dns · · 15 min read

Cloudflare DNS vs Google Public DNS: How to Choose for Privacy, Filtering, and Speed

1.1.1.1 or 8.8.8.8? A plain-English guide to how Cloudflare DNS and Google Public DNS differ on privacy, family filtering, encryption, and speed, with setup steps for every platform, ways to verify it works, and common questions.

Mttao Mttao @bearboy80 3,168 words 中文 →

There are endless threads asking “1.1.1.1 or 8.8.8.8?”, and most of them end up as a pile of speed-test screenshots. One person says Cloudflare was 3 ms faster, someone else says Google felt a bit steadier. You finish reading and still have no idea which one to pick.

The truth is, for most people a few milliseconds is impossible to notice. The questions actually worth thinking about are different ones: Do you care whether your browsing history gets logged? Do you have kids at home, and do you want to block the sketchy corners of the internet? Is this a work computer?

Answer those, and the choice mostly makes itself. If you’re in a hurry, here’s the short version:

If you care about privacy, or you want to filter malicious and adult sites for your household, go with Cloudflare’s 1.1.1.1. If you just want a reliable DNS, either one is fine — try each on your own network for a few days and keep whichever feels better. If it’s a work or school computer, leave it alone and ask IT first.

Now for the longer version.

A one-minute primer on DNS

When you type example.com into your browser, your computer doesn’t actually understand those letters. It needs the site’s IP address (a string of numbers) before it knows where to connect.

The thing that translates names into IP addresses is DNS. Think of it as a giant phone book: you give it a name, it gives you a number.

This happens constantly. A single web page might pull images, ads, and analytics scripts from a dozen different domains, and every one of them needs a lookup. It’s just so fast you never notice.

The DNS you use by default is usually assigned automatically by your internet provider — you probably don’t even know who it is. Switching to 1.1.1.1 or 8.8.8.8 simply means: from now on, instead of asking my ISP to look things up in the phone book, ask Cloudflare or Google.

Who are these two

Google Public DNS launched back in 2009 with the easy-to-remember 8.8.8.8, making it one of the veterans of public DNS. For a lot of people, it was the first DNS they ever typed in by hand.

Cloudflare’s 1.1.1.1 launched on April 1, 2018. Picking April Fools’ Day for the release was very on-brand for Cloudflare. From day one it led with privacy, promising not to make money from user data and bringing in a third-party auditor to check.

Both are big companies with servers all over the world, so reliability isn’t really a concern with either. The differences show up in a few specific places.

Before you switch, keep your expectations in check

A lot of people assume that changing their DNS makes them “secure” or “anonymous.” Time for a little cold water.

Switching DNS does have real benefits. Paired with encryption, it makes it harder for your ISP or a public Wi-Fi network to see which sites you visit. Pick the right service and it can also block some phishing and malware sites along the way.

But it won’t make you invisible. When you send your lookups to Cloudflare or Google, of course they know what you looked up — otherwise they couldn’t answer. The sites you visit still see your IP address too. And it’s no substitute for a VPN: DNS only handles the “find the address” step. What travels between you and the website afterward is none of its business.

So switching DNS is more like putting a better lock on your door than hiding your house.

Difference #1: Who remembers less

This is where the two differ the most.

First, what they have in common: both publicly promise not to sell your DNS data or use it for advertising. You don’t need to worry about that part.

What differs is how much they keep, and for how long.

Cloudflare is pretty stingy about it: your full IP address basically never gets stored. Any trimmed-down logs it does keep are deleted within 25 hours. It retains some aggregate stats — things like which sites are popular worldwide — but nothing in that data can identify you.

Google temporarily stores query logs that include your IP and deletes them within 24 to 48 hours. It also keeps a sampled set of data long-term. The IP is removed, but it may still include the domains you looked up and roughly which city you’re in. During security or abuse investigations, relevant data may be kept a bit longer.

Here’s one way to picture it: Cloudflare is a sticky note you tear up after reading. Google is a notebook that gets cleaned out regularly but keeps a few anonymous tallies. Neither is unreasonable, but if you’re privacy-conscious, Cloudflare is the one that’ll put your mind more at ease.

