Set up
By default, the DNS server ↗ your devices use is provided by your Internet service provider (ISP). Some ISPs and network equipment providers partner with Cloudflare to add safer browsing to their offerings.
If your providers are not currently using Cloudflare, you can change the DNS settings on your device or router as detailed in the following instructions.
Device or router specific guides
  You can also set up 1.1.1.1 for Families for an added layer of protection on your home network against malware and adult content. 1.1.1.1 for Families leverages Cloudflare's global network to ensure that it is fast and secure around the world, and includes the same strong privacy guarantees that Cloudflare committed to when launching 1.1.1.1.
1.1.1.1 for Families categorizes destinations on the Internet based on the potential threat they pose regarding malware, phishing, or other types of security risks.
1.1.1.1 for Families has two default options:
Block malware
 Use the following DNS resolvers to block malicious content:
- 1.1.1.2
- 1.0.0.2
- 2606:4700:4700::1112
- 2606:4700:4700::1002
Block malware and adult content
 Use the following DNS resolvers to block malware and adult content:
- 1.1.1.3
- 1.0.0.3
- 2606:4700:4700::1113
- 2606:4700:4700::1003
Cloudflare returns 0.0.0.0 if the fully qualified domain name (FQDN) ↗ or IP in a DNS query is classified as malicious.
After configuring 1.1.1.1 for Families, you can test if it is working as intended with the following URLs:
- https://malware.testcategory.com/ ↗: Use this to test if 1.1.1.1 for Families is blocking known malware addresses correctly.
- https://nudity.testcategory.com/ ↗: Use this to test if 1.1.1.1 for Families is blocking known adult content and malware addresses correctly.
If you have a DoH-compliant client, such as a compatible router, you can set up 1.1.1.1 for Families to encrypt your DNS queries over HTTPS. This prevents spoofing and tracking by malicious actors, advertisers, ISPs, and others. For more information on DoH, refer to the Learning Center article on DNS encryption ↗.
To configure an encrypted DoH connection to 1.1.1.1 for Families, type one of the following URLs into the appropriate field of your DoH-compliant client:
Block malware
 https://security.cloudflare-dns.com/dns-queryBlock malware and adult content
 https://family.cloudflare-dns.com/dns-query1.1.1.1 for Families also supports DoT if you have a compliant client, such as a compatible DoT router. DoT allows you to encrypt your DNS queries, protecting you from spoofing, malicious actors, and others. You can learn more about DoT in the Learning Center article on DNS encryption ↗.
To configure an encrypted DoT connection to 1.1.1.1 for Families, type one of the following URLs into the appropriate field of your DoT-compliant client:
Block malware
 security.cloudflare-dns.comBlock malware and adult content
 family.cloudflare-dns.comWas this helpful?
- Resources
- API
- New to Cloudflare?
- Products
- Sponsorships
- Open Source
- Support
- Help Center
- System Status
- Compliance
- GDPR
- Company
- cloudflare.com
- Our team
- Careers
- © 2025 Cloudflare, Inc.
- Privacy Policy
- Terms of Use
- Report Security Issues
- Trademark