Cloudflare Docs
Cloudflare Zero Trust
Visit Cloudflare Zero Trust on GitHub
Set theme to dark (⇧+D)

Global policies

Cloudflare Zero Trust applies a set of global policies to all accounts.

​​ DNS policies

Criteria Value Action Description
Hostname *.nel.cloudflare.com allow Allows SNI domains for WARP registration.
Hostname *.cloudflareclient.com allow Allows Zero Trust client.
Hostname *.cloudflare-gateway.com allow Allows Gateway proxy with PAC files.
Hostname dash.teams.cloudflare.com, help.teams.cloudflare.com, blocked.teams.cloudflare.com, api.cloudflare.com, cloudflarestatus.com, www.cloudflarestatus.com, and one.dash.cloudflare.com allow Allows Cloudflare Zero Trust services.
Hostname *.cloudflareaccess.com allow Allows Cloudflare Access applications.

​​ Network proxy policies

Criteria Value Action Description
Hostname *.cloudflareaccess.com allow Allows Cloudflare Access applications.
Hostname help.teams.cloudflare.com allow Used by the WARP client to check if Gateway is on by inspecting the certificate and checking if it is properly installed on the client device.
Content Category Child Abuse block Blocks child abuse materials.

​​ HTTP inspection policies

Criteria Value Action Description
Hostname *.cloudflareclient.com bypass Ensures users cannot accidentally block themselves from making account changes.
Hostname *.cloudflarestatus.com bypass Bypasses cloudflarestatus.com so users can reach the status page in case of a Gateway outage.
Hostname *.cloudflare-gateway.com bypass Ensures requests to the cloudflare-gateway.com DNS endpoint will not be inspected.
Hostname *.nel.cloudflare.com bypass Bypasses *.nel.cloudflarestatus.com for Cloudflare’s network error logging feature.
Hostname api.cloudflare.com bypass Bypasses Cloudflare’s API endpoint.
Hostname dash.teams.cloudflare.com bypass Prevents users from being locked out of the Zero Trust dashboard.
Hostname *.dash.cloudflare.com bypass Bypasses the Cloudflare dashboard and subdomains.
Hostname blocked.teams.cloudflare.com bypass Prevents an infinite loop on the Gateway block page.
Hostname developers.cloudflare.com and help.cloudflarebrowser.com noisolate Prevents isolation of Cloudflare developer docs and help pages to help users troubleshoot configuration issues.
Hostname *.assets.browser.run bypass Required for Remote Browser Isolation (RBI).
Hostname *.edge.browser.run and *.cloudflarebrowser.com bypass Required for RBI.
Hostname *.edge.browser.run and *.cloudflarebrowser.com isolate Required for RBI.
Hostname speed.cloudflare.com noscan Allows files transferred by the Cloudflare speed test.
Request Header Accept: text/html noisolate Ensures only browsers will be isolated. Browsers issue an Accept: HTTP header that begins with text/html.
Application Online Certificate Status Protocol bypass Enables OCSP stapling.