One more small detail. When you make a lookup, Google tells the website roughly which region you’re in, so the site can point you to a nearby server — sometimes that makes video or downloads a bit faster. Cloudflare generally doesn’t do this. Better privacy, at the cost of some sites occasionally sending you to a server that’s not quite as close. It’s a small privacy-versus-speed tradeoff, and most of the time you won’t notice it.

Difference #2: Can it block bad sites for your family

Cloudflare wins this one outright.

Standard 1.1.1.1 and 8.8.8.8 are both hands-off: whatever site you ask for, they give you the address.

But Cloudflare also offers a family version called 1.1.1.1 for Families, with two levels:

1.1.1.2 and 1.0.0.2 block known malware and phishing sites. Good if you want an extra layer of protection without restricting much else.

1.1.1.3 and 1.0.0.3 do all of that and also block adult content. Good if you have kids at home.

Blocked sites simply won’t load — as if they don’t exist.

The easiest way to use it is to put it on your home router. That way every device on your Wi-Fi — phones, tablets, laptops, the TV — is covered at once, with nothing to install on each one. Google has no equivalent.

Don’t think of it as a cure-all, though. It blocks based on site categories, and those categories are sometimes wrong, so legitimate sites can get caught. If a kid switches to mobile data or changes the DNS on their own device, the filter stops working. It’s a good first line of defense, not a complete parental-control setup.

Address cheat sheet

What you wantCloudflareGoogle
Standard, no filtering1.1.1.1 and 1.0.0.18.8.8.8 and 8.8.4.4
Block malicious sites1.1.1.2 and 1.0.0.2Not available
Block malicious + adult sites1.1.1.3 and 1.0.0.3Not available
IPv6 (skip if you’re not sure)2606:4700:4700::1111 and 2606:4700:4700::10012001:4860:4860::8888 and 2001:4860:4860::8844

Most settings screens ask for two DNS servers, a primary and a secondary. Use the same provider for both — for example 1.1.1.1 plus 1.0.0.1 — rather than mixing them. More on why below.

Difference #3: Encryption

Traditional DNS lookups aren’t encrypted. It’s like sending a postcard: the mail carrier, the sorting staff, anyone who handles it along the way can read what you wrote. If you’re on coffee-shop Wi-Fi, whoever runs that network can, in principle, see which sites you look up.

Encrypted DNS puts the postcard in an envelope. The two common flavors are DoH (over HTTPS) and DoT (over TLS). You don’t need to remember the difference — just know they’re both “encrypted.” Other people can see that you sent a letter to Cloudflare or Google, but not what’s inside.

Both providers support this, and there’s not much difference between them here. Cloudflare also offers something called ODoH, which takes privacy a step further, but most people won’t need it.

Here’s a trap a lot of people fall into: typing 1.1.1.1 into your network settings does not turn on encryption. All that does is change which phone book you use — the lookup itself is still a postcard. To actually encrypt, you need to turn it on in a specific place, which the setup section below covers.

Difference #4: Which one is faster

Honestly, there’s no single answer.

How fast DNS feels mostly comes down to three things: how far you are from its servers, how good your internet connection is, and how congested the network is at that moment. The same DNS can perform differently in different cities or on different ISPs. One might be faster today and the other faster tomorrow.

Both have huge global networks, and in most cases a lookup takes somewhere between ten and a few dozen milliseconds — far too small to feel.

There’s another thing many people don’t realize: DNS results get cached. For sites you visit often, your computer and browser remember the answer for a while after the first lookup and reuse it, without asking DNS again. So DNS speed really only affects the first visit, and its impact on everyday browsing is much smaller than you’d think.

If you want to test it yourself on a Mac or Linux, open a terminal and run:

# Look for "Query time" in the output — lower is faster
dig @1.1.1.1 example.com
dig @8.8.8.8 example.com

On Windows, run this in PowerShell:

# Look at TotalMilliseconds at the end
Measure-Command { Resolve-DnsName example.com -Server 1.1.1.1 -DnsOnly }
Measure-Command { Resolve-DnsName example.com -Server 8.8.8.8 -DnsOnly }

Run it several times and try a few sites you actually visit. Don’t judge by a single result — one unusually fast run means nothing. Consistently steady, no hiccups, no errors is what matters.

