WindowsMacAndroidiOS

1.1.1.1 with WARP

Rating

+4

Category

Security & Privacy

Security & Privacy

Developer

dev

LastPass

Languages

Arabic, Chinese (Simplified), Chinese (Traditional), Dutch, English, French, German, Indonesian, Italian, Japanese, Korean, Persian (Farsi), Polish, Portuguese, Russian, Spanish, Turkish, Ukrainian

Description

Everything you need to know about 1.1.1.1 with WARP
01

Cloudflare gives away 1.1.1.1 with WARP, a free VPN and encrypted DNS app for Windows, Mac, Android, and iOS, with no account to create and no data cap attached. Linux is served too, though only by a command-line client. The tunnel encrypts everything leaving the device and swaps your address for one of Cloudflare’s, and then it stops: there is no country list, and there never will be. Whether to download it comes down to whether a VPN that keeps you where you are is the kind you wanted.

The protection 1.1.1.1 with WARP gives you, and where it stops

It covers the stretch of network between your device and Cloudflare, which is the stretch strangers can reach. On café, hotel, or campus Wi-Fi, nobody else on that network can read what you are doing, and your provider loses its usual view of every site and app you open. DNS lookups are encrypted in every mode, so even the addresses you ask for stop travelling in the clear.

What it does not cover is anything past Cloudflare’s edge. The site you land on still sees a request arrive, just with a Cloudflare address attached instead of yours, and Cloudflare itself sits in the middle of everything. There is no server list to choose from, and no kill switch if the tunnel drops. As an always-on layer on untrusted networks it earns its place; as a way to look like you are somewhere else, it is the wrong download.

Which WARP mode and protocol should you actually use?

The app looks like a single switch, and most people never open anything else. The settings underneath are where it stops behaving like a generic VPN.

WARP mode, DNS only, and what each one covers

Four settings decide how much traffic leaves the device protected:

  • WARP tunnels everything, encrypting all traffic between the device and Cloudflare’s network.
  • DNS only over HTTPS encrypts your lookups through the 1.1.1.1 resolver and leaves the rest of your traffic on its normal path.
  • DNS only over TLS does the same job over a different transport that some networks handle better.
  • WARP with 1.1.1.1 for Families adds domain filtering on top of the full tunnel.

DNS only is the setting for networks that dislike tunnels, and it costs almost nothing in speed, which is why the free 1.1.1.1 resolver spread on its own long before the VPN arrived.

Cloudflare large 1.1.1.1 logo

Malware and adult-content filtering with 1.1.1.1 for Families

Families is a filtered version of the resolver, and it stays off until you turn it on from the app’s DNS settings. One tier blocks known malware and phishing domains, the other adds adult content on top. Filtering happens at the lookup stage with no scanning involved, so it does nothing about a file already on the machine.

Split tunnel and trusted networks

Split tunnel decides which apps or addresses skip the tunnel, which is the fix for a banking app that refuses to run behind a VPN. On Android the app can also learn networks you mark as trusted and stand the tunnel down there, keeping printers, casting, and smart-home devices reachable without switching it off by hand.

MASQUE and WireGuard, and why the choice matters

Two tunnel protocols ship in the app. MASQUE is the default and rides on HTTP/3, so it blends in with ordinary web traffic and survives networks that block anything unusual. WireGuard is the older option and needs its own UDP ports open. The setting sits in the advanced connection options, and it is the first thing to change when the app misbehaves.

Your IP address, your location, and what WARP swaps them for

This is the part the internet gets wrong. Pages written about WARP contradict each other flatly, some saying it hides your address like any VPN and others insisting it does not hide it at all, and many are describing an older version of the service. Cloudflare replaces your address with one of its own, then registers those addresses with geolocation databases so they resolve to your approximate metro area. Local search results, regional pricing, and delivery estimates keep working while your real address stays behind the tunnel.

The catch follows from the same design. Because the address is meant to look like your city, there is no country to switch, so nothing geo-restricted opens up. There is also a carve-out worth knowing before you rely on it: WARP does not proxy WebRTC, so live video calls, screen sharing, and some browser games reach past the tunnel and expose your real address to those services. Cloudflare documents this plainly in its own support material.

How much you are trusting Cloudflare once the tunnel is on

Traffic is encrypted from the device to Cloudflare’s network, and the resolver’s no-logging promise has been through independent audit, which is more than most privacy promises ever get. Cloudflare does not sell browsing data, and the business it is actually in makes that credible.

The honest reservation is structural. Every request now passes through a single company that already handles a large share of the web, so this is a decision to trust Cloudflare more and your provider less, not a decision to trust nobody. The missing kill switch matters here too: if the tunnel drops, traffic keeps flowing unprotected instead of stopping, and the app will not say so.

