Cloudflare · OFFICIAL ARTICLE

Cloudflare Internal DNS 现已正式可用

Cloudflare Internal DNS 将适用于私有网络的权威 DNS 和递归 DNS 整合到运行 Cloudflare Zero Trust、网络以及公共 DNS 的同一全球网络和控制平面之上。

来源:Cloudflare
ORIGINAL · 官方原文

Cloudflare Internal DNS is now generally available

详细说明

Blog Cloudflare Gateway DNS General Availability +5 Show 5 more tags

8 Tags Show 8 tags

Internal DNS Networking Product News SASE Zero Trust

Cloudflare Gateway DNS General Availability Internal DNS Networking Product News SASE Zero Trust

July 20, 2026

  • Selected Tags
  • Cloudflare Gateway DNS General Availability Internal DNS Networking Product News SASE Zero Trust
  • All tags
  • Matching tags
  • No tags found
  • 1.1.1.1
  • 2FA
  • Abuse
  • Access
  • Access Control Lists (ACLs)
  • Accessibility
  • Account Takeover
  • Acquisitions
  • Addressing
  • Advanced Certificate Manager
  • Advanced DDoS
  • Advertising
  • Aegis
  • Africa
  • Afroflare
  • Agent Readiness
  • Agents
  • Agents Week
  • AI
  • AI Bots
  • AI Gateway
  • AI Search
  • AI-SPM
  • AI WAF
  • AI Week
  • Alertmanager
  • Always Online
  • AMD
  • AMP
  • Analytics
  • Anonymous
  • Anti Malware
  • Anycast
  • API
  • API Gateway
  • API Security
  • API Shield
  • APJC
  • Apple
  • Application Security
  • Application Services
  • Area 1 Security
  • Argo Smart Routing
  • ASCII
  • Asia
  • Athenian Project
  • Atlassian
  • Attacks
  • Audit Logs
  • Austin
  • Australia
  • Authentication
  • Authy
  • Automatic HTTPS
  • Automatic Platform Optimization
  • Automation
  • AutoMinify
  • Auto Rag
  • Awards
  • AWS
  • Baidu
  • Bandwidth Alliance
  • Bandwidth Costs
  • Best Practices
  • Beta
  • Better Internet
  • BGP
  • Birthday Week
  • Blackbird
  • Black Friday
  • Bot Fight Mode
  • Bot Management
  • Botnet
  • Bots
  • BPF
  • Brand
  • Brand Protection
  • Brazil
  • Browser Insights
  • Browser Rendering
  • Browser Run
  • Bug Bounty
  • Bugs
  • BYOIP
  • Cache
  • Cache Purge
  • Cache Reserve
  • Cache Rules
  • California
  • Canada
  • Cap'n Proto
  • CAPTCHA
  • Careers
  • CASB
  • Categories
  • CDN
  • CDNJS
  • Certificate Authority
  • Certificate Pinning
  • Certificate Transparency
  • Certification
  • CFSSL
  • Challenge Page
  • ChatGPT
  • China
  • China Network
  • Christmas
  • Chrome
  • CIO Week
  • CISA
  • Claire
  • CLI
  • ClickHouse
  • Clientless
  • Clientless Web Isolation
  • Cloud Connector
  • Cloud Email Security
  • Cloudflare Access
  • Cloudflare Apps
  • Cloudflare Area 1
  • Cloudflare Calls
  • Cloudflare Email Service
  • Cloudflare for Campaigns
  • Cloudflare for SaaS
  • Cloudflare for Startups
  • Cloudflare Gateway
  • Cloudflare History
  • Cloudflare Images
  • Cloudflare Media Platform
  • Cloudflare Meetups
  • Cloudflare Network
  • Cloudflare One
  • Cloudflare One Client
  • Cloudflare One User Risk Score
  • Cloudflare One Week
  • Cloudflare Pages
  • Cloudflare Polish
  • Cloudflare Queues
  • Cloudflare Realtime
  • Cloudflare Stream
  • Cloudflare Tunnel
  • Cloudflare TV
  • Cloudflare Workers
  • Cloudflare Workers KV
  • Cloudflare Workers KV (ES)
