PublicDNS.info Live-tested public DNS
Retested every 72 hours.

Is Cloudflare DNS Secure?

Independent privacy and security audit of Cloudflare DNS DNS servers, with live monitoring data.

Last updated March 26, 2026

Passes Security Audit

Cloudflare DNS meets our security criteria with strong encryption support, DNSSEC validation, and no NXDOMAIN hijacking.

Security Audit Results

CheckResultDetails
DNSSEC Validation Yes Validates DNSSEC signatures, protecting against DNS spoofing.
NXDOMAIN Hijacking No Returns proper NXDOMAIN responses for non-existent domains.
DNS-over-TLS (DoT) Supported Encrypted DNS available on port 853. Prevents ISP snooping on DNS queries.
DNS-over-HTTPS (DoH) Supported HTTPS-based encrypted DNS available. Works through firewalls and is supported by most browsers.
Logging Policy Purged within 24 hours, audited by KPMG
Reliability 100% Based on continuous monitoring from our probe network.

Cloudflare DNS DNS Addresses

TypeIP Address
Primary 1.1.1.1
Secondary 1.0.0.1

Test Cloudflare DNS Yourself

Run a live privacy and security check on 1.1.1.1 from your location. Get DNSSEC, NXDOMAIN, encryption, and latency results in seconds.

Run Privacy Check on 1.1.1.1

How Cloudflare DNS Compares

See security audits for other DNS providers:

Related Guides

Frequently Asked Questions

Is Cloudflare DNS safe to use?

Cloudflare DNS passes our security audit with DNSSEC validation, no NXDOMAIN hijacking, and encrypted DNS support. It is safe for everyday use.

Does Cloudflare DNS log DNS queries?

Cloudflare DNS logging policy: Purged within 24 hours, audited by KPMG. Always review the provider's current privacy policy for the latest details.

Does Cloudflare DNS support encrypted DNS?

Cloudflare DNS supports both DNS-over-TLS (DoT) and DNS-over-HTTPS (DoH), providing full encryption for your DNS queries.

How reliable is Cloudflare DNS?

Cloudflare DNS (1.1.1.1) has a reliability score of 100% based on our continuous monitoring. This is excellent uptime.

What are the DNS addresses for Cloudflare DNS?

Primary: 1.1.1.1, Secondary: 1.0.0.1. Configure both for redundancy.