1.1.1.1 Passes Its Second Independent Privacy Audit
Cloudflare's 1.1.1.1 public DNS resolver launched eight years ago with a dual mandate: be the fastest resolver on the Internet and the most private. The company argued that trust is the foundation of any service handling the "phonebook of the Internet," and backed that stance up in 2020 with an independent audit by a Big 4 accounting firm to verify its privacy claims rather than asking users to take them on faith.
Since that first examination, Cloudflare's DNS infrastructure has undergone significant architectural change. The company built an entirely new platform to power 1.1.1.1 and its other DNS systems. That evolution prompted a second comprehensive review, the results of which the company is now sharing: the same accounting firm has completed a fresh privacy examination covering the 2024 calendar year, and the final report is available on Cloudflare's compliance page.
The audit process required several months of evidence collection across many Cloudflare teams. The resulting report confirms that the core privacy guarantees established at launch remain intact:
- Cloudflare will not sell or share public resolver users' personal data with third parties, nor use that data to target users with advertisements.
- Cloudflare retains only the information needed to answer a query, not information identifying who asked it.
- Source IP addresses are anonymized and deleted within 25 hours.
Scope Notes and Transparency Points
The company took the opportunity to clarify two aspects of the audit. First, as detailed in the original 2020 report, Cloudflare samples network packets at a rate of at most 0.05% of all traffic. Those samples include querying IP addresses and are used solely for network troubleshooting and attack mitigation.
Second, the current examination's scope differs from the 2020 audit. That first review covered all of Cloudflare's representations about the resolver, including how anonymized transaction and debug logs ("Public Resolver Logs") would be handled for operational and research purposes. Over time, use cases for that data have evolved — Cloudflare Radar, launched after the first examination, is one example — although the company stresses that these changes have no impact on personal information or privacy.
Cloudflare reiterated the stance it took with the initial review: the company doesn't want to know what individuals do online and has taken technical measures to ensure it cannot. Its Privacy Policy commits to never combining 1.1.1.1 DNS query data with any other Cloudflare or third-party data in a way that could identify individual end users. The company notes that no other major public resolver has subjected its practices to similar independent examination, and it positions the audit as a call for industry-wide standards on DNS privacy.
The full accountant's report is available on Cloudflare's certifications and compliance resources page, and setup documentation for the resolver can be found at https://developers.cloudflare.com/1.1.1.1/.



