The nitty gritty
188.8.131.52 is a DNSSEC validating resolver. 184.108.40.206 sends the DO (DNSSEC Ok) bit on every query to convey to the authoritative server that it wishes to receive signed answers if available. 220.127.116.11 supports including the newer DS-13, DS-14, and DNS-15.
EDNS client subnet
18.104.22.168 is a privacy centric resolver so it does not send any client IP information and does not send the EDNS Client Subnet Header to authoritative servers.
It’s not 1995.
22.214.171.124 has full IPv6 support.
Query name minimization
Cloudflare minimizes privacy leakage by only sending minimal query name to authoritative DNS servers. For example, if a client is looking for foo.bar.example.com, the only part of the query 126.96.36.199 discloses to .com is that we want to know who’s responsible for example.com and the zone internals stay hidden.