in clear text.
  • Full IPv6 parity - 2606:4700:4700::1112 and ::1002 for malware only, ::1113 and ::1003 for malware plus adult content, which matters because a dual-stack home that filters only IPv4 effectively filters nothing.
  • A malware-only tier most family filters do not offer - 1.1.1.2 gives phishing and malware protection with no content judgement attached, the correct setting for a great many homes.
  • Independently examined privacy commitments - a Big Four firm examined Cloudflare's public resolver commitments for calendar 2024, and source IP addresses are anonymised and deleted within 25 hours.

✗ Watch out

  • No logs, no reports and no alerts - Cloudflare's network operators page directs anyone wanting analytics or customisable DNS policies to Cloudflare Zero Trust, which is a straightforward admission that Families has neither.
  • Bypassed by anything that changes the resolver - a device pointed at another DNS server, a VPN, a browser doing its own DNS-over-HTTPS, or a phone on cellular never touches 1.1.1.3. Cloudflare's iOS guide states that manual configuration applies only to the current Wi-Fi network and does not work for cellular connections.
  • One policy for everybody, with no schedule - the resolver cannot tell a child from a parent, so there is no per-user rule, no bedtime, no time allowance and no temporary override.
  • Blocking is silent - returning 0.0.0.0 means a false positive presents as a broken website, not a filter notice, and Cloudflare publishes no allowlist or reclassification process for these resolvers. Its 1.1.1.1 FAQ does not mention Families at all.
  • Exactly two fixed categories - malware only, or malware plus adult content. No gambling, self-harm, social media or streaming category, no custom blocklist, no allowlist and no SafeSearch enforcement.
  • The category data is licensed in, and has shipped wrong - on 2 April 2020 Cloudflare included the wrong Adult Content definition from a third-party provider in the production build and 1.1.1.3 blocked LGBTQIA+ sites for roughly two hours.

Best for

  • Households with pre-teens wanting a baseline layer
  • Renters and parents who cannot install software on every device
  • Smart TVs, consoles and IoT devices that reject filtering agents
  • Adults who want malware blocking without a content filter

Avoid if

  • Parenting a technically capable teenager
  • You need reports an accountability partner can read
  • You need per-child rules or screen-time schedules
  • Recovery from compulsive pornography use

What Cloudflare 1.1.1.1 for Families is

1.1.1.1 for Families is a filtered public DNS resolver, not an app and not a parental control suite. Cloudflare runs two variants beside the unfiltered 1.1.1.1: the 1.1.1.2 pair, blocking queries to domains associated with malware and phishing, and the 1.1.1.3 pair, which adds adult content. Configuration means replacing the DNS addresses on a router, laptop or phone. Any device that then asks that resolver where a domain lives gets 0.0.0.0 back if the domain is listed.

The 1.1.1.1 mobile app is a separate product that happens to expose the same service. It is Cloudflare's consumer WARP client - a privacy tunnel first - with a DNS screen where Families can be enabled, and it is the only supported route to filtering a phone's mobile data.

Free, invisible, and nobody owns the configuration

Every commercial filter in this category sells a subscription, an agent and an account. Cloudflare sells none of the three, and the consequences run both ways. With no agent there is nothing to install on a Nintendo Switch, a smart television or a school-managed Chromebook. With no account there is nobody to log in as, no per-child profile and no history. The product is a pair of numbers, and numbers cannot report to you.

The other real differentiator is that the filtering runs on the same infrastructure as a heavily used unfiltered resolver, examined for privacy by an outside accounting firm, with anonymised source IP addresses deleted within 25 hours. That is a genuine virtue and it is also why there is nothing to review: a resolver that deliberately forgets who asked cannot produce the record a supervising parent wants. Privacy and accountability are incompatible here, and Cloudflare chose privacy.

The two resolver pairs, and which one you actually want

Malware only is 1.1.1.2 with 1.0.0.2 as secondary, or 2606:4700:4700::1112 and ::1002 over IPv6; Cloudflare documents it as blocking queries to domains associated with malware and phishing. Malware plus adult content is 1.1.1.3 with 1.0.0.3, or ::1113 and ::1003. Encrypted variants exist for both, at security.cloudflare-dns.com and family.cloudflare-dns.com. Enter the IPv6 addresses too if the line carries IPv6, or lookups route around the filter.

Households should weigh 1.1.1.2 more seriously than they do: pure security, no content judgement, no misclassification risk, and the right default for an adults-only network. 1.1.1.3 carries the category risk. Cloudflare's April 2020 post-mortem describes shipping the wrong Adult Content feed - one provider definition matched Google SafeSearch criteria, another was broader - which blocked LGBTQIA+ and sex-education sites for about two hours.

