
<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:media="http://search.yahoo.com/mrss/">
    <channel>
        <title><![CDATA[ The Cloudflare Blog ]]></title>
        <description><![CDATA[ Get the latest news on how products at Cloudflare are built, technologies used, and join the teams helping to build a better Internet. ]]></description>
        <link>https://blog.cloudflare.com</link>
        <atom:link href="https://blog.cloudflare.com/" rel="self" type="application/rss+xml"/>
        <language>en-us</language>
        <image>
            <url>https://blog.cloudflare.com/favicon.png</url>
            <title>The Cloudflare Blog</title>
            <link>https://blog.cloudflare.com</link>
        </image>
        <lastBuildDate>Tue, 14 Apr 2026 16:27:40 GMT</lastBuildDate>
        <item>
            <title><![CDATA[How To Use 1.1.1.1 w/ WARP App And Cloudflare Gateway To Protect Your Phone From Security Threats]]></title>
            <link>https://blog.cloudflare.com/how-to-use-1-1-1-1-w-warp-app-and-cloudflare-gateway-to-protect-your-phone-from-security-threats/</link>
            <pubDate>Wed, 08 Apr 2020 11:00:00 GMT</pubDate>
            <description><![CDATA[ Starting today, you can get even more out of your 1.1.1.1 app. By adding Cloudflare Gateway’s secure DNS filtering to your 1.1.1.1 app, you can add a layer of security and block malicious domains flagged as phishing, command and control, or spam. ]]></description>
            <content:encoded><![CDATA[ <p><a href="https://teams.cloudflare.com/gateway/">Cloudflare Gateway</a> protects users and devices from security threats, starting with your local network. We are bringing that same level of security to your mobile devices with the 1.1.1.1 w/ WARP app. Wherever your devices connect, they can block the same types of threats that Gateway keeps off your home or office WiFi.</p><p>The 1.1.1.1 w/ WARP app has secured millions of mobile Internet connections. When installed, 1.1.1.1 w/ WARP encrypts the traffic leaving your device, giving you a more private browsing experience.</p><p>You can get even more out of your 1.1.1.1 w/ WARP. By adding Cloudflare Gateway’s secure DNS filtering to the app, you can add a layer of security and block malicious domains flagged as phishing, command and control, or spam. This protection isn’t dependent on what network you’re connected to - it follows you everywhere you go.</p><p>The feature is rolling out to both the iOS and Android clients this week. You do not need to install a different app; as the release is available, you will be able to upgrade your version and follow the steps below for a safer Internet on any network.</p>
    <div>
      <h3>Download the 1.1.1.1 w/ WARP mobile app</h3>
      <a href="#download-the-1-1-1-1-w-warp-mobile-app">
        
      </a>
    </div>
    <p>If you don’t have the latest version of the 1.1.1.1 w/ WARP app go to the <a href="https://itunes.apple.com/us/app/1-1-1-1-faster-internet/id1423538627">Apple App Store</a> or <a href="https://play.google.com/store/apps/details?id=com.cloudflare.onedotonedotonedotone">Google Play Store</a> to download the latest version.</p>
    <div>
      <h3>Sign up for Cloudflare Gateway</h3>
      <a href="#sign-up-for-cloudflare-gateway">
        
      </a>
    </div>
    <p><a href="https://dash.teams.cloudflare.com">Sign up for Cloudflare Gateway</a> by visiting the Cloudflare for Teams dashboard. You can use Cloudflare Gateway for free, all you need is a Cloudflare account to get started.</p>
    <div>
      <h2>Get the unique ID for your DNS over HTTPS hostname</h2>
      <a href="#get-the-unique-id-for-your-dns-over-https-hostname">
        
      </a>
    </div>
    <p>On your Cloudflare Gateway dashboard go to ‘Locations’.</p>
            <figure>
            
            <img src="https://cf-assets.www.cloudflare.com/zkvhlag99gkb/3zZk756TJxR3T3iGoRDydI/6521d7f24a255c8565eeea657c8da0cc/image5-3.png" />
            
