Cloudflare gives away 1.1.1.1 with WARP, a free VPN and encrypted DNS app for Windows, Mac, Android, and iOS, with no account to create and no data cap attached. Linux is served too, though only by a command-line client. The tunnel encrypts everything leaving the device and swaps your address for one of Cloudflare’s, and then it stops: there is no country list, and there never will be. Whether to download it comes down to whether a VPN that keeps you where you are is the kind you wanted.
The protection 1.1.1.1 with WARP gives you, and where it stops
It covers the stretch of network between your device and Cloudflare, which is the stretch strangers can reach. On café, hotel, or campus Wi-Fi, nobody else on that network can read what you are doing, and your provider loses its usual view of every site and app you open. DNS lookups are encrypted in every mode, so even the addresses you ask for stop travelling in the clear.
What it does not cover is anything past Cloudflare’s edge. The site you land on still sees a request arrive, just with a Cloudflare address attached instead of yours, and Cloudflare itself sits in the middle of everything. There is no server list to choose from, and no kill switch if the tunnel drops. As an always-on layer on untrusted networks it earns its place; as a way to look like you are somewhere else, it is the wrong download.
Which WARP mode and protocol should you actually use?
The app looks like a single switch, and most people never open anything else. The settings underneath are where it stops behaving like a generic VPN.
WARP mode, DNS only, and what each one covers
Four settings decide how much traffic leaves the device protected:
DNS only is the setting for networks that dislike tunnels, and it costs almost nothing in speed, which is why the free 1.1.1.1 resolver spread on its own long before the VPN arrived.

Malware and adult-content filtering with 1.1.1.1 for Families
Families is a filtered version of the resolver, and it stays off until you turn it on from the app’s DNS settings. One tier blocks known malware and phishing domains, the other adds adult content on top. Filtering happens at the lookup stage with no scanning involved, so it does nothing about a file already on the machine.
Split tunnel and trusted networks
Split tunnel decides which apps or addresses skip the tunnel, which is the fix for a banking app that refuses to run behind a VPN. On Android the app can also learn networks you mark as trusted and stand the tunnel down there, keeping printers, casting, and smart-home devices reachable without switching it off by hand.
MASQUE and WireGuard, and why the choice matters
Two tunnel protocols ship in the app. MASQUE is the default and rides on HTTP/3, so it blends in with ordinary web traffic and survives networks that block anything unusual. WireGuard is the older option and needs its own UDP ports open. The setting sits in the advanced connection options, and it is the first thing to change when the app misbehaves.
Your IP address, your location, and what WARP swaps them for
This is the part the internet gets wrong. Pages written about WARP contradict each other flatly, some saying it hides your address like any VPN and others insisting it does not hide it at all, and many are describing an older version of the service. Cloudflare replaces your address with one of its own, then registers those addresses with geolocation databases so they resolve to your approximate metro area. Local search results, regional pricing, and delivery estimates keep working while your real address stays behind the tunnel.
The catch follows from the same design. Because the address is meant to look like your city, there is no country to switch, so nothing geo-restricted opens up. There is also a carve-out worth knowing before you rely on it: WARP does not proxy WebRTC, so live video calls, screen sharing, and some browser games reach past the tunnel and expose your real address to those services. Cloudflare documents this plainly in its own support material.
How much you are trusting Cloudflare once the tunnel is on
Traffic is encrypted from the device to Cloudflare’s network, and the resolver’s no-logging promise has been through independent audit, which is more than most privacy promises ever get. Cloudflare does not sell browsing data, and the business it is actually in makes that credible.
The honest reservation is structural. Every request now passes through a single company that already handles a large share of the web, so this is a decision to trust Cloudflare more and your provider less, not a decision to trust nobody. The missing kill switch matters here too: if the tunnel drops, traffic keeps flowing unprotected instead of stopping, and the app will not say so.
1.1.1.1 with WARP against Proton VPN, Windscribe, and Mullvad
Proton VPN’s free tier is the closest rival and takes the opposite position: a small set of countries to choose from and no data cap, but a limit on simultaneous devices and servers that fill up at peak hours. Windscribe’s free tier hands you a wider country list and built-in ad blocking, then meters you with a monthly data allowance, so it is a tool you ration, not one you leave running. Mullvad is paid and answers a different question, with anonymous accounts, full protocol control, and the kill switch this app lacks.
If you want a tunnel you never think about and never top up, WARP wins on every device you own. If choosing an exit country is the reason you are downloading a VPN, Proton VPN’s free tier is the better start, and Mullvad is where you land once privacy becomes something you will pay for.
Speed on broadband, mobile data, and the protocol trap
Cloudflare says outright that WARP trades some throughput for encryption, and that desktop users on fast broadband are the ones likely to notice. On phones the difference usually sits inside normal variation, and DNS lookups often feel quicker than the provider’s own resolver.
Then there is the failure that gets blamed on the app. When speeds do not dip but collapse to a fraction of the line, the network’s handling of the default protocol is usually behind it, not WARP. Switching the tunnel protocol in the advanced connection options fixes it on the networks that choke HTTP/3, and on other networks the same switch kills the connection outright because the ports WireGuard needs are blocked. It is a two-way setting whose correct value depends on the Wi-Fi you are sitting on, and nothing in the app tells you that.
The case for keeping 1.1.1.1 with WARP installed
For anyone who spends time on Wi-Fi they do not control and wants encryption without settings to learn, 1.1.1.1 with WARP is worth the download and costs nothing to leave running. Anyone whose real goal is a different country or a kill switch should put money into a full VPN. Install it as a default layer, not as a disguise.