Cloudflare Internal DNS is now generally available
Key Points
- GA: Cloudflare Internal DNS
- Authoritative + recursive on one control plane
- Included with Cloudflare Gateway (Enterprise)
Summary
Cloudflare Internal DNS is generally available. It unifies authoritative and recursive private DNS onto the same global Cloudflare control plane you already use for public DNS, Zero Trust, and networking services. For Enterprise customers, Internal DNS is included with Cloudflare Gateway at no additional charge.
Key Points
- Single control plane: manage public and private DNS with one API, one audit trail, and centralized policies.
- Split-horizon made simple: internal and external resolution are separate views on shared zones, reducing drift and outage risk.
- Zero Trust for DNS: resolver policies route users/devices to the correct view and are enforced by Cloudflare Gateway.
- Modernization: retire hardware appliances and cloud-locked resolvers; runs on Cloudflare infrastructure (1.1.1.1).
- Architecture: two components — Gateway Resolver (recursive resolution + policy engine) and Internal Authoritative DNS (zone management).
Practical next steps for engineers
- Inventory internal zones and split-horizon requirements.
- Map which users/devices should resolve each view and define resolver policies.
- Test zones and policies in a staging account via the Cloudflare API before wide rollout.
- Plan decommissioning of legacy DNS appliances once parity and failover are validated.
Why it matters
Consolidating DNS reduces operational overhead, removes synchronization risk between parallel DNS systems, and extends existing Zero Trust controls to internal name resolution, improving security and reliability.