Authoritative DNS providers may want to whitelist IP’s 22.214.171.124 uses to query upstream DNS providers. The comprehensive list of IP’s to whitelist is available at https://www.cloudflare.com/ips/.
126.96.36.199 is a privacy centric resolver so it does not send any client IP information and does not send the EDNS Client Subnet Header to authoritative servers
It’s not 1995.
188.8.131.52 has full IPv6 support.
184.108.40.206 is a DNSSEC validating resolver. 220.127.116.11 sends the DO (DNSSEC Ok) bit on every query to convey to the authoritative server that it wishes to receive signed answers if available. 18.104.22.168 supports all signature algorithms including the newer DS-13, DS-14, and DNS-15.
Cloudflare stopped supporting the ANY query in 2015 as ANY queries are more often used to perpetuate large volumetric attacks against the DNS system than valid use. 22.214.171.124 returns NOTIMPL when asked for qtype==ANY.
For decreased latency, reduced privacy leakage of queries and lower load on the DNS system, 126.96.36.199 upstreams to locally hosted root zone files.
Cloudflare minimizes privacy leakage by only sending minimal query name to authoritative DNS servers. For example, if a client is looking for foo.bar.example.com, the only part of the query 188.8.131.52 discloses to .com is that we want to know who’s responsible for example.com and the zone internals stay hidden.