Cloudflare Internal DNS is now generally available – The Cloudflare Blog
15 hours ago
- Cloudflare Internal DNS, combining authoritative and recursive resolution for private networks, is now generally available on the same global network used for public DNS and Zero Trust services.
- It consolidates public and private DNS into a single platform with one API, audit trail, and policy engine, eliminating the need for separate systems and reducing drift and outages.
- Key features include simplifying split-horizon DNS via DNS Views, extending Zero Trust enforcement to DNS queries, and replacing legacy hardware with Cloudflare's global infrastructure.
- The system handles queries by routing them through Gateway Resolver, which applies Resolver Policies that direct traffic to specific Internal Authoritative DNS views or block queries, with optional fallback to public resolution.
- Changes propagate quickly through a unified write path (API, dashboard, or Terraform), replicating across Cloudflare's network and invalidating caches in seconds.
- Setup involves creating an internal zone, a DNS view, and a Gateway resolver policy, with support for various connectivity methods like Cloudflare One Client, DoH, DoT, and standard DNS.
- Internal DNS integrates with the Cloudflare Connectivity Cloud, enabling consistent resolution across remote users, branches, and clouds, and paving the way for tighter integration between DNS, networking, and Zero Trust policy.