Cloudflare makes Internal DNS generally available for enterprise private networks

Cloudflare makes Internal DNS generally available for enterprise private networks

Cloudflare Internal DNS is now generally available, bringing private DNS zones, views and resolver policies into Gateway.

Format News Brief
Read Time 2 min
Category Software
Updated Jul 21, 2026

Cloudflare has made Internal DNS generally available, moving private name resolution into the same control plane that many of its enterprise customers already use for public DNS, Zero Trust policy, networking and application security.

The July 20 announcement targets a persistent infrastructure problem: companies often operate separate public DNS, private DNS and cloud-specific resolver systems, then add separate security policies on top. Cloudflare says that split can create drift, especially in split-horizon DNS deployments where internal and external users must receive different answers for the same hostname.

What changed

Internal DNS is now available to Cloudflare Enterprise customers that use Cloudflare Gateway, with no additional charge according to the company. The service combines two pieces. Gateway Resolver handles recursive DNS resolution and policy evaluation, while Internal Authoritative DNS serves records for private zones on Cloudflare's authoritative DNS platform.

Administrators work with three main objects: internal zones for private records such as service endpoints and databases, DNS views that define which users or devices can see which zones, and resolver policies that route matching queries to the right view. Cloudflare says zone references let teams reuse shared zones across multiple views, instead of copying the same records into parallel environments.

The product also fits into Cloudflare's broader Zero Trust pitch. A DNS query first reaches the Gateway Resolver, where policy is evaluated. Depending on the policy, the query can be answered from an internal DNS view, blocked, or sent through the public resolution path using 1.1.1.1. Cloudflare says views can fall back to public resolution when a name is not found internally, allowing one resolver path to cover both private and public names.

For operations teams, the most practical promise is fewer separate systems to keep synchronized. Cloudflare says DNS record changes flow through the same DNS Records API whether they come from the dashboard, Terraform or direct API calls, then replicate across its global network. The company also says Internal DNS works with Cloudflare One Client, DNS over HTTPS, DNS over TLS, standard DNS on port 53, PAC file deployments and Cloudflare WAN.

The launch is not a flashy consumer feature, but it is meaningful for enterprises trying to consolidate network plumbing while enforcing identity-aware access controls. Private DNS has historically remained a separate operational island; Cloudflare is betting customers want it governed alongside the rest of their connectivity and security stack.

Sources

Cover photo by Brett Sayles on Pexels, used under the Pexels License.

Comments (0)

Leave a Comment

Loading comments...