            </figure><p>Click on the location listed on the locations page to expand the location item.</p>
            <figure>
            
            <img src="https://cf-assets.www.cloudflare.com/zkvhlag99gkb/7azaK8oi5EU2jLklOy0M6L/5bcc3e403cf301e6b53f01de3bdf5efe/image3-3.png" />
            
            </figure><p>Copy the unique 10 character subdomain from the DNS over HTTPS endpoint. This unique ID is case sensitive. Either note it down on a paper or keep this window open on your computer because you will need it when you setup Gateway inside your 1.1.1.1 w/ WARP app.</p>
    <div>
      <h3>Enabling Cloudflare Gateway for 1.1.1.1 w/ WARP app</h3>
      <a href="#enabling-cloudflare-gateway-for-1-1-1-1-w-warp-app">
        
      </a>
    </div>
    <p>After you open the 1.1.1.1 w/ WARP app, click on the menu button on the top right corner:</p>
            <figure>
            
            <img src="https://cf-assets.www.cloudflare.com/zkvhlag99gkb/1BE9N5QUm3gIfpNFGLo20u/421657eda702b7b86e8f530322b4e757/image2-6.png" />
            
            </figure><p>Click on 'Advanced' which is located under the 'Account' button.</p>
            <figure>
            
            <img src="https://cf-assets.www.cloudflare.com/zkvhlag99gkb/pgeF14ltvZyhUotWrbYlR/b7a3e42a91c6ae285a83a067b6e457ea/image4-6.png" />
            
            </figure><p>Click on 'Connection options' which is located at the bottom of the screen right above 'Diagnostics'.</p>
            <figure>
            
            <img src="https://cf-assets.www.cloudflare.com/zkvhlag99gkb/2DkGwLig3vWQQTZfi1S5Xo/b3d5af42c47f49f2fbb814046287efa9/image6-2.png" />
            
            </figure><p>Click on 'DNS Settings'. This will take you to the screen where you can configure Gateway for your 1.1.1.1 mobile app.</p>
            <figure>
            
            <img src="https://cf-assets.www.cloudflare.com/zkvhlag99gkb/32JTbf5meBPQnQQw4sz58W/f4579276ab1045c3c124ed30ddcb8284/image1-8.png" />
            
            </figure><p>When you are on this screen on your phone, you will need to enter the unique subdomain of the location you created for your mobile phone. This is the unique ID I asked you to note down in the previous section.</p>
            <figure>
            
            <img src="https://cf-assets.www.cloudflare.com/zkvhlag99gkb/1kFBLQZ39tKaZLxrTxot8e/7e774afbb5f821a29c8169ad55a79db4/image7-3.png" />
            
            </figure><p>Enter the subdomain inside the field <b>GATEWAY UNIQUE ID</b>.</p><p>If 1.1.1.1 DNS, WARP or WARP+ was already enabled, the 1.1.1.1 w/ WARP app should be using Gateway.</p><p>If you are using Android you can read about the setup instructions <a href="https://developers.cloudflare.com/gateway/locations/setup-instructions/android/">here</a>.</p><p>If you are trying to enable Gateway for your corporate mobile devices using an MDM, you can read the setup instructions <a href="https://developers.cloudflare.com/gateway/locations/setup-instructions/ios/mdm/">here</a>.</p><p>Now that you have Gateway setup inside your 1.1.1.1 w/ WARP app, it will enforce security policies that are tied to the location and analytics will show up on your dashboard.</p>
    <div>
      <h3>What’s next</h3>
      <a href="#whats-next">
        