Really, the most reliable test is just to switch and use it for a few days. See whether opening pages, streaming, or gaming feels any different. If you can’t tell, that’s your answer: either one is fine.

If you’re in mainland China

Most of both providers’ servers are outside mainland China. From networks inside China, latency is often higher than with local DNS, connections can occasionally be unstable, and encrypted DNS sometimes won’t connect at all.

If you mostly visit sites hosted in China and don’t have strong privacy requirements, your ISP’s default DNS or a local public DNS (such as Alibaba’s 223.5.5.5 or Tencent’s 119.29.29.29) will usually be faster. Local CDNs are also more likely to route you to a nearby server.

If privacy or family filtering is what you’re after, Cloudflare is worth a try, but use it for a few days to make sure it’s stable before committing.

How to set it up on each platform

Android 9 and later has a built-in “Private DNS” feature. Set it once and you’re encrypted. Highly recommended.

Go to Settings → Network & internet → Private DNS (the exact location varies by brand; you can also just search Settings for “Private DNS”), choose “Private DNS provider hostname,” and enter one of these:

  • Cloudflare: one.one.one.one
  • Cloudflare for Families (block malicious sites): security.cloudflare-dns.com
  • Cloudflare for Families (also block adult sites): family.cloudflare-dns.com
  • Google: dns.google

Once saved, encrypted DNS is used whether you’re on Wi-Fi or mobile data.

iPhone / iPad

iOS doesn’t have a one-tap system switch like Android. The easiest option is Cloudflare’s official 1.1.1.1 app — flip the toggle and you’re on encrypted DNS.

If you just want to change the regular (unencrypted) DNS, go to Settings → Wi-Fi, tap the ⓘ next to your current network, choose Configure DNS → Manual, remove the existing addresses, and add the new ones. Note that this only applies to that one Wi-Fi network; you’ll need to repeat it for others.

Windows 11

Open Settings → Network & internet, go into the Wi-Fi or Ethernet connection you’re using, find “DNS server assignment,” click Edit, switch it to Manual, turn on IPv4, and enter your preferred and alternate DNS.

If you enter 1.1.1.1 or 8.8.8.8, Windows 11 automatically recognizes that they support encryption — just set the “DNS over HTTPS” option below to On (automatic template).

Mac

Open System Settings → Network, click your current Wi-Fi, go to Details → DNS, click the + button to add the new DNS addresses, and remove the old ones.

That changes regular DNS. For encryption on a Mac, the simplest approach is to turn it on in your browser (see below) or use Cloudflare’s 1.1.1.1 app.

Browsers

Chrome, Edge, and Firefox all have built-in encrypted DNS. It only applies to the browser and doesn’t affect other apps, which makes it a good option if you’d rather not touch system settings.

In Chrome: Settings → Privacy and security → Security, scroll down to Use secure DNS, turn it on, and pick Cloudflare or Google from the list.

Home router

Every router brand has a different interface. You’ll usually find the DNS option under something like “Internet settings,” “WAN settings,” or “DHCP settings” — switch it to manual and enter the addresses. If you can’t find it, search for “your router model + change DNS.”

The upside of doing it on the router is that you set it once and the whole household is covered. It pairs perfectly with Cloudflare for Families.

How to check that it’s working

If you want to make sure everything took effect, here’s how to verify.

If you’re using Cloudflare, just open 1.1.1.1/help. It tells you whether you’re currently using 1.1.1.1 and whether encryption (DoH or DoT) is on. If you see “Yes,” you’re all set.

If some sites still seem to behave the old way after you switch, your computer may have cached the old results. Clearing the cache fixes that:

# Mac
sudo dscacheutil -flushcache; sudo killall -HUP mDNSResponder
# Windows
ipconfig /flushdns

If that doesn’t help, restarting your device or browser does the same job.

