http://gstatic.com (Chrome uses http://gstatic.com/generate_204 , which returns a 204 No Content)
http://www.msftncsi.com (Windows, desktop and mobile, uses http://www.msftncsi.com/ncsi.txt. NCSI is "Network Connectivity Status Indicator")
http://captive.apple.com (macOS / iOS)
because those are likely to be extraordinarily well-maintained and reliable.
Unfortunately sometimes some captive portals allow just this one site through and not the others. Looking at you, United WiFi, which whitelists gstatic.com, but fortunately not msftncsi.com.
Of course this thread makes me wonder if I've been doing it wrong.
Using 1.1.1.1 makes a http request, which lets the captive portal take over, so good job, but you are actually hitting a group that actually exists, and what if they suddenly launch a HTST site on that IP? It might break your method.
I think specifically this url: http://www.apple.com/library/test/success.html
For those interested, learn more at: http://www.dns-sd.org/trailingdotsindomainnames.html https://en.wikipedia.org/wiki/Fully_qualified_domain_name