      </a>
    </div>
    <p>We <a href="/announcing-the-beta-for-warp-for-macos-and-windows/">announced last week</a> the 1.1.1.1 w/ WARP beta for Windows and macOS. If you are interested in using Cloudflare Gateway on macOS or Windows you can sign up for the <a href="https://one.one.one.one/">beta here</a> and we will reach out to you as soon as they are available.</p><p>Our team will continue to enhance Cloudflare Gateway. If you want to secure corporate devices, data centers or offices from security threats, get started today by visiting the <a href="https://dash.teams.cloudflare.com">Cloudflare for Teams dashboard</a>.</p> ]]></content:encoded>
            <category><![CDATA[1.1.1.1]]></category>
            <category><![CDATA[WARP]]></category>
            <category><![CDATA[Cloudflare Gateway]]></category>
            <category><![CDATA[Security]]></category>
            <category><![CDATA[Mobile]]></category>
            <guid isPermaLink="false">1gvF7JIiDSbI6R95aOvqQE</guid>
            <dc:creator>Irtefa</dc:creator>
        </item>
        <item>
            <title><![CDATA[Using Cloudflare Gateway to Stay Productive (and turn off distractions) While Working Remotely]]></title>
            <link>https://blog.cloudflare.com/using-cloudflare-gateway-to-stay-productive-and-turn-off-distractions-while-working-remotely/</link>
            <pubDate>Thu, 19 Mar 2020 16:00:00 GMT</pubDate>
            <description><![CDATA[ This week, like most of you reading this article, I am working from home. I don’t know about you, but I’ve found it hard to stay focused when the Internet is full of news related to Coronavirus.  ]]></description>
            <content:encoded><![CDATA[ <p>This week, like many of you reading this article, I am working from home. I don’t know about you, but I’ve found it hard to stay focused when the Internet is full of news related to the coronavirus.</p><p>CNN. Twitter. Fox News. It doesn’t matter where you look, everyone is vying for your attention. It’s totally riveting…</p><p>… and it’s really hard not to get distracted.</p><p>It got me annoyed enough that I decided to do something about it. Using Cloudflare’s <a href="https://teams.cloudflare.com/gateway/index.html">new product, Cloudflare Gateway,</a> I removed all the online distractions I normally get snared by — at least during working hours.</p><p>This blog post isn’t very long, but that’s a function of how easy it is to get Gateway up and running!</p>
    <div>
      <h2>Getting Started</h2>
      <a href="#getting-started">
        
      </a>
    </div>
    <p>To get started, you’ll want to set up Gateway under your Cloudflare account. Head to the <a href="https://dash.teams.cloudflare.com">Cloudflare for Teams dashboard</a> to set it up for free (if you don’t already have a Cloudflare account, hit the ‘Sign up’ button beneath the login form).</p><p>If you are using Gateway for the first time, the dashboard will take you through an onboarding experience:</p>
            <figure>
            
            <img src="https://cf-assets.www.cloudflare.com/zkvhlag99gkb/lFkfxTeOS4EvgngLGsfYj/52c3788760f69a70386be4d202af7e9c/1.gif" />
            
            </figure><p>The onboarding flow will help you set up your first location. A location is usually a physical entity like your home, office, store or a data center.</p><p>When you are setting up your location, the dashboard will automatically identify your IP address and create a location using that IP. Gateway will associate requests from your router or device by matching requests with your location by using the linked IP address of your location (for an IPv4 network). If you are curious, you can read more about how Gateway determines your location <a href="https://developers.cloudflare.com/gateway/locations/match-query-to-location/">here</a>.</p><p>Before you complete the setup you will have to change your router’s DNS settings by removing the existing DNS resolvers and adding Cloudflare Gateway’s recursive DNS resolvers:</p><ul><li><p>172.64.36.1</p></li><li><p>172.64.36.2</p></li></ul><p>How you configure your DNS settings may vary by router or a device, so we <a href="https://developers.cloudflare.com/gateway/locations/setup-instructions/">created a page</a> to show you how to change DNS settings for different devices.</p><p>You can also watch this video to learn how to setup Gateway:</p>
    <div>
      <h2>Deep Work</h2>
      <a href="#deep-work">
        
      </a>
    </div>
    <p>Next up, in the dashboard, I am going to go to my policies and create a policy that will block my access to distracting sites. You can call your policy anything you want, but I am going to call mine “Deep work.”</p>
            <figure>
            
            <img src="https://cf-assets.www.cloudflare.com/zkvhlag99gkb/28c4V0EDP1aLZTLgD7chc8/5d484fd48dc619647c4f0de6e904c00b/2-1.png" />
            