  • Cloudflare Workers (PT)
  • Cloudflare Zero Trust
  • Cloudforce One
  • Cloudy
  • Code Orange
  • Coinbase
  • Colombia
  • Community
  • Compliance
  • Compression
  • Config Rules
  • Configuration Management
  • Congestion Control
  • Connectivity
  • Connectivity Cloud
  • Consumer Services
  • Containers
  • Content Independence Day
  • Content Scanning
  • Context
  • Core
  • COVID-19
  • Crawler Hints
  • CrowdStrike
  • Cryptography
  • Crypto Week
  • CSAM Reporting
  • Customers
  • Customer Success
  • Customer Zero
  • CVE
  • CVE-2023-50387
  • Cyber Readiness
  • Cybersecurity
  • D1
  • Dashboard
  • Data
  • Database
  • Data Catalog
  • Data Center
  • Data Localization
  • Data Localization Suite
  • Data Loss
  • Data Loss Prevention
  • Data Platform
  • Data Privacy Day
  • Data Protection
  • Data Sovereignty
  • Data Transfer Bucket
  • DDoS
  • DDoS Alerts
  • DDoS Reports
  • Debugging
  • Deep Dive
  • Descaler
  • Design
  • Deskope
  • Developer Documentation
  • Developer Platform
  • Developers
  • Developer Spotlight
  • Developers Storage
  • Developer Week
  • Device Security
  • DevOps
  • DEX
  • Digital Experience Monitoring
  • Digital Forensics
  • Disrupt
  • Distributed
  • Distributed Systems
  • Distributed Web
  • Diversity
  • DLP
  • DMARC
  • DNS
  • DNS Filtering
  • DNS Flood
  • DNSSEC
  • DNS Security
  • Dogfooding
  • DoH
  • Domain Rankings
  • Domain Scoped Roles
  • dosd
  • Drupal
  • Due Process
  • Durable Execution
  • Durable Objects
  • Early Hints
  • Earth Day
  • eBPF
  • EC2
  • eCommerce
  • Edge
  • Edge Computing
  • Edge Database
  • Edge Rules
  • Education
  • Egress
  • Elastic
  • Elections
  • Election Security
  • Elliptic Curves
  • Email
  • Email Routing
  • Email Security
  • Email Workers
  • EmDash
  • Emissions
  • Employee Resource Groups
  • Encrypted SNI
  • Encryption
  • Engineering
  • Enterprise
  • Entropy
  • EPYC
  • Ethereum
  • Europe
  • European Union
  • Events
  • Exploit
  • Facebook
  • Fancy Bear
  • Fast Fonts
  • FCC
  • Feature Flags
  • FedRAMP
  • FedRAMP High
  • FedRAMP Moderate
  • Firefox
  • Firewall
  • Firmware
  • Florida
  • Football
  • Formal Methods
  • Forrester
  • Fortran
  • Foundation DNS
  • Founders' Letter
  • France
  • Fraud
  • Free
  • Freedom of Speech
  • Front End
  • Full Stack
  • Full Stack Week
  • Fun
  • Gartner
  • Gatebot
  • GA Week
  • GDPR
  • General Availability
  • Generative AI
  • Gen X
  • Geo Key Manager
  • Germany
  • GitHub
  • Go
  • Google
  • Google Analytics
  • Google Cloud
  • Google Workspace
  • Government Innovation
  • Grace Hopper
  • Grafana
  • GraphQL
  • Green
  • Grinch
  • Growth
  • gRPC
  • Guest Post
  • Hackathon
  • Halloween
  • Hardware
  • HashiCorp
  • Hertzbleed
  • Heuristics
  • History
  • Holidays
  • Holocaust
  • Hong Kong
  • Hosting Con
  • Hostnames
  • HTTP2
  • HTTP3
  • HTTPS
  • Human Rights
  • Hurricane
  • Hybrid Cloud
  • Hyperdrive
  • IBM
  • ICANN
  • iCloud Private Relay
  • Identity
  • IETF
  • IL4
  • Image Optimization
  • Image Recognition
  • Image Resizing
