Cloudflare Internal DNS Reaches General Availability Inside Zero Trust Gateway
Cloudflare's Internal DNS bundles authoritative and recursive DNS for private networks into Zero Trust Gateway at no extra cost for Enterprise customers - a real reason to reconsider a separate internal-DNS tool if you're already paying for Gateway.
Decision Brief
What to do with this research
Cloudflare Internal DNS is now generally available, combining Gateway Resolver (recursive resolution) and Internal Authoritative DNS (private zone records) on Cloudflare's existing network. For Enterprise customers already on Cloudflare Gateway, it's included at no extra cost, supports split-horizon DNS without duplicating records, and propagates changes in seconds rather than waiting on TTLs. That's a real reason for those customers to reconsider a separate internal-DNS tool, but Cloudflare hasn't said whether Free, Pro, or Business plans get any access at all.
Use the conclusion, then validate live pricing and plan limits before buying.
SaaS Pricing Checks changes
Get a practical ToolPick alert when pricing, free-plan limits, policy risk, or alternatives change.
Weekly at most ยท one-click unsubscribe
Cloudflare Internal DNS is now generally available, combining Gateway Resolver (recursive resolution) and Internal Authoritative DNS (private zone records) on Cloudflare's existing network. For Enterprise customers already on Cloudflare Gateway, it's included at no extra cost, supports split-horizon DNS without duplicating records, and propagates changes in seconds rather than waiting on TTLs. That's a real reason for those customers to reconsider a separate internal-DNS tool, but Cloudflare hasn't said whether Free, Pro, or Business plans get any access at all.
- Two components: Gateway Resolver for recursive lookups and Internal Authoritative DNS for private zone records
- No additional charge for Enterprise customers already on Cloudflare Gateway
- Split-horizon DNS via zone references, with global propagation in seconds instead of TTL waits
Keep reading for the full analysis.
Where this decision goes next
Skip the scroll: the pages most readers open after this one.
Serverless Monitoring Tools in 2026: AWS, Datadog, Lumigo, and New RelicRead the next related article.Cloudflare has taken its internal DNS product out of beta. Internal DNS is now generally available, running authoritative and recursive DNS resolution for private networks on the same global network and control plane customers already use for public DNS, Zero Trust, and application delivery. That's a narrow but genuine piece of news: for teams already writing a check for Cloudflare Gateway, it's one fewer piece of infrastructure to run, patch, and pay for separately.
What Cloudflare actually shipped
The product is built from two named components: Gateway Resolver, which handles recursive resolution and policy enforcement, and Internal Authoritative DNS, which serves the actual private zone records. Split that way, one half of Internal DNS answers "where do I send this query," and the other half answers "what's the record for this internal hostname" - a division that mirrors how most enterprise DNS deployments are already architected, just collapsed onto Cloudflare's infrastructure instead of a self-managed pair of resolvers and authoritative servers.
Why Gateway customers get a real reason to reconsider
The decision-relevant detail is cost. Cloudflare says Internal DNS is included with Cloudflare Gateway for Enterprise customers at no additional charge. If your organization is already paying for Gateway at that tier, running a separate internal-DNS or split-horizon-DNS product - Infoblox, BlueCat, a self-hosted BIND pair, or AWS Route 53 Resolver - starts to look like redundant spend on a capability you already own. That's not true for everyone: it only holds if Gateway Enterprise is already in your stack, and Cloudflare's post says nothing about whether Free, Pro, or Business customers get any version of this at all. Treat the "included at no cost" framing as an Enterprise-tier fact, not a platform-wide one, until Cloudflare documents otherwise.
The product also plugs into infrastructure most Zero Trust shops are already running. Cloudflare lists integrations with Gateway itself, the Cloudflare One Client (the rebranded WARP agent), Cloudflare's WAN offering, DNS over HTTPS and DNS over TLS, and 1.1.1.1 as a fallback for public resolution. None of that is new engineering for a Gateway customer - it's the same agent and the same policy surface, extended to cover internal hostnames instead of stopping at the perimeter. This follows a broader pattern in Cloudflare's 2026 roadmap of folding adjacent infrastructure into products teams already pay for, similar to how Cloudflare rolled out temporary preview accounts for AI agents into its existing Workers platform rather than shipping a standalone tool.
Setup, split-horizon DNS, and what's still open
Cloudflare frames setup as three steps: create an internal zone, establish a DNS view, and define resolver policies. The company says this supports split-horizon DNS - serving different answers to internal versus external queries for the same hostname - without duplicating records across zones, using zone references instead. That's the detail worth checking against your current setup if you're maintaining split-horizon manually today, since record duplication and drift between internal and external zone files is a common source of DNS incidents.
The other headline claim is propagation speed: changes propagate globally in seconds rather than waiting on TTL expiry. For teams used to budgeting minutes-to-hours for a DNS change to fully roll out across resolvers, that's a meaningful operational difference, though it's worth validating in your own environment rather than taking a vendor's seconds-not-minutes framing at face value on day one.
What's not in Cloudflare's announcement matters just as much as what is. There's no mention of pricing or availability for Free, Pro, or Business Gateway tiers, no migration tooling described for teams moving off Infoblox or BlueCat, and no detail on rate limits, query volume caps, or SLA terms for the authoritative side. Cloudflare's general DNS documentation covers the company's broader DNS product line, but as of this announcement it's not yet clear how deep the Internal DNS-specific docs go beyond the blog post itself. Teams evaluating the full cost picture of standardizing on Cloudflare - Gateway, WARP, WAN, and now internal DNS together - can cross-reference ToolPick's Cloudflare pricing breakdown for the platform-wide plan structure this sits inside.
Where to go from here
Two more angles on this decision before you go.
Amplitude Alternatives in 2026: What PostHog, Mixpanel, Heap, and GA4 Actually CostThe next closely related decision in this cluster.Send it to a teammate or save it for the next renewal check.
๐ฌ Get the Weekly SaaS Digest
New tool reviews, pricing-change alerts, and stack cost tips โ one email a week, one-click unsubscribe. No spam, no fake urgency.
Turn this article into a decision path
Every ToolPick article should lead to a second useful page: another article, a hub, or a calculator action.
Serverless Monitoring Tools in 2026: AWS, Datadog, Lumigo, and New RelicRead the next related article.