            </figure><p>And I will add a few websites that I don’t want to get distracted by, like CNN, Fox News and Twitter.</p>
            <figure>
            
            <img src="https://cf-assets.www.cloudflare.com/zkvhlag99gkb/27zOQlDV1Rw5bPxMwKGFk0/219d2d689189ffcda7e4adf988392788/3-1.png" />
            
            </figure><p>After I add the domains, I hit Save.</p><p>If you find the prospect of blocking all of these websites cumbersome, you can use category-based DNS filtering to block all domains that are associated with a category (‘Content categories’ have limited capabilities on Gateway’s free tier).</p>
            <figure>
            
            <img src="https://cf-assets.www.cloudflare.com/zkvhlag99gkb/7pUCaw8tWwVF7a90HLHgxt/4fb11fef3d278dac1633694d290a2f95/4-1.png" />
            
            </figure><p>So if I select Sports, all websites that are related to Sports will now be blocked by Gateway. This will take most people a few minutes to complete.</p><p>And once you set the rules by hitting ‘Save’, it will take just seconds for the selected policies to propagate across all of Cloudflare’s data centers, spread across more than 200 cities around the world.</p>
    <div>
      <h2>How can I test if Gateway is blocking the websites?</h2>
      <a href="#how-can-i-test-if-gateway-is-blocking-the-websites">
        
      </a>
    </div>
    <p>If you now try to go to one of the blocked websites, you will see the following page on your browser:</p>
            <figure>
            
            <img src="https://cf-assets.www.cloudflare.com/zkvhlag99gkb/41ohJ8ViJNlpQnSg0U2lui/31a1be3bb2144ba19ec0bd040fc20563/5.png" />
            
            </figure><p>Cloudflare Gateway is letting your browser know that the website you blocked is unreachable. You can also test if Gateway is working by using dig or nslookup on your machine:</p>
            <figure>
            
            <img src="https://cf-assets.www.cloudflare.com/zkvhlag99gkb/1sncQ9FhDKMtHuta8Se20H/f8ad20a29702a3e2aeee1faf059667ae/6.png" />
            
            </figure><p>If a domain is blocked, you will see the following in the DNS response <code>status: **REFUSED.**</code></p><p>This means that the policy you created is working!</p><p>And once working hours are over, it’s back to being glued to the latest news.</p><p>If you’d rather watch this in video format, here’s one I recorded earlier:</p><p>And to everyone dealing with the challenges of COVID-19 and working from home — stay safe!</p> ]]></content:encoded>
            <category><![CDATA[Cloudflare Gateway]]></category>
            <category><![CDATA[Cloudflare Zero Trust]]></category>
            <category><![CDATA[Security]]></category>
            <guid isPermaLink="false">7uTyIuF0IiIKQ21AEn01Oc</guid>
            <dc:creator>Irtefa</dc:creator>
        </item>
        <item>
            <title><![CDATA[Protect your team with Cloudflare Gateway]]></title>
            <link>https://blog.cloudflare.com/protect-your-team-with-cloudflare-gateway/</link>
            <pubDate>Thu, 12 Mar 2020 12:00:00 GMT</pubDate>
            <description><![CDATA[ Announcing Cloudflare for Teams, a new way to protect organizations and their employees, without sacrificing performance. Cloudflare for Teams centers around Cloudflare Access and Cloudflare Gateway. ]]></description>
            <content:encoded><![CDATA[ <p>On January 7th, we <a href="https://www.cloudflare.com/press-releases/2020/cloudflare-enters-new-security-market-launches-cloudflare-for-teams-to-make/">announced</a> Cloudflare for Teams, a new way to protect organizations and their employees globally, without sacrificing performance. Cloudflare for Teams centers around two core products - Cloudflare Access and Cloudflare Gateway. Cloudflare Access is already available and used by thousands of teams around the world to <a href="https://www.cloudflare.com/application-services/solutions/">secure internal applications</a>. Cloudflare Gateway solves the other end of the problem by <a href="https://www.cloudflare.com/products/zero-trust/threat-defense/">protecting those teams from security threats</a> without sacrificing performance.</p><p>Today, we’re excited to announce new secure DNS filtering capabilities in Cloudflare Gateway. Cloudflare Gateway protects teams from threats like malware, phishing, ransomware, crypto-mining and other security threats. You can start using Cloudflare Gateway at <a href="https://dash.teams.cloudflare.com">dash.teams.cloudflare.com</a>. Getting started takes less than five minutes.</p>
    <div>
      <h2>Why Cloudflare Gateway?</h2>
      <a href="#why-cloudflare-gateway">
        
