Cloudflare Internal DNS goes GA | public/private DNS merged, Zero Trust extends to name resolution
TL;DR
Cloudflare on July 20 announced Internal DNS is generally available, providing authoritative and recursive DNS resolution for private enterprise networks on the same global network and control plane as its public DNS, Zero Trust, and network services. Free for existing Gateway customers. Zero Trust policy now extends to DNS resolution.
Cloudflare on July 20 announced its Internal DNS service is generally available. It offers authoritative and recursive DNS resolution for private enterprise networks, sharing the same global network and control plane as Cloudflare's public DNS, Zero Trust and network services — the first time Cloudflare has folded private DNS into its anycast edge.
Existing Cloudflare Gateway customers get it at no additional cost. That pricing move takes direct aim at Cisco Umbrella and Zscaler's "private-DNS add-on" business model — those rivals sell internal resolution as a premium; Cloudflare bundles it into the Gateway subscription.
The core design is "DNS Views" — unifying public and private DNS on one platform, simplifying split-horizon DNS setup and eliminating data drift from syncing multiple systems (same name resolving differently inside vs outside). Admins set resolver policies deciding which internal views different users and devices can reach — Zero Trust policy extends to DNS resolution, the first time Cloudflare Zero Trust has folded DNS into the policy engine.
Deployment supports API, Terraform and Cloudflare WAN. That means handing internal DNS to Cloudflare can retire the old Windows AD DNS / BIND / Infoblox stack many enterprises maintain in-house.
Cloudflare hit DNS vendors, SASE vendors and identity vendors in one release — its most aggressive lateral expansion since assembling Access → Gateway → WAN as a full stack in 2024.
via The Cloudflare Blog
Existing Cloudflare Gateway customers get it at no additional cost. That pricing move takes direct aim at Cisco Umbrella and Zscaler's "private-DNS add-on" business model — those rivals sell internal resolution as a premium; Cloudflare bundles it into the Gateway subscription.
The core design is "DNS Views" — unifying public and private DNS on one platform, simplifying split-horizon DNS setup and eliminating data drift from syncing multiple systems (same name resolving differently inside vs outside). Admins set resolver policies deciding which internal views different users and devices can reach — Zero Trust policy extends to DNS resolution, the first time Cloudflare Zero Trust has folded DNS into the policy engine.
Deployment supports API, Terraform and Cloudflare WAN. That means handing internal DNS to Cloudflare can retire the old Windows AD DNS / BIND / Infoblox stack many enterprises maintain in-house.
Cloudflare hit DNS vendors, SASE vendors and identity vendors in one release — its most aggressive lateral expansion since assembling Access → Gateway → WAN as a full stack in 2024.
via The Cloudflare Blog
