A router configuration change is gaining attention as a way to add defense against phishing and malware. Cybersecurity commentator Luis Catacora urged users to replace default DNS resolvers on a router with Cloudflare’s addresses: 1.1.1.2 as the primary server and 1.0.0.2 as the secondary server.
The change does not replace endpoint security, but it can stop risky connections before a phone, laptop, television, or smart-home device reaches a malicious domain.
DNS, or the Domain Name System, is the internet’s address book. Before a browser or app opens a website, it asks a DNS resolver to translate a domain name into the IP address needed to connect. Cloudflare’s 1.1.1.1 for Families malware-filtering resolver checks those requests against its threat classifications.
When it identifies a queried domain as associated with malware or phishing, it returns 0.0.0.0 rather than the site’s real address, preventing the device from establishing a connection. Cloudflare documents the service as a free option that blocks domains linked to malware and phishing.
Router DNS Tweak Blocks Malware
Applied at the router, the protection can cover devices using that network without installing an application or configuring each device separately. That makes it useful in homes where family members use computers, phones, game consoles, smart TVs, cameras, and internet-connected equipment.
It also offers a low-friction safeguard for people exposed to scam messages or fraudulent login pages. One response to Catacora’s advice described changing an elderly parent’s router settings after concerns about online scams, illustrating why the approach has resonated.
Families seeking a content-control layer can instead use 1.1.1.3 and 1.0.0.3. That Cloudflare resolver is designed to block malware and phishing as well as domains classified for adult content.
The configuration is usually found in a router’s administration interface under Internet, WAN, DHCP, LAN, or DNS settings, although labels vary by vendor and internet service provider.
Administrators should record addresses before making changes, save the new configuration, and test browsing afterward. Cloudflare also provides IPv6 resolver pairs and encrypted DNS endpoints for both filtering options.
The DNS tweak has limitations. It blocks requests when the harmful destination has been classified and when a device uses the router’s resolver; a device using its own encrypted DNS setting, VPN, mobile connection, or hard-coded resolver may bypass it.
DNS filtering also cannot disinfect an infected machine, detect every malicious file, prevent credential theft on a permitted service, or substitute for patching and multifactor authentication. Users may encounter false positives, ISP-level DNS restrictions, or compatibility issues with services that depend on location-aware DNS.
The stronger message is not that a DNS change is “free antivirus,” but that it is an accessible, network-wide control that raises the cost of common web-based attacks.
Router DNS filtering works best alongside unique passwords stored in a password manager, multifactor authentication, timely software and firmware updates, reputable endpoint protection, and a pause-before-you-click habit.
For households wanting a simple security improvement without another subscription or app, Cloudflare’s filtered DNS is a sensible layer—provided its boundaries are understood across modern home networks today.
Prevent incidents due to slow investigations. Power your Tier 1 with threat intelligence from 15K SOCs: Integrate TI Lookup in your SOC