      </a>
    </div>
    <p>We built Cloudflare Gateway to address key challenges our customers experience with <a href="https://www.cloudflare.com/network-security/">managing and securing global networks</a>. The root cause of these challenges is architecture and inability to scale. Legacy network security models solved problems in the 1990s, but teams have continued to attempt to force the Internet of the 2020s through them.</p><p>Historically, branch offices sent all of their Internet-bound traffic to one centralized data center at or  near corporate headquarters. Administrators configured that to make sure all requests passed through a secure hardware firewall. The hardware firewall observed each request, performed inline SSL inspection, applied DNS filtering and made sure that the corporate network was safe from security threats. This solution worked when employees accessed business critical applications from the office, and when applications were not on the cloud.</p>
            <figure>
            
            <img src="https://cf-assets.www.cloudflare.com/zkvhlag99gkb/4HCYjlo96gO2l25olEdxHW/27e9d2eb5af5c72beb8b1f0dd8750ccb/image1-4.png" />
            
            </figure><p>Average SaaS spending per company since 2008 (<a href="https://www.blissfully.com/saas-trends/2019-annual/">source</a>)</p><p>SaaS broke this model when cloud-delivered applications became the new normal for workforce applications. As business critical applications moved to the cloud, the number of Internet bound requests from all the offices went up. Costs went up, too. In the last 10 years, SaaS spending across all company size segments  grew by more than <b>1615%</b>. The legacy model of backhauling all Internet traffic through centralized locations could not keep up with the digital transformation that all businesses are still going through.</p>
            <figure>
            
            <img src="https://cf-assets.www.cloudflare.com/zkvhlag99gkb/6lym9DYYf2dNZIpWJpsgcR/314594f4b1424db2402393a447eb6bcf/image6-2.png" />
            
            </figure>
    <div>
      <h2>The challenge of backhauling traffic for a global workforce</h2>
      <a href="#the-challenge-of-backhauling-traffic-for-a-global-workforce">
        
      </a>
    </div>
    
    <div>
      <h3>Expensive and slow</h3>
      <a href="#expensive-and-slow">
        
      </a>
    </div>
    <p>SaaS adoption is only one element that is breaking traditional network models. Geographically distributed offices and <a href="https://www.cloudflare.com/products/zero-trust/remote-workforces/">remote workers</a> are playing a role, too.</p><p>Cloudflare Gateway has been in beta use for some of our customers over the last few months. One of those customers had more than 50 branch offices, and sent all of their <a href="https://www.cloudflare.com/learning/dns/what-is-dns/">DNS traffic</a> through one location. The customer’s headquarters is in New York, but they have offices all over the world, including in India. When someone from the office in India visits google.com, DNS requests travel all the way to New York.</p><p>As a result, employees in India have a terrible experience using the Internet. The legacy approach to solve this problem is to add <a href="https://www.cloudflare.com/learning/network-layer/what-is-mpls/">MPLS links</a> from branch offices to the headquarters. But MPLS links are expensive, and can take a long time to configure and deploy. Businesses end up spending millions of dollars on legacy solutions, or they remain slow, driving down employee productivity.</p>
            <figure>
            
            <img src="https://cf-assets.www.cloudflare.com/zkvhlag99gkb/56KduMw759bHJUBPwCyZ6s/9db7a5d611250754b65b8d7f3c69b414/image2-6.png" />
            
