(I agree that for privacy DNS over https is good, but the resolver still sees your dns queries)
Dnscrypt-proxy spreads your queries across multiple servers and keeps them private.
If you can afford consider running dnscrypt server yourself. [2]
[1] https://github.com/jedisct1/dnscrypt-proxy
[2] https://github.com/jedisct1/dnscrypt-proxy/wiki/How-to-setup...
> This is unfortunately something we can’t do something about. Nameservers responsible for archive.is (ben.archive.is, anna.archive.is) are returning answers tailored to the IP address of the requestor.
> it is because of 1.1.1.1
> try 8.8.8.8
But compare that answer, to the continued technical breakdowns given by CloudFlare as they tried to work out why archive.is is returning an inaccessible IP based an request IP.
CloudFlare attempted to determine why there was a problem, archive.is shrugged it off.
Or are they claiming archive.is is explicitly blacklisting the cloudflare IP range? If that is the case it seems odd they are claiming the upstream is misconfigured as opposed to explicitly blocking them. Something does not add up correctly.
They do not handle it at all. Remember that the responses are tailored to the IP address of the client, i.e. Cloudflare's back end. It is not Cloudflare that is doing that tailoring. So the question that you should be asking is how come archive.is did that tailoring for (as you claim at any rate, although I suspect that no-one has exhaustively tested this before claiming it) every single other DNS provider and not Cloudflare.
Indeed, if you read what you replied to, you'll find that it's the inverse of that situation. archive.is answers are explicitly tailored by archive.is for whenever it is, specifically, Cloudflare asking. So the question that you should be asking is how come archive.is is saying that it is on a Cloudflare-hosted CDN ("cdn-wo-ecs.archive.is", mapped to Cloudflare hosting IP addresses), but only saying that when it is Cloudflare asking.
Once you ask that latter question, you'll get to the meat of the issue, which is that archive.is demands that Cloudflare et al. pass on (most of) your IP address to them, and returns fake name-to-address mappings for Cloudflare and indeed anyone else who says that (for privacy or otherwise) they are not going to pass on that kind of ultimate client identifying information to archive.is nor to anyone else.
(It's archive.is tailoring its response where there is no EDNS0 client subnet, a.k.a. ECS, information, for the technical. That's what the "wo-ecs" means.)
"returning answers tailored to the IP address of the requestor" is normal and correct behavior for most large websites, the problem is that one of those IP addresses is wrong. Specifically, when the requester is CloudFlare, archive.is is returning a CloudFlare internal IP address instead of their own. I'm guessing where they got that IP address is that it's the requester, and where they got mixed up is that virtually all high-volume DNS requesters that appear overnight are DDoS attacks.
Look at the incentive and core business of the two companies.
Cloudflare is not in the business of mining as much data about you as possible. They don't sell ads and don't make money trying to make you fit into a profile. They have zero incentive to keep an history of all your DNS requests.
Google on the other hand, claim they don't do it but it will make complete sense for their business to do it.
Your username is anothergoogler; do you work for Google?
0. https://twitter.com/eastdakota/status/1024018061311897600