Which to choose for your situation

Your own phone and computer

If privacy is what you want, use Cloudflare — and make sure encryption is on, or you lose much of the privacy benefit. On Android use Private DNS, on iPhone install the 1.1.1.1 app, and on a computer turn on secure DNS in your browser.

If Google feels more stable where you are, go with Google — and turn on encryption there too.

Your home router

If you have kids, or older relatives who aren’t very tech-savvy, setting Cloudflare for Families on the router is a great idea. 1.1.1.2 is usually enough: it blocks phishing and malware with very little risk of getting in the way of normal use. Consider 1.1.1.3 if you have kids.

Once it’s set up, open the sites and apps your household uses regularly to make sure nothing important is being blocked by mistake.

Work or school computers

Seriously, don’t change these yourself.

Internal websites, company systems, printers, and shared drives often depend on your organization’s own DNS to be found. Switch to a public DNS and Cloudflare or Google have no idea what exists inside your company’s network, so all of that stops working. Your company VPN may break too.

Plenty of organizations also have security policies that prohibit changing network settings on your own. If you really need something changed, talk to IT.

Two common misconceptions

Isn’t Cloudflare as primary and Google as secondary the best of both worlds?

No. Many people assume the system always uses the primary and only falls back to the secondary if the primary fails. In reality, different systems behave differently: some alternate between them, some pick whichever responds fastest at that moment. The result is that you can’t tell which provider handled any given lookup.

If you’re using Cloudflare for Families to block bad sites but put Google as the secondary, those sites can easily slip through via Google, and your filtering is effectively useless. So use the same provider for primary and secondary.

Does switching DNS let me get around access restrictions or encrypt everything?

No again. DNS only handles the “find the address” step. Once the address is found, how your device connects to the site and what gets sent has nothing to do with DNS. If you want the whole connection encrypted, you need something like a VPN. Cloudflare itself treats “encrypt DNS only” and “encrypt all traffic” (its WARP service) as two separate features.

FAQ

Will switching DNS make my internet faster?

Generally, no. DNS only affects the moment of “finding the website,” not download or streaming speed. If your ISP’s DNS was slow or flaky, pages might open a bit snappier after switching, but your bandwidth won’t increase.

Is switching DNS risky?

Barely. The worst case is that some sites won’t load, and you just switch back. So before you change anything, write down or screenshot your original DNS settings.

Why did some sites stop working after I changed DNS?

A few common reasons: you’re using the family version and the site got blocked by mistake; you’re on a work network where internal sites need the company DNS; or the cache hasn’t refreshed yet. Try clearing the cache first, and if that doesn’t help, switch back to the standard addresses or your original DNS.

Do I need to change it on both my phone and my computer?

It depends on what you want. If you change it on the router, every device on your home Wi-Fi is covered, but not when you’re out on mobile data. If you want it to apply everywhere, you’ll need to set it on each device.

With encrypted DNS, does my ISP have no idea what I’m doing?

Not quite. Your ISP can’t see which domains you look up, but it can still see which IP addresses you connect to. Many websites now share the same pools of IPs, so guessing what you visited from the IP alone isn’t easy — but it’s not impossible either.

Final thoughts

DNS can be as complicated or as simple as you want it to be. For most people, a few things are all you need to remember:

If you care about privacy, choose Cloudflare and turn on encryption. If you want to block bad sites at home, put Cloudflare for Families on your router. If you just want stability, try both and keep whichever works better. If you’re in mainland China and mostly visit local sites, a local DNS may be faster. And leave work computers alone.

Changing DNS is about as low-stakes as tech tweaks get — if you get it wrong, you just change it back. Don’t get hung up on a few milliseconds in some speed ranking. Whichever one runs smoothly and doesn’t give you trouble is the right one for you.

References

Mttao

Mttao GitHub ↗

Exploring technology and life's wisdom

Related Posts

View all →
  1. 01 Why Encrypt DNS Queries? dns· Aug 30, 2026
  2. 02 NameSilo vs Porkbun: Which Domain Registrar Should You Choose? dns· May 17, 2026
  3. 03 Choosing Domain Registrars for Global Business: NameSilo, Namecheap, Porkbun vs Cloudflare dns· Jul 14, 2025

/ Comments