            </figure>
    <div>
      <h3>Slow to react to security threats</h3>
      <a href="#slow-to-react-to-security-threats">
        
      </a>
    </div>
    <p>When businesses backhaul traffic to a single location to inspect and filter malicious traffic using a hardware firewall. But, the legacy hardware appliances were not built for the modern Internet. The threat landscape for the Internet is constantly changing.</p><p>For example: about 84% of phishing sites exist for less than 24 hours (<a href="https://www.infosecurity-magazine.com/news/84-of-phishing-sites-last-for-less/">source</a>) and legacy hardware firewalls are not fast enough to update their static rules to thwart phishing attacks. When security threats on the Internet act like moving targets, legacy hardware appliances that rely on static models to filter malicious traffic cannot keep up. As a result, employees remain <a href="https://www.cloudflare.com/learning/email-security/what-is-email-fraud/">vulnerable to new threats</a> even when businesses backhaul Internet bound traffic to a single location.</p>
    <div>
      <h3>Cloudflare Gateway</h3>
      <a href="#cloudflare-gateway">
        
      </a>
    </div>
    <p>Starting today, businesses of all sizes can secure all their Internet-bound traffic and make it faster with  Cloudflare Gateway. Cloudflare has data centers in more than 200 cities around the world and all of our services run in every single data center. Therefore, when a business uses Cloudflare Gateway, instead of backhauling traffic to a single location (slow), all Internet-bound requests <a href="https://www.cloudflare.com/learning/network-layer/what-is-branch-networking/">travel to the nearest data center</a> (fast) from the end user where Cloudflare Gateway applies security policies to protect businesses from security threats. All of this is done without the need for expensive MPLS links.</p>
            <figure>
            
            <img src="https://cf-assets.www.cloudflare.com/zkvhlag99gkb/U5JtESBJQiFZTjvZ2hPYj/489b75a170e8b32a05c33db7bcb59eb3/image7-2.png" />
            
            </figure><p>(<a href="https://www.dnsperf.com/#!dns-resolvers">Source</a>)</p><p>Gateway’s secure DNS filtering capabilities are built on top of 1.1.1.1, the fastest public DNS resolver in the world. We took the pieces that made the 1.1.1.1 public DNS resolver the fastest and built Cloudflare Gateway’s secure DNS filtering capabilities for customers who want to secure their connection to the Internet. Combined with Cloudflare’s global presence of data centers in more than 200 cities and the fastest public DNS resolver in the world, Cloudflare Gateway secures every connection from every device to every destination on the Internet without sacrificing performance.</p>
            <figure>
            
            <img src="https://cf-assets.www.cloudflare.com/zkvhlag99gkb/797aIlRBWUhiHnPOCZfUn5/443da29928a16a64545c3762d707ae6a/image11-1.png" />
            
            </figure>
    <div>
      <h2>Why Secure DNS Filtering?</h2>
      <a href="#why-secure-dns-filtering">
        
      </a>
    </div>
    <p>More than <a href="https://www.infosecurity-magazine.com/webinars/dns-based-attacks-1-1-1-1-1-1-1/">90%</a> of malware use DNS to perform command &amp; control attacks and exfiltrate sensitive data. Here’s an example of how a malware can infect a device or a data center and perform a command &amp; control (also known as C2C or C&amp;C) attack:</p>
            <figure>
            
            <img src="https://cf-assets.www.cloudflare.com/zkvhlag99gkb/4i4Gyr9P2k9duO8L3npuDI/2c25bc76915eebf2434b71a7aec0d24a/Screen-Shot-2020-03-16-at-5.55.30-PM.png" />
            