The 1.1.1.1 app, and why a phone is the hard case

A router change covers the house and stops at the front door. Once a phone leaves the Wi-Fi it resolves through the carrier and the filter is gone. Cloudflare says so in its iOS guide: manual configuration applies only to the Wi-Fi network you are currently connected to, and does not work for cellular connections. Its recommended fix is the 1.1.1.1 app, which applies Cloudflare on any network including cellular.

That solves coverage and creates a governance problem. The app is a free download rated 17+ with an Unrestricted Web Access advisory, its headline pitch is that it encrypts more of the traffic leaving your phone so nobody can snoop on you, and no parent PIN on the Families toggle is documented. Cloudflare advertises resistance to network observation in the same binary it recommends for family filtering.

What DNS filtering cannot see

A resolver works on domain names, so its resolution is exactly one domain wide. If a domain is allowed, everything served from it is allowed: explicit results inside an image search on an allowed engine, material inside an allowed social platform, video site or link shortener. There is no SafeSearch enforcement, so 1.1.1.3 rewrites nothing on a page, and most of what parents worry about in 2026 arrives inside domains no filter can block wholesale.

It is blind in the other direction too. It cannot see an app talking to hard-coded IP addresses, encrypted DNS inside a browser that ships its own resolver, a VPN, a tethered second phone or a friend's hotspot, and Cloudflare notes that security scanning or proxied traffic may in rare cases be rate limited. None of this is an implementation defect. It is what the DNS layer is.

Pricing

Best value

1.1.1.1 for Families resolvers

Free

Both pairs - 1.1.1.2 and 1.0.0.2 for malware and phishing, 1.1.1.3 and 1.0.0.3 for malware plus adult content, with matching 2606:4700:4700 IPv6 addresses - are free with no account, no device cap and no expiry. Cloudflare funds the public resolver from its commercial business and states it does not sell resolver users personal data or use it for targeted advertising.

1.1.1.1 app for iOS and Android

Free

The consumer WARP app is free and carries the 1.1.1.1 for Families switch in its DNS settings. It is the practical way to apply the filter to a phone's cellular connection, because iOS manual DNS settings apply only to the current Wi-Fi network. Nothing documented locks that switch with a parent PIN.

WARP+

Paid monthly subscription - amount not published in the App Store listing

The store description says WARP+ is a paid in-app subscription unlocking a larger Cloudflare network for lower latency, with free WARP+ data earnable by referring friends. It is a speed upgrade to the privacy tunnel and adds nothing to the family filter. No dollar figure appears in the store metadata.

The resolvers are free, with no account, no device cap and no tier that unlocks reporting. Cloudflare funds the public resolver from a business that sells network services to companies, and states it does not sell or share public resolver users personal data or use it to target advertising.

The app is free too, and its paid product is unrelated to filtering. The store description sells WARP+ as a monthly in-app subscription for access to a larger Cloudflare network and lower latency - and no price appears anywhere in the store metadata, so a buyer cannot see the cost before opening the app. That is a disclosure gap, not an estimate on our part.

The honest paid comparison is not WARP+ but Cloudflare Zero Trust, which the company points network operators toward for customisable DNS policies, analytics, extra categories and custom rate limiting. That is enterprise tooling with a login, per-user policy and query logs, and it is administratively heavy for a family.

Against the market the arithmetic is stark. Canopy lists its ten-device Family plan at $9.99 per month billed annually, which is $119.88 a year, against $0.00 for unlimited devices here. The comparison only means something if the products do the same job, and they do not: Canopy is on-device software with per-child controls and parent notifications, Cloudflare is a filtered phone book.

Where Cloudflare 1.1.1.1 for Families falls behind

No reporting of any kind. This is the disqualifying gap, and it is a design consequence of anonymising source IP addresses and deleting them within 25 hours rather than an oversight. A parent cannot see which sites were blocked, which were attempted, from which device, or when, and an accountability partner has nothing to receive. Covenant Eyes exists because a silent block is a different intervention from showing a trusted person what happened.

Nothing here survives a motivated teenager. Changing DNS on a laptop takes under a minute, a free VPN takes two, enabling DNS-over-HTTPS in a browser takes three clicks, and moving from Wi-Fi to cellular defeats a router filter with one tap. There is no tamper alert because there is no telemetry to notice tampering. Canopy, Safe Surfer and Tech Lockdown put a supervised agent or locked configuration profile on the device so removal is blocked or noticed.

One policy for the entire household. Everyone on the network is treated identically, so a parent who wants 1.1.1.3 for a nine-year-old gets it themselves, with no exception and no override. There is no schedule, so no homework window and no device curfew, and no way to relax the filter for a fifteen-year-old while tightening it for a seven-year-old.

Domain-level granularity and two fixed categories. No gambling, self-harm, social media or streaming category, no custom blocklist, no allowlist. Adult content comes from a licensed third-party feed Cloudflare says it intends to align with the Google SafeSearch definition of sexually explicit content, and a household cannot inspect, tune or dispute it. A misclassified site simply will not load, and Cloudflare's 1.1.1.1 FAQ does not mention the Families service at all.