1.1.1.1 with WARP against Proton VPN, Windscribe, and Mullvad

Proton VPN’s free tier is the closest rival and takes the opposite position: a small set of countries to choose from and no data cap, but a limit on simultaneous devices and servers that fill up at peak hours. Windscribe’s free tier hands you a wider country list and built-in ad blocking, then meters you with a monthly data allowance, so it is a tool you ration, not one you leave running. Mullvad is paid and answers a different question, with anonymous accounts, full protocol control, and the kill switch this app lacks.

If you want a tunnel you never think about and never top up, WARP wins on every device you own. If choosing an exit country is the reason you are downloading a VPN, Proton VPN’s free tier is the better start, and Mullvad is where you land once privacy becomes something you will pay for.

Speed on broadband, mobile data, and the protocol trap

Cloudflare says outright that WARP trades some throughput for encryption, and that desktop users on fast broadband are the ones likely to notice. On phones the difference usually sits inside normal variation, and DNS lookups often feel quicker than the provider’s own resolver.

Then there is the failure that gets blamed on the app. When speeds do not dip but collapse to a fraction of the line, the network’s handling of the default protocol is usually behind it, not WARP. Switching the tunnel protocol in the advanced connection options fixes it on the networks that choke HTTP/3, and on other networks the same switch kills the connection outright because the ports WireGuard needs are blocked. It is a two-way setting whose correct value depends on the Wi-Fi you are sitting on, and nothing in the app tells you that.

The case for keeping 1.1.1.1 with WARP installed

For anyone who spends time on Wi-Fi they do not control and wants encryption without settings to learn, 1.1.1.1 with WARP is worth the download and costs nothing to leave running. Anyone whose real goal is a different country or a kill switch should put money into a full VPN. Install it as a default layer, not as a disguise.

Technically yes, but not the kind most people mean. 1.1.1.1 with WARP builds an encrypted tunnel from your device to Cloudflare's network, which is the core of what a VPN does, while leaving out server switching, country selection, and a kill switch.
Open Source:
No
License:
Freemium
Account required:
No
Data collection level:
Standard
Maintenance status:
Actively maintained
Data collected:
Account info
Usage and telemetry
Location
Third party data sharing:
Yes
No logs policy:
Yes
Encryption:
Yes

Pros

  • Free with no data cap, no account, and no sign-in to manage across your devices
  • Encrypted DNS and a full tunnel from one switch, with nothing to configure
  • The exit address stays near your real region, so local sites and search results keep working
  • Optional malware and adult-content filtering through 1.1.1.1 for Families
  • Split tunnel and trusted networks keep printers, casting, and awkward apps working

Cons

  • No country selection, so it unblocks nothing
  • No kill switch, so a dropped tunnel silently exposes traffic
  • Throughput can fall on fast broadband, and on some networks the default protocol makes it much worse

Specs

Technical details and system requirements
02

Windows

Version:
2026.7.1343.0
File Size:
56.73 MB
Release Date:
August 19, 2026
Windows 10 or later, 3 MB RAM, 184 MB disc space

Mac

Version:
2026.7.1343.0
File Size:
145.71 MB
Release Date:
August 19, 2026
macOS Sonoma 14.0 or later, 35 MB RAM, 75 MB disc space

iOS

Version:
6.31.6
File Size:
77.2 MB
Release Date:
August 12, 2026
iOS 13.0 or later

Android

Version:
6.38.9
File Size:
56.02 MB
Release Date:
August 07, 2026
Android 7.0 or later

Verified Source: All specifications, version histories, and download links on this page are checked against the developer's official website before publishing.

Brand

LastPass

System

Android, iOS, Mac, Windows

Languages

ArabicChinese (Simplified)Chinese (Traditional)DutchEnglishFrenchGermanIndonesianItalianJapaneseKoreanPersian (Farsi)PolishPortugueseRussianSpanishTurkishUkrainian

