📰 Home 🔒 Admin Login
Jul 27, 2026 ⏰ 4 min read

Say Goodbye to Split DNS: Cloudflare Unifies Public and Private DNS on One Control Plane

If you manage internal DNS for your organisation, you know the pain. Your RFC 1918 addresses (10.x, 172.16.x, 192.168.x) need one resolver — usually BIND, Windows Server DNS, or a Pi-hole — while your public-facing domains run through a separate provider. Two systems. Two policy engines. Two audit trails. And far too many late-night sessions comparing logs across them.

That architecture just got a major simplification option. On July 20, 2026, Cloudflare Internal DNS reached General Availability — bringing authoritative and recursive DNS for private networks onto Cloudflare's global network alongside its public DNS, Zero Trust, and SASE services. This is the kind of release that doesn't make flashy headlines but quietly changes how every sysadmin should think about DNS architecture.

What Actually Changed

Until now, Cloudflare offered two separate DNS products:

  • Cloudflare DNS — authoritative DNS for public domains (what the internet sees)
  • Cloudflare 1.1.1.1 — public recursive resolver (used by clients worldwide)

Neither handled private/internal DNS zones. If you wanted to resolve `intranet.internal.company` or `print-server.admin.corp`, you needed a separate internal DNS stack. That meant managing zones, ACLs, forwarders, and logging on at least two independent systems — with no single pane of glass.

With Internal DNS GA, Cloudflare closes that gap. You can now:

  • Host private DNS zones on Cloudflare's network, resolvable only by your connected clients (via WARP, Magic WAN, or Cloudflare Tunnel)
  • Apply one unified policy engine — every DNS query, public or private, goes through the same security filters, logging rules, and routing policies
  • Get one audit trail — all DNS resolution logged against a single source of truth. No more correlating syslog from two different DNS servers to trace a query's full path

How It Works Under the Hood

The architecture is straightforward but powerful. Cloudflare positions a Recursive DNS Resolver at every one of its 330+ data centers worldwide. When a connected client sends a DNS query:

  1. The query hits the nearest Cloudflare data center
  2. If it's a public domain (e.g., `google.com`), it resolves normally over the public internet
  3. If it's a private zone (e.g., `corp.internal`), Cloudflare checks your Internal DNS configuration and serves the record directly from its edge — never touching your internal infrastructure
  4. Both paths go through the same policy engine — same security filtering, same logging, same Zero Trust policies

The key enabler is Cloudflare's existing connectivity stack. Your clients don't need a new agent — they connect via Cloudflare WARP (the 1.1.1.1 client with WARP enabled), Magic WAN (Cloudflare's SD-WAN), or Cloudflare Tunnel (cloudflared). Once connected, Internal DNS routes are automatically available to those clients regardless of their physical location.

What This Means for Sysadmins

Kill the Split-DNS Headache

The biggest win is operational simplicity. Instead of maintaining separate internal resolvers — patching them, monitoring their logs, managing their ACLs, and troubleshooting why `app.internal.corp` resolves on one floor but not another — you get a single managed service. Cloudflare handles the uptime, the security patches, and the global anycast distribution.

Zero Trust DNS, Natively

If you're already running Cloudflare Zero Trust, Internal DNS slots in naturally. You can write a single Gateway policy that says "block malware domains for all DNS queries — public AND private — with exceptions for these three private zones." One rule. One enforcement point. No "oh, the malware block only works for internet-bound traffic" blind spots.

Single Audit Trail for Compliance

For anyone dealing with SOC 2, ISO 27001, or PCI-DSS audits, this is gold. Every DNS query — `google.com`, `payments.internal.corp`, `s3.amazonaws.com` — lands in the same log stream with the same metadata. No more stitching together logs from different DNS resolvers to answer "who queried what, when, and where."

The Bottom Line for Your Network

Cloudflare Internal DNS is not a replacement for every internal DNS setup. If you run Active Directory, you still need Windows DNS for zone replication and SRV record registration. If you operate a tightly air-gapped network, a local resolver is non-negotiable.

But for the vast middle ground — organisations with distributed workforces, multi-cloud architectures, or hybrid networks — this is a genuine simplification. One control plane. One policy engine. One audit trail. And the operational overhead of split DNS becomes a thing you used to deal with, not a thing you deal with daily.

For sysadmins evaluating their DNS strategy in 2026, the question is no longer "which resolver should I run" but "do I need to run one at all?"


Cloudflare Internal DNS is generally available now. Pricing is based on the number of private DNS zones and query volume — check Cloudflare's pricing page for your region's rates.

Infographic: Cloudflare Internal DNS — Unified DNS Explained

Infographic: Cloudflare Internal DNS — Unified DNS Explained

← Back to Homepage

💬 0 Comments

☕ Support Eismar Tech Hub

🌎 International

Buy me a coffee

Credit Card / PayPal accepted

💳 Local (Malaysia)

Touch N Go QR

Touch 'n Go / DuitNow QR