  • Image Storage
  • Impact
  • Impact Week
  • I'm Under Attack Mode
  • Incident Report
  • Incident Response
  • India
  • Indicators of Compromise
  • Indonesian
  • Infrastructure
  • Infrastructure as Code
  • Insights
  • Intel
  • Interconnection
  • Internal DNS
  • Internet Performance
  • Internet Quality
  • Internet Regulation
  • Internet Shutdown
  • Internet Summit
  • Internet Traffic
  • Internet Trends
  • Internship Experience
  • Intrusion Detection
  • Investors
  • IoCs
  • iOS
  • IoT
  • IPFS
  • IPsec
  • IPv4
  • IPv6
  • IRAP
  • Israel
  • Italy
  • IWD
  • JAMstack
  • Japan
  • JavaScript
  • Jengo
  • Jengo Policy
  • Joomla
  • Judeoflare
  • Kafka
  • Kernel
  • Keyless SSL
  • KeyTrap
  • Key Value
  • Killnet
  • Korea
  • Kubernetes
  • LangChain
  • Latency
  • Latin America
  • Latinflare
  • LavaRand
  • Lazarus group
  • Leaked Credential Checks
  • Legal
  • Legal Patents Sable
  • LGBTQIA+
  • Life at Cloudflare
  • Linux
  • Lisbon
  • Live Streaming
  • Llama
  • LLM
  • Load Balancing
  • Localization
  • Log4J
  • Log4Shell
  • Logging
  • Log Push
  • Logs
  • LUA
  • Machine Learning
  • Magecart
  • Magic Firewall
  • Magic Network Monitoring
  • Magic Transit
  • Magic WAN
  • Magic WAN Connector
  • Malicious JavaScript
  • Malware
  • Managed Components
  • Managed Rules
  • March of Cloudflare
  • MASQUE
  • MCP
  • Meerkat
  • MeetUp
  • Meris
  • Message Protocol
  • Mexico
  • Micro-frontends
  • Microsoft
  • Microsoft 365
  • Microsoft Azure
  • Middle East
  • Migration Hub
  • Milestones
  • Miniflare
  • Mirage
  • Mirai
  • Mitel
  • Mitigation
  • Mixed Content Errors
  • MLops
  • Mobile
  • Mobile SDK
  • Model Context Protocol
  • Moldova
  • Monitoring
  • Multi-Cloud
  • Multi-User
  • MySQL
  • NaaS
  • Net Neutrality
  • Network
  • Networking
  • Network Interconnect
  • Network Performance Update
  • Network Protection
  • Network Services
  • New Year
  • NGINX
  • Ninjas
  • NIST
  • Node.js
  • North America
  • Notebooks
  • Notifications
  • NSEC3
  • OAuth
  • Observability
  • Oceania
  • OCSP
  • Offices
  • Okta
  • Olympics
  • Onboarding
  • OpenAI
  • Open API
  • OpenBMC
  • OpenDNS
  • Open Source
  • OpenSSL
  • OpenTelemetry
  • Optimization
  • Origin Rules
  • Outage
  • Oxy
  • Pacific Northwest
  • Page Rules
  • Page Shield
  • Parallels
  • Partners
  • Partnership
  • Password-reuse
  • Passwords
  • Passwords (PT)
  • Patents
  • PAYGO
  • Payments
  • Pay Per Crawl
  • PCI Certified
  • Peering
  • Performance
  • Phishing
  • php
  • Phython
  • Pingora
  • Pipelines
  • PlanetScale
  • Plans
  • Platform Engineering
  • Platform Week
  • Plesk
  • Policy & Legal
  • Politics
  • Portugal
  • Postgres
  • Post Mortem
  • Post-Quantum
  • Precursor
  • Prepared Statements
  • Prisma
  • Privacy
  • Privacy Pass
  • Privacy Week
  • Private IP
  • Private Network
  • Product Design
  • Product News
  • Programming
  • Programming (PT)
  • Project Fair Shot
  • Project Galileo
  • Project Honey Pot
  • Project Pangea
  • Project Safekeeping
  • Project Turpentine
  • Prometheus
