@lucataco
Post
Change your parents' router DNS to 1.1.1.2 and 1.0.0.2
Cloudflare blocks malware and phishing at the network level
Free antivirus that actually works. Nothing to install/update/disable

Image from X post
Explanation
The post is recommending a very simple network-wide security hardening step: change a home router’s DNS servers to `1.1.1.2` and `1.0.0.2`. Those addresses are Cloudflare’s free “1.1.1.1 for Families” DNS resolvers configured specifically to block domains Cloudflare classifies as malware or phishing. Because the setting is made on the router, devices using that router’s DNS automatically inherit the protection without installing software on each phone, laptop, TV, etc. That is what the author means by “free antivirus that actually works” and “nothing to install/update/disable.” ([Cloudflare Docs][1])
The important technical point is that this is not really antivirus. DNS is the system that translates names such as `example.com` into IP addresses. With these resolvers, if a device asks for the address of a domain on Cloudflare’s malicious-domain list, Cloudflare deliberately refuses to return the real destination, currently answering with `0.0.0.0`. The connection therefore usually dies before the browser or application reaches the malicious server. ([Cloudflare Docs][1])
That makes it quite useful against a large class of attacks: phishing links, malware download sites, command-and-control domains, and other known bad hostnames. It can protect poorly maintained devices and people who click bad links, and putting it at the router is unusually high-leverage because one configuration change covers much of the household.
But the “antivirus” comparison exaggerates what it does. It cannot inspect a downloaded executable, detect malicious code embedded on an otherwise legitimate domain, stop an attack that connects directly to an IP address, or necessarily catch a brand-new malicious domain before Cloudflare has classified it. A compromised legitimate website may also remain reachable because the DNS name itself is not considered malicious. Traditional endpoint protection operates much deeper in the stack.
The two addresses are not two different levels of filtering; they are primary and secondary instances of the same malware-filtering service for redundancy. Ordinary Cloudflare DNS is `1.1.1.1` / `1.0.0.1`, with no content filtering. `1.1.1.2` / `1.0.0.2` adds malware/phishing filtering. `1.1.1.3` / `1.0.0.3` additionally blocks adult content. ([Cloudflare Docs][2])
One subtle limitation: configuring the router does not guarantee every device will use it. Browsers or operating systems can use encrypted DNS with their own resolver, VPNs commonly supply their own DNS, and IPv6 may require configuring Cloudflare’s corresponding IPv6 addresses too. So the post’s core recommendation is sound and unusually cheap, but the precise description is “network-level malicious-domain filtering,” not antivirus.
[1]: https://developers.cloudflare.com/1.1.1.1/setup/?utm_source=chatgpt.com "Set up Cloudflare 1.1.1.1 resolver · Cloudflare 1.1.1.1 docs" [2]: https://developers.cloudflare.com/1.1.1.1/ip-addresses/?utm_source=chatgpt.com "IP addresses · Cloudflare 1.1.1.1 docs"