            </figure><ol><li><p>Imagine Bob receives an email from someone impersonating his manager with a link to ‘Box’ that looks harmless. The email looks legitimate but in reality it is a phishing email intended to steal valuable information from Bob’s computer or infected with malware.</p></li><li><p>When Bob clicks on the link, the website phishing ‘Box’ delivers an exploit and installs malware onto Bob’s computer.</p></li><li><p>The downloaded malware sends a request to the Command &amp; Control server signaling that the malware is ready to receive instructions from the server.</p></li><li><p>Once the connection between the malware and Command &amp; Control server is established, the server sends instructions to the malware to steal proprietary data, control the state of the machine to reboot it, shut it down or perform DDoS attacks against other websites.</p></li></ol><p>If Bob’s computer was using DNS filtering, it could have prevented the attack in two places.</p><p>First, when Bob clicked on the phishing link (2). The browser sends a DNS request to resolve the domain of the phishing link. If that domain was identified by DNS filtering as a phishing domain, it would have blocked it right away.</p><p>Second, when malware initiated the connection with the Command &amp; Control server, the malware also needed to make a DNS request to learn about the Command &amp; Control server’s IP address. This is another place where a secure DNS filtering service can detect the domain as malware and block access to it.</p><p>Secure DNS filtering acts as the first layer of defence against most security threats and prevents corporate networks and devices from getting infected by malicious software in the first place. According to a <a href="https://www.darkreading.com/network-and-perimeter-security/dns-firewalls-could-save-companies-billions/d/d-id/1334965">security report</a> by Global Cyber Alliance, companies could have prevented losses of more than <b>$200B</b> using DNS filtering.</p>
    <div>
      <h2>How does Gateway’s secure DNS filtering work?</h2>
      <a href="#how-does-gateways-secure-dns-filtering-work">
        
      </a>
    </div>
    <p>The primary difference between the 1.1.1.1 public DNS resolver and Gateway’s secure DNS filtering is that the 1.1.1.1 public DNS resolver does not block any DNS queries. When a browser requests <a href="http://example.com">example.com</a>, the 1.1.1.1 public DNS resolver simply looks up the answer for the DNS query either in cache or by performing a full recursive query.</p><p>Cloudflare Gateway adds one new step to introduce security into this flow. Instead of allowing all DNS queries, Gateway first checks the name being queried against the intelligence Cloudflare has about threats on the Internet. If that query matches a known threat, or is requesting a blocked category, Gateway stops it before the site could load for the user - and potentially execute code or phish that team member.</p>
            <figure>
            
            <img src="https://cf-assets.www.cloudflare.com/zkvhlag99gkb/33cp6n2YSAmbzPtm5H8KVs/bbaec33a18697c7d3df1d658e0deb556/image10-1.png" />
            
            </figure><p>For example, if a customer is using Cloudflare Gateway, and sends a DNS query to <a href="http://example.com">example.com</a>, first, Gateway checks if the DNS query is coming from a customer. Second, if it is coming from a customer Gateway checks if the DNS query matches with any of the policies setup by the customer. The policy could be a domain that the customer is manually blocking or it could be part of a broader security category that the customer enabled. If the domain matches one of those cases, Cloudflare Gateway will block access to the domain. This will prevent the end user from going to example.com.</p>
    <div>
      <h2>Encrypted DNS from day one</h2>
      <a href="#encrypted-dns-from-day-one">
        
      </a>
    </div>
    <p>Gateway supports DNS over HTTPS today and will also support DNS over TLS in the future. You can use <a href="https://developers.cloudflare.com/gateway/locations/setup-instructions/firefox/">Firefox</a> to start sending DNS queries to Gateway in an encrypted fashion. It will also support other DNS over HTTPS clients as long as you can change the hostname in your preferred DNS over HTTPS client.</p><p>Here’s how DNS over HTTPS for Cloudflare Gateway works:</p>
            <figure>
            
            <img src="https://cf-assets.www.cloudflare.com/zkvhlag99gkb/27FR8rI0RVKTGAATu6lOBn/9d321a6af617de0b6141d140845cae98/image5-4.png" />
            
            </figure><p>The DNS over HTTPS client encrypts the DNS request and sends it to the closest Cloudflare’s data center. Upon receiving the encrypted DNS request, it will decrypt it and send it to Cloudflare Gateway. Cloudflare Gateway will apply the required security policies and return the response to our edge. Our edge will encrypt the response and send it back to the DNS over HTTPS client.</p><p>By encrypting your DNS queries you will make sure that ISPs cannot snoop on your DNS queries and at the same time filter DNS requests that are malicious.</p>
    <div>
      <h2>Cloudflare Gateway is for everyone</h2>
      <a href="#cloudflare-gateway-is-for-everyone">
        