  • Protocols
  • Proudflare
  • Proxying
  • Public Sector
  • Python
  • Queues
  • QUIC
  • QUICHE
  • Quicksilver
  • R2
  • R2 Super Slurper
  • Radar
  • Radar Alerts
  • Radar API
  • Radar Maps
  • Railgun
  • Randomness
  • Ransom Attacks
  • Rapid Reset
  • Raspberry Pi
  • Rate Limiting
  • RC4
  • RDDoS
  • React
  • Reading List
  • Real-time
  • Recruiting
  • Regional Services
  • Registrar
  • Reliability
  • Remote Browser Isolation
  • Remote Desktop Protocol
  • Remote Work
  • Replication
  • Research
  • Resolver
  • Restreaming
  • Retreat
  • Reverse Engineering
  • REvil
  • Risk Management
  • Road to Zero Trust
  • Rocket Loader
  • RocksDB
  • Routing
  • Routing Security
  • RPKI
  • RRDNS
  • RSA
  • Russia
  • Rust
  • Rust Workers
  • SaaS
  • SAAS Security
  • Sable
  • Salt
  • Sampling
  • Sandbox
  • SASE
  • Save The Web
  • SDK
  • Search Engine
  • Secrets Store
  • Secure Web Gateway
  • Security
  • Security Analytics
  • Security Center
  • Security Posture
  • Security Posture Management
  • Security Service Edge
  • security.txt
  • Security Week
  • SEO
  • Serverless
  • Serverless AI
  • Serverless (PT)
  • Serverless Week
  • Server Push
  • Servers
  • SIEM
  • Signed Exchanges (SXG)
  • SIM
  • Singapore
  • Single Sign On (SSO)
  • Smart Placement
  • Smart Shield
  • Snippets
  • SOC as a Service
  • South Africa
  • South America
  • Spain
  • spdy
  • Spectrum
  • Speed
  • Speed Brain
  • Speed & Reliability
  • Speed Week
  • Spoofing
  • Sports
  • SQL
  • SRE
  • SSE
  • SSH
  • SSL
  • Standards
  • Startup Enterprise Plan
  • Statistics
  • StopTheHacker
  • Storage
  • Sumo Logic
  • Super Bowl
  • Supercloud
  • Supply Chain Attacks
  • Support
  • Sustainability
  • SWAG
  • SWG
  • Swift
  • Switzerland
  • SXSW
  • SYN
  • SYN Flood
  • Syria
  • TCP
  • Team
  • Teams Dashboard
  • TechCrunch
  • Technical Writing
  • Tech Talks
  • Terraform
  • Testimonials
  • Testing
  • Texas
  • Thanksgiving
  • The Serverlist Newsletter
  • Threat Data
  • Threat Feeds
  • Threat Intelligence
  • Threat Operations
  • Threats
  • Tiered Cache
  • TikTok
  • TLS
  • TLS 1.3
  • Tools
  • Tor
  • Tracing
  • Traffic
  • Transform Rules
  • Transparency
  • Trends
  • Trust & Safety
  • TTFB
  • TTL
  • TURN
  • TURN Server
  • Turnstile
  • TypeScript
  • UDP
  • Ukraine
  • United Kingdom
  • Universal SSL
  • URL Scanner
  • USA
  • User Research
  • VDI
  • Vectorize
  • Vetflare
  • Video
  • Visibility
  • Vite
  • VoIP
  • VPC
  • VPN
  • Vulnerabilities
  • WAF
  • WAF Attack Score
  • WAF Rules
  • Waiting Room
  • WARP
  • WARP Connector
  • WASM
  • Web3
  • Web Application Firewall
  • WebAssembly
  • Web Asset Discovery
  • Webinars
  • WebP
  • WebRTC
  • WebSockets
  • Wildebeest
  • Womenflare
  • WordPress
  • Workers AI
  • Workers Launchpad
  • Workers Logs
  • Workers Observability
  • Workers Sites
  • Workers Unbound
  • Workers VPC
  • Workflows
  • World IPv6 Day
  • Wrangler
  • x402
  • Year in Review
  • Z3
  • Zaraz
  • Zero Day Threats
  • Zero Trust
  • Zero Trust Week
  • Zone Versioning

