> While DNSSEC ensures integrity of data between a resolver and an authoritative server, it does not protect the privacy of the “ last mile ” towards you. DNS resolver, 1.1.1.1, supports both emerging DNS privacy standards - DNS-over-TLS, and DNS-over-HTTPS, which both provide last mile encryption to keep your DNS queries private and free from tampering.
> In the end, we decided to build the system around the Knot Resolver from CZ NIC.
https://blog.cloudflare.com/dns-resolver-1-1-1-1/