1.1.1.3: Cloudflare for Families, adult content blocking
1.1.1.3 is the family filtering resolver in Cloudflare's 1.1.1.1 for Families service. It blocks both malware domains and adult content by returning 0.0.0.0, requires no account, and otherwise resolves names exactly as 1.1.1.1 does.
Operated by Cloudflare, Inc. (AS13335).
Live data
- Classification
- public
- Reverse DNS
- family.cloudflare-dns.com
- ASN
- AS13335
- AS name
- Cloudflare, Inc.
- Netname
- APNIC-LABS
- Registry
- APNIC — Asia-Pacific Network Information Centre
- Country
- Australia
- Block
- 1.1.1.0/24
- Registered
- 2011-08-10T23:12:35Z
- Abuse contact
- helpdesk@apnic.net
- Blocklists
- 1 of 9 zones list it
Hostname: DNS PTR via 1.1.1.1 · ASN: IPinfo Lite · AS name: IPinfo Lite · Geo: IPinfo Lite · Registry record: rdap.apnic.net. Registry data from RDAP. Reverse DNS and blocklist checks over DNS-over-HTTPS. Run a full lookup on 1.1.1.3.
1.1.1.3 is the family filtering resolver in Cloudflare’s 1.1.1.1 for Families service. It blocks both malware domains and adult content by returning 0.0.0.0, requires no account, and otherwise resolves names exactly as 1.1.1.1 does.
What it filters and how
Cloudflare classifies domains into categories using the same intelligence that powers its Gateway product, then applies the malware and adult content categories to queries arriving on 1.1.1.3. A blocked lookup answers 0.0.0.0 for A records and :: for AAAA, both unroutable, so the browser fails to connect rather than loading a warning page.
That design keeps Cloudflare out of the connection entirely, which is why the free service can honestly say it holds no record of what a household blocked. It also means a blocked page shows a generic browser error, and a child gets no explanation.
Setting it up for a household
Configure it on the router, not on each device, so anything that joins the Wi-Fi inherits the filter.
- Router LAN DHCP DNS:
1.1.1.3and1.0.0.3, plus the IPv6 pair2606:4700:4700::1113and2606:4700:4700::1003if the network runs dual stack. - Block the escape routes: add a firewall rule that drops outbound UDP and TCP port 53 to anything other than those addresses, otherwise a device with hardcoded DNS ignores your setting.
- Disable IPv6 or set the IPv6 pair: a dual stack network with only IPv4 filtering configured will resolve over IPv6 and skip the filter completely. This is the most common reason a family filter appears not to work.
- Per device: Android 9 and later accept the hostname
family.cloudflare-dns.comunder Private DNS; iOS and desktop take the raw addresses. - DNS over HTTPS:
https://family.cloudflare-dns.com/dns-query.
The honest limits
Browser-level DNS over HTTPS bypasses the router entirely. Firefox and Chrome can both send lookups to their own resolver over HTTPS, which your DHCP setting has no say over. A VPN app does the same. A phone on mobile data is not on your network at all.
Cloudflare’s category lists are also imperfect in both directions. Some adult sites are missed and some ordinary sites are miscategorised, and there is no per-household allow list on the free tier. If you need exceptions, reporting, or per-user policy, that is what Cloudflare’s Zero Trust Gateway or a paid product from another vendor is for.
Privacy and policy
The Cloudflare public resolver privacy commitments apply here as they do to 1.1.1.1: no querying IP address written to disk, operational logs discarded within 24 hours, no sale of query data, and independent examinations published. The categorisation happens in memory at the edge, so choosing the family address does not create a browsing history somewhere.
What it is not
1.1.1.3 is not parental control software. It cannot limit screen time, filter within a site, or tell you what someone tried to visit. It is not a safe search enforcer either, so image search results are untouched. And it is not tamper proof: a filter delivered by DHCP is a default, and treating it as a guarantee is how a parent gets a false sense of coverage.
For a stricter filter that also forces safe search on the major search engines, look at the CleanBrowsing Family pair described on the 185.228.168.9 page. Check what your devices actually resolve through in /dns-leak-test.
Questions people ask
- What is the secondary for 1.1.1.3?
- 1.0.0.3, with IPv6 at 2606:4700:4700::1113 and 2606:4700:4700::1003.
- Can a teenager get around it?
- Yes, easily, unless the router blocks outbound DNS from other devices. Changing DNS settings on a phone, using a browser's own DNS over HTTPS, or installing a VPN all bypass it.
- Does 1.1.1.3 force safe search?
- No. It blocks domains on Cloudflare's adult content list but does not enforce safe search on Google, Bing, or YouTube. CleanBrowsing's Family Filter does that.
- Can I see what was blocked?
- Not with the free resolver. It keeps no per-user logs by design. Cloudflare's Zero Trust Gateway offers reporting for an account.
Related
Last reviewed 2026-09-04. editorial