Cloudflare 1.1.1.1 for Families

  • Thread starter Thread starter Sushubh
  • Start date Start date
  • Replies Replies 15
  • Views Views 3,783

Sushubh

Admin
Staff member
Messages
406,867
Location
Gurgaon
ISP
Excitel
Airtel
Malware Blocking Only
Primary DNS: 1.1.1.2
Secondary DNS: 1.0.0.2

Malware and Adult Content
Primary DNS: 1.1.1.3
Secondary DNS: 1.0.0.3
In the coming months, we will provide the ability to define additional configuration settings for 1.1.1.1 for Families. This will include options to create specific whitelists and blacklists of certain sites. You will be able to set the times of the day when categories, such as social media, are blocked and get reports on your household's Internet usage.
 
 
For IPv6 use:

Malware Blocking Only
Primary DNS: 2606:4700:4700::1112
Secondary DNS: 2606:4700:4700::1002

Malware and Adult Content
Primary DNS: 2606:4700:4700::1113
Secondary DNS: 2606:4700:4700::1003
 
Will this malware-only blocking DNS (1.1.1.2) help block the problem of BSNL malware injection scripts/websites?
 
lol. probably not. plus i think most of the js is fetched through ip though i have seen domains mentioned as well. they do now have a NextDNS type product that lets you define your own blocklist.

 
So that's what this was:

 


1.1.1.1 app now has integrated support for Cloudflare 1.1.1.1 for Families and Cloudflare Gateway.

skJGc4i.png
 
1.1.1.3 is at par with opendns family security 208.67.222.123.
Infact better as it latches to India server, where opendns for me atleast usually latches to Singapore server.
 
Yes, to block malware, use security.cloudflare-dns.com, to block malware & adult content, use family.cloudflare-dns.com.

DNS over HTTPS settings. No support for DNS over TLS yet. So cannot be used on Android natively for now.

 
Last edited:
Sushubh yesterday half a day i spend with this Private DNS on Samsung A50s , but this family.cloudflare-dns.com does not work. It says Couldn't connect. Only cleanbrowsing works properly if you are in family security - family-filter-dns.cleanbrowsing.org

I research and concluded Cleanbrowsing.org is more systamatic in their approach towards security. Cloudflare.com has messed up with 1.1.1.3 ..... they are still to come up with proper solution for their two new variant for DOH and TLS.
The drawback of cleanbrowsing is that they do not anycast in India. I get their Europe servers which lag.
 
Last edited:
Actually i am using it for my son. He keeps a track of all apps. but this hidden setting down under is the area he would not experiment and hence using cleanbrowsing quietly and is working well. The lag is no issue there..

DOH
Coming to main point, I think Google has rivalry with mainly cloudflare as firefox by default uses the doh with cloudflare. In Chrome DOH is still not available to public unless you use the experiment settings. But it still fails to capture end point of cloudflare family security and uses pure 1.1.1.1 end point automatically. This Automatic capture of end points make it unreliable as they would only work if you have your local DNS set to either cloudflare/opendns/cleanbrowsing and google.

TLS
Atleast in Samsung, the cloudflare family does not connect. I have same feeling like DOH. The Automatic setting in Private DNS is for getting end points automatically if the device identifies that user is using either cloudflare/opendns/google/Clean browsing and automatically convert it to the TLS versions without checking that the family variants are required or generic versions. It will take few months for them to come to proper agreements and policy and then release versions/update addressing this
 
I am confused. 1.1.1.1 for Families doesn't support internal android private DNS feature at the moment. There is no automatic switching to doh or dot in Android. Windows 10 is planning to take that route.

You should check out Cloudflare Gateway or NextDNS if your aim is to have a kid friendly dns 😟
 
Its auto upgradable in Automatic setting in Chrome & Edge as far I researched.
But many questions are un answered as its not public yet. Firefox & Cloudflare 1.1.1.1 support doh in new releases since long time.
Windows 10 will address this issue as their Insider program is already work in progress. You can join insider program and tweak few regedit entries. (Thought I have stopped doing it as I once had to format my pc)

My understanding is that automatic setting in Android is in principle lines with the Auto upgrade of DOH in browsers. But I am not sure !!

DoH Providers
Here are the providers from milestone 83 and beyond:

ProviderAuto-upgradeableSettings Countries
Cleanbrowsing*
Cloudflare*
Comcast (N/A)(N/A)
DNS.SBEE, DE
Google*
IIJ(N/A)JP
OpenDNS(M85: TBC)(M85: TBC)
Quad9 *
CZ.NIC ODVR(M84: ✓) (M85: TBC) CZ
*: worldwide
 

Top