Cloudflare 1.1.1.1 for Families vs. Canopy vs. Safe Surfer vs. Tech Lockdown

These four are layers rather than substitutes, and treating them as interchangeable is the error this product invites. Cloudflare is a network-level DNS filter: free, universal, zero visibility. Canopy is on-device software with per-child device assignment, app and website blocking, screen-time management and parent alerts, listed at $8.33 per month billed annually for three devices and $9.99 for ten. Safe Surfer sells a five-device Pro Surfer subscription with category blocking, screen time, browsing history and activity alerts, and prints no dollar amounts on its pricing page. Tech Lockdown sells a rule engine: block, allow and SafeSearch rules by device, audience and schedule, with traffic logs and profile locking.

The functional difference reduces to one question: does anything tell you what happened? The other three answer yes, in different currencies - alerts, browsing history, traffic logs. Cloudflare answers no, deliberately and permanently. That is why it is not a substitute for Canopy in a house with children, and not remotely one for Covenant Eyes for an adult working on compulsive use, which rests on a human relationship: activity goes to a chosen ally who can ask about it. Cloudflare has no ally, no report and no memory of the query.

The sensible configuration is Cloudflare underneath one of the others, not instead of it. Point the router at 1.1.1.3 so consoles, televisions and guest devices inherit a baseline no paid agent can reach, and run Canopy, Safe Surfer or Tech Lockdown on the phones and laptops where per-user policy and visibility matter.

The bottom line

Judged as what it is, 1.1.1.1 for Families is excellent: a free, fast, privacy-examined resolver any household can deploy in two minutes, covering device classes no paid agent can touch. Judged as an accountability product it fails, and Cloudflare's own documentation is the evidence - the network operators page sends anyone wanting policies, categories or analytics to Zero Trust. Set 1.1.1.3 on the router today because it costs nothing. Then, if there is a teenager in the house or an adult in recovery, buy the product that reports.

Alternatives to Cloudflare 1.1.1.1 for Families

Frequently asked questions

What are the 1.1.1.1 for Families addresses?

For malware and phishing only, use 1.1.1.2 with 1.0.0.2 as secondary, or 2606:4700:4700::1112 and 2606:4700:4700::1002 over IPv6. For malware plus adult content, use 1.1.1.3 and 1.0.0.3, or 2606:4700:4700::1113 and 2606:4700:4700::1003. Encrypted endpoints exist too: DNS-over-HTTPS at security.cloudflare-dns.com/dns-query and family.cloudflare-dns.com/dns-query, and DNS-over-TLS at those hostnames. Enter the IPv6 addresses if your connection carries IPv6, or half the traffic resolves unfiltered.

Can a child bypass it?

Yes, easily and in several ways. Changing the DNS server on a laptop or phone takes under a minute. A free VPN routes around it entirely. A browser with its own DNS-over-HTTPS resolver ignores the network setting. And switching from Wi-Fi to cellular defeats a router-level filter with one tap, which Cloudflare itself notes in its iOS guide. There is no tamper alert, because there is no telemetry that could raise one.

Can I see what was blocked?

No. There is no dashboard, no history and no notification, and this is design rather than omission: Cloudflare anonymises source IP addresses and deletes them within 25 hours. A blocked domain resolves to 0.0.0.0, so the site fails to load with no message. If you need a record a parent or accountability partner can read, this product cannot be configured to produce one.

Does the 4.5 App Store rating apply to the family filter?

Not directly, and it is worth being clear about this. The 4.5 average from 215,920 ratings belongs to 1.1.1.1: Faster Internet, Cloudflare's consumer WARP app, which is mainly a privacy and speed tool. 1.1.1.1 for Families is one toggle in that app's DNS settings, and the resolvers have no store listing because they are IP addresses. Those votes reflect satisfaction with a VPN-style utility, not an assessment of filtering accuracy.

Has the adult content filter ever blocked the wrong sites?

Yes, and Cloudflare published the post-mortem itself. On 2 April 2020 it shipped the wrong Adult Content category from its data provider - one feed matched the narrower Google SafeSearch definition of sexually explicit content, another was broader - and 1.1.1.3 blocked LGBTQIA+ and sex-education sites. Cloudflare says corrected data was generated roughly two hours after the first report.

Is this a replacement for Canopy or Covenant Eyes?

No. Canopy puts software on each device for per-child rules, app blocking, screen-time limits and parent alerts. Covenant Eyes reports activity to a chosen ally, so the mechanism is a human conversation. Cloudflare provides neither: no per-user policy, no alerts, no reports and no ally. Run 1.1.1.3 on the router underneath one of those products so consoles, televisions and guest devices get a baseline, and keep paying for the layer that reports.

Sources & further reading

More Accountability & Filtering Apps

Try Cloudflare 1.1.1.1 for Families