Cloudflare Internal DNS is now generally available

Enrique Somoza and Hannes Gerhart

6 minute read

COPY URL

Starting today, Cloudflare Internal DNS is generally available. Cloudflare Internal DNS provides authoritative and recursive DNS for private networks on the same global network and control plane customers already use for public DNS, Zero Trust, networking, and application services.

Internal DNS — sometimes also referred to as private DNS — is one of the last pieces of enterprise infrastructure still managed separately from the rest of the network. Many organizations operate one platform for public DNS, another for internal DNS, and use cloud-native DNS services inside each cloud environment with separate security policies layered on top. None of these systems share a common control plane. Split-horizon DNS adds another layer of complexity, often requiring multiple DNS environments to remain synchronized so internal and external users receive different answers for the same hostname. When those systems drift, outages follow.

With Cloudflare Internal DNS, you get a single platform to manage public and private DNS resources, enforcing DNS policies and gaining visibility across your entire DNS stack. For Enterprise customers, this is included with Cloudflare Gateway without any additional charge.

Why customers are adopting Internal DNS

Consolidate DNS operations . Public and private DNS run on one platform, with one API, one audit trail, and one place to set policy. The appliance refresh cycle and the scaling bottlenecks that came with legacy DNS go away.

Simplify split-horizon DNS . Internal and external resolution are defined as separate views over shared zones, managed from a single control plane. There are no parallel systems to keep in sync, so there's no drift to chase down.

Extend Zero Trust to DNS . Resolver policies decide which users and devices resolve against which view, enforced by the same Cloudflare Gateway that already governs the rest of your traffic. Private name resolution stops being the gap in an otherwise Zero Trust architecture.

Modernize legacy infrastructure . Retire hardware appliances, legacy DNS servers, and cloud-locked resolvers. Cloudflare Internal DNS runs on the infrastructure behind 1.1.1.1, with no hardware to rack and no capacity to provision.

What we built

Cloudflare Internal DNS consists of two components: Gateway Resolver and Internal Authoritative DNS . Authoritatively managing zones is a different job from enforcing DNS security and routing policies.

The Gateway Resolver handles recursive resolution and policy evaluation. Launched in 2020 and powered by 1.1.1.1 for public resolution, it comes with a built-in policy engine that can filter DNS queries and redirect queries to different upstream sources — all based on flexible expressions , with comprehensive logging and audits feeding a single pane of glass.

Internal Authoritative DNS serves records for internal zones built on the same authoritative platform Cloudflare has operated for over a decade and that serves more domains than any other provider.

There are three primary objects customers work with:

Zone references let administrators reuse a shared zone across multiple views rather than copying its records into each one. A common zone like intranet.local is defined once and referenced everywhere it's needed, which is the difference between a Don't-Repeat-Yourself configuration and the duplicated, drift-prone setup that split-horizon usually forces.

  • Internal Zones hold the authoritative records for private resources: environment-specific apps, service endpoints, databases.
  • DNS Views group zones into the resolution context a given set of users or devices should see. This is what makes split-horizon work without parallel systems.
  • Resolver Policies sit in Gateway and route matching queries to a specific view.

