DNS query volume from AS49023
Copy linkDNS queries to 1.1.1.1
Learn more...The traffic analysis presented here is based on anonymized DNS query logs, in accordance with Cloudflare's Privacy Policy, as well as our 1.1.1.1 Public DNS Resolver privacy commitments.
DNSSEC adds a signing layer to DNS, protecting responses from tampering
Posts tagged with "1.1.1.1" from the Cloudflare blog
On May 5, 2026, DENIC published broken DNSSEC signatures for the .de TLD, making millions of domains unreachable. Here's what 1.1.1.1 saw, how serve stale cushioned the impact, and how we restored resolution.
Eight years ago, we launched 1.1.1.1 to build a faster, more private Internet. Today, we’re sharing the results of our latest independent examination. The result: our privacy protections are working exactly as promised.
A recent change to 1.1.1.1 accidentally altered the order of CNAME records in DNS responses, breaking resolution for some clients. This post explores the technical root cause, examines the source code of affected resolvers, and dives into the inherent ambiguities of the DNS RFCs.