      </a>
    </div>
    <p>One of our customers, Algolia, is a fast growing startup. Algolia grew by 1005% in 2019 (<a href="https://www.globenewswire.com/news-release/2019/11/07/1943413/0/en/Algolia-Ranked-Number-125-Fastest-Growing-Company-in-North-America-on-Deloitte-s-2019-Technology-Fast-500.html">source</a>). As the company experienced rapid growth, Cloudflare Gateway helped maintain their corporate security without slowing them down:</p><blockquote><p>“<i>Algolia is growing pretty fast. At Algolia, we needed a way to have visibility across our corporate network without slowing things down for our employees. Cloudflare Gateway gave us a simple way to do that</i>”<b>Adam Surak</b> (Director of Infrastructure &amp; Security Algolia)</p></blockquote><p>But Gateway isn’t just for fast growing startups. Anyone with a Cloudflare account can start using Cloudflare Gateway today. Gateway has a free tier where we wanted to make sure even <a href="https://www.cloudflare.com/small-business/">small businesses</a>, teams and <a href="https://www.cloudflare.com/personal/">households</a> who cannot afford expensive security solutions can use Cloudflare Gateway to protect themselves from security threats on the Internet. We offer a free plan to our customers because we have a paid tier for this product with additional functionality that are more suited towards super users. Features like longer data retention for analytics, more granular security and content categories, individual DNS query logs, logpush to a cloud storage bucket etc. are features that are only available to our paid customers. You can learn more about Gateway in our <a href="https://teams.cloudflare.com/gateway/">product page</a>.</p>
    <div>
      <h2>How can you get started?</h2>
      <a href="#how-can-you-get-started">
        
      </a>
    </div>
    <p>If you already have a Cloudflare account get started by visiting the <a href="https://dash.teams.cloudflare.com/">Teams dashboard</a>.</p><p>The onboarding will walk you through how to configure your router, or device to send DNS queries to Gateway. The onboarding will help you setup a location. A location is usually a physical entity like your office, retail location, data center or home.</p>
            <figure>
            
            <img src="https://cf-assets.www.cloudflare.com/zkvhlag99gkb/1m7XdgcUqe68OSTB9SkxLz/c6f2126d0a4493a1b712e0b084034cfc/image9.gif" />
            
            </figure><p>Once you finish onboarding, start by configuring a policy. A policy will allow you to block access to malicious websites when anyone is using the Internet from the location that you just created.</p>
            <figure>
            
            <img src="https://cf-assets.www.cloudflare.com/zkvhlag99gkb/63HlO6ByuEvlRwfSRm1AGd/dfca2f85e8f807295b34b23b6587b5c8/image4.gif" />
            
            </figure><p>You can choose from the categories of policy that we have created. You can also manually add a domain to block it using Gateway.</p>
            <figure>
            
            <img src="https://cf-assets.www.cloudflare.com/zkvhlag99gkb/2Jim8l3kK9S8aWVYwgzEZi/3b57abf523c3e7c1014d09f751d54ce0/image3-4.png" />
            
            </figure><p>Once you start sending DNS queries to Gateway, you will see analytics on the team's dashboard. The analytics dashboard will help you understand if there are any anomalies in your network.</p>
    <div>
      <h3>What’s next</h3>
      <a href="#whats-next">
        
      </a>
    </div>
    <p>Cloudflare's mission is to help create a better Internet. We have achieved this by protecting millions of websites around the world and securing millions of devices using WARP. With Cloudflare Access, we helped secure and protect internal applications. Today, with Cloudflare Gateway’s secure DNS filtering capabilities we have extended our mission to also protect the people who use the Internet every day. The product you are seeing today is a glimpse of what we are building for the future. Our team is incredibly proud of what we have built and we are just getting started.</p> ]]></content:encoded>
            <category><![CDATA[Cloudflare Zero