How a query resolves

A DNS query from a client first hits the Gateway Resolver, where policy is evaluated. From there, one of three things happens. If a resolver policy matches and points at an internal view, the query is routed to Internal Authoritative DNS and answered from the matching view's zones. If policy blocks the query, it is dropped at the resolver. Otherwise, the query follows the public path, with 1.1.1.1 resolving it against the public DNS hierarchy. Views can also fall back to public resolution when a name isn't found internally, so a single resolver can serve both private and public names without the client needing to know which is which.

How a change propagates

Record changes follow a predictable, high-speed path from input to edge.

Every change enters through the same DNS Records API, whether it originates in the dashboard, in Terraform, or in a direct API call. That unified ingress means there is exactly one write path to reason about and audit, regardless of how the change was made. The change is persisted in Cloudflare's core data centers for durability and validated before it propagates.

From there, changes replicate across Cloudflare's global network and affected cached entries are invalidated as the updates arrive, so edited records take effect in seconds rather than waiting on TTL expiry.

Getting started

If you're an Enterprise customer using Cloudflare Gateway, you have access to Internal DNS today. Open the Cloudflare dashboard, navigate to Networking, then Internal DNS .

Setting up Internal DNS typically takes three steps: create a zone, create a view, and define a resolver policy that determines which users and devices should resolve against that view.

Create an internal zone and your first internal record:

POST https: //api.cloudflare.com/client/v4/accounts/zones

{

"account" : {

"id" : "{account_id}"

},

"name" : "corp.internal" ,

"type" : "internal"

}

POST https: //api.cloudflare.com/client/v4/zones/{zone_id}/dns_records

{

"type" : "A" ,

"name" : "db.corp.internal" ,

"content" : "10.0.1.50" ,

"ttl" : 300

}

Then create a DNS view and link your zone to it:

POST https: //api.cloudflare.com/client/v4/accounts/{account_id}/internal_dns/views

{

"name" : "production-view" ,

"zones" : [ "{zone_id}" ]

}

Finally, create a Gateway resolver policy in the Zero Trust dashboard that routes matching traffic to your view. Create a Gateway location , set your conditions, select Internal DNS View as the resolution method, and choose your view. That's it. Queries matching your policy now resolve against your internal zones.

Terraform support is available, and because Terraform writes through the same DNS Records API as everything else, infrastructure-as-code changes follow the identical ingestion and propagation path. Full documentation and end-to-end configuration examples are available in our developer documentation .

Internal DNS as part of the Connectivity Cloud

Internal DNS works with any Cloudflare connectivity method that routes DNS traffic through the Gateway Resolver, including the Cloudflare One Client (formerly WARP), DNS over HTTPS (DoH), DNS over TLS (DoT), standard DNS on port 53, PAC file deployments, and Cloudflare WAN.

For organizations running Cloudflare WAN, every device on the connected network can resolve internal hostnames through Cloudflare without requiring the Cloudflare One Client on individual devices. The result is a consistent DNS experience across remote users, branch offices, data centers, and cloud environments using a single control plane.

More importantly, Internal DNS is not a standalone DNS service. It extends the same Connectivity Cloud platform that organizations already use to secure users with Zero Trust, connect networks with Cloudflare WAN, accelerate applications, and protect Internet-facing services.

Bringing private DNS onto the same global network as everything else is just the starting point. Tighter integration across DNS, networking, and Zero Trust policy is where this goes next — so resolving an internal hostname, reaching the service behind it, and enforcing who is allowed to access it become decisions made through a single platform, rather than multiple disconnected systems.

Ready to consolidate your DNS? Open the dashboard, head to Networking, then Internal DNS , and create your first zone today. Questions or want to compare notes with other operators? Join the conversation in the Cloudflare Community .

Related tags

Cloudflare Gateway DNS General Availability Internal DNS Networking Product News SASE Zero Trust

Follow on Social Media

  • Cloudflare
  • Hannes Gerhart