Cloudflare Gateway Now Redirects Internal DNS Lookups
Cloudflare Gateway, the DNS filtering component of Cloudflare for Teams, has added a domain override capability. Administrators can now define rules that return an alternative IP address for a hostname instead of the address the resolver would normally produce. The change lets organizations keep traffic for internal services on-premise or in a private network while still routing everything else through Gateway’s security filtering.
The feature works across Cloudflare’s full network footprint of over 200 cities, so the redirection logic runs at the same edge locations that enforce Gateway’s threat-blocking policies. There is no performance penalty for combining the two functions.
Where Gateway Fits in a Zero-Trust Stack
Cloudflare for Teams combines Gateway’s secure DNS with Cloudflare Access, which provides identity-based access control for internal applications. Together, the two products let organizations replace on-premise security appliances and private-network trust assumptions with a cloud-delivered model.
Gateway’s initial release introduced DNS-layer security filtering and content blocking on top of Cloudflare’s 1.1.1.1 resolver. Deployment is designed to take less than five minutes, whether for a full office network, per-device through an MDM on IPv6-capable networks, or via dedicated IPv4 addresses for enterprise accounts. A single toggle blocks known malware and phishing sources, and policies can extend to categories such as gambling or social media. When a request hits a filtered hostname, Gateway prevents the DNS query from resolving and shows the user a “blocked domain” page.
Routing Traffic That Stays on the Private Network
Organizations modernizing their infrastructure often run some services on the private network while moving others to SaaS or protecting them with Cloudflare Access. Domain overrides ease that transition: teams can keep certain hostnames pointing at local IPs while the same resolver secures all other Internet-bound traffic. End users continue reaching those internal resources without changing anything on their devices.
When the organization is ready, those same hostnames can be moved behind Cloudflare Access, removing the need for the private network entirely. The override also addresses split-horizon DNS setups, where a hostname exists publicly but must resolve to an internal IP for users on the local network. Admins can define a policy that routes traffic for that name, even if it is publicly registered, to the private address.
Rule Enforcement on the Edge
Override policies are distributed to Cloudflare’s edge and become part of the Gateway enforcement flow for that organization. They take precedence over allow and block rules: when a request arrives at a Gateway IP, Cloudflare identifies the source IP, checks for an applicable override, and returns the configured address. The feature is supported on Cloudflare’s IPv4 and IPv6 addresses as well as over DNS over HTTPS.
The feature requires no additional cost and is available to all Cloudflare for Teams customers immediately. To create an override, administrators go to the Policies section of Gateway and select the “Custom” tab; the platform supports up to 1,000 custom rules. Cloudflare is also offering free Teams platform access through September 1 for organizations transitioning to remote work, and free dedicated onboarding sessions are available on request.