Changelog

v 2026.7.1343.0
August 19, 2026
  • Reauthentication notifications are clearer and now redirect to the browser instead of the app window, cutting the steps needed to get back to work.
  • On networks that block or degrade HTTP/3, the client learns to try HTTP/2 first and falls back to HTTP/3 only if needed, reducing connection delays.
  • Fixed a process leak in the Windows GUI that could exhaust system resources during IPC client-creation failures.
  • Fixed the inability to switch organizations while stuck in the "Device not in organization" state.
  • Fixed Microsoft Defender falsely flagging the installation as malicious when deployed via Intune.
  • Made the Windows domain-joined posture check more reliable.
  • A DNS search domain parsing failure no longer blocks the connection.
  • The cloud icon now reflects the real connection status instead of showing disconnected while connected.
  • Fixed a missing certificate error display caused by a race condition.
  • Fixed the empty black window after moving from docked dual displays to an internal display.
v 2026.7.1343.0
August 19, 2026
  • Reauthentication notifications are clearer and now redirect to the browser instead of the app window, cutting the steps needed to get back to work.
  • On networks that block or degrade HTTP/3, the client learns to try HTTP/2 first and falls back to HTTP/3 only if needed, reducing connection delays.
  • Fixed the client refusing to log into another organization while showing "Device not in organization".
  • A DNS search domain parsing failure no longer blocks the connection.
  • The cloud icon now reflects the real connection status instead of showing disconnected while connected.
  • Fixed a missing certificate error display caused by a race condition.
  • Fixed a crash when connecting to a captive portal over Wi-Fi.
  • Fixed the empty black window after moving from docked dual displays to an internal display.
v 6.38.9
August 07, 2026
  • Signing into Zero Trust teams from the 1.1.1.1 app is no longer supported; use the Cloudflare One Agent app for Zero Trust teams.
  • Adjusted the TCP fallback timing for MASQUE tunnels to improve connectivity on unreliable networks.
  • Reduced the number of logged events for smaller, more readable diagnostic logs.
v 6.31.6
August 12, 2026
  • Added wildcard domain support to split tunnel exclude configurations, with wildcard entries resolved and routed at DNS query time.
  • Fixed a crash triggered by "Reset All Settings" while the app was disabled for a specific Wi-Fi connection.

Common Problems and Fixes

Troubleshooting Guide for 1.1.1.1 with WARP
03
Disconnect any other VPN client first, since two tunnels cannot both hold the connection, then switch between Wi-Fi and mobile data to force a fresh attempt. If it still hangs, change the tunnel protocol in the advanced connection options, since some networks block the ports one of them needs.

Reviews

0 verified user reviews
04
{{ reviewsTotal }}{{ options.labels.singularReviewCountLabel }}
{{ reviewsTotal }}{{ options.labels.pluralReviewCountLabel }}
{{ options.labels.noReviewsLabel }}
{{ options.labels.newReviewButton }}
{{ userData.canReview.message }}

Alternatives

Similar software to 1.1.1.1 with WARP
05
Anyone who needs disk encryption that no company holds a key to ends up at VeraCrypt: free, open source, and unforgiving of a forgotten password.
CyberGhost VPN pairs one of the largest server networks around with streaming servers labeled by service name. Its ownership, and what the audits cover, decides the rest.
For travellers and streamers who want a VPN that needs no tuning, ExpressVPN is the easy paid pick. Who owns it is what sends other buyers elsewhere.
KeePassXC is a free, open source password manager for people who would rather hold their own encrypted file than trust a company's vault. Sync and mobile stay in your hands.
LastPass is a familiar password manager with an unlimited free tier, a one device-type ceiling, and a security record worth weighing before you download it.
Bitwarden is a free, open source password manager that stores unlimited logins across unlimited devices. One real question decides whether Premium is worth adding.
Every entry in a password manager carries more than the password: a site name, a username, sometimes a note. Most managers leave that part unencrypted. Proton Pass does not.
1Password is a password manager bundling generation, passkeys, and breach alerts into one subscription. No free tier means the polish has to earn its cost.
Surfshark VPN protects unlimited devices on one subscription and has passed independent no-logs audits. There is no free tier, which decides who should download it.

Explore More

Windows Search makes you wait; Everything answers as you type. A free file search utility from voidtools that reads names, not contents.
Every entry in a password manager carries more than the password: a site name, a username, sometimes a note. Most managers leave that part unencrypted. Proton Pass does not.
Cryptomator adds client-side encryption to any cloud folder you already sync. Free and complete on desktop, read-only on phones until you pay once.
The browser that came with your machine is fine until a site breaks. Google Chrome is what the web gets tested against, and what that costs in blocking and privacy.
7-Zip is a free, open-source file archiver that opens almost everything and compresses tighter than most paid rivals. A plain interface is the only real cost.
CyberGhost VPN pairs one of the largest server networks around with streaming servers labeled by service name. Its ownership, and what the audits cover, decides the rest.
Advanced SystemCare is a Windows system utility that cleans, speeds up, and locks a cluttered PC down in one dashboard, worth weighing against a leaner cleaner.
1Password is a password manager bundling generation, passkeys, and breach alerts into one subscription. No free tier means the polish has to earn its cost.
LibreOffice is a completely free, open source Office & Productivity suite covering six apps, though heavily formatted Word and Excel files don't always translate perfectly.

+4

Suitable for all agesContains no objectionable content. No violence, gambling, sexual references, or strong language.

1.1.1.1 with WARP: Trust & Privacy Summary

1.1.1.1 with WARP is a closed-source app from Cloudflare with a freemium model: the WARP tunnel is free, while WARP+ is a paid subscription. No account sign-up is required to install and connect. Data collection is standard: account information, usage and telemetry, and location, and the app's store listing states these data types may be shared with third parties. All traffic to and from the device is encrypted in transit through the WARP tunnel, and Cloudflare states it does not store data beyond what its privacy policy sets out and does not use it to identify who you are or what you do on the Internet. The app is actively maintained.