Meter builds a multi-tenant DNS filter on Cloudflare’s Gateway
Cloudflare’s tenant architecture, introduced with the Tenant API, was designed to let managed service providers and infrastructure businesses deploy Cloudflare security offerings across many downstream customers. The integration with Cloudflare Gateway — the company’s Secure Web Gateway — lets those organizations apply DNS filtering and web inspection from a single control plane. Early adopters include the US federal government, MalwareBytes, and a large global ISP. Now Cloudflare is highlighting how Internet infrastructure provider Meter uses the same mechanism to deliver DNS filtering to its own client base.
Parent-child policies for distributed organizations
Meter, founded in 2015 and based in San Francisco, builds Internet infrastructure for commercial spaces: routing, switching, wireless, and related applications. Its customers span offices, warehouses, retail outlets, manufacturing facilities, biotech companies, and educational institutions. Through the Meter dashboard, those customers can define policies that permit or block domain access, with categories based on security risk (phishing, malware, DGA, etc.) or content type (adult, gambling, shopping, etc.).
The ability to manage parent-child policy relationships is a recurring requirement across Meter’s customer base. A school district, for instance, may need to apply district-wide rules while individual schools enforce their own stricter or more permissive browsing policies.
Cloudflare’s parent-child model lets Meter administrators set granular, different policies for specific offices, retail locations, or warehouses (configured as child accounts) within a larger organization (the parent account). When a DNS query arrives, it is first evaluated against parent account policies, then against the applicable child account policies.
At the account level, each child customer can carry its own users and tokens for management purposes. Meter’s customers set up their own DNS endpoints via Gateway locations, which can be IPv4, IPv6, DoH, or DoT endpoints, and define DNS policies for those locations. Customers can also tailor the block page shown to end users, including uploading their own certificates to serve that custom page.

Beyond DNS filtering
Cloudflare positions DNS filtering as the entry point for a broader Zero Trust push through its tenant platform. The company says it intends to expose additional Zero Trust services via the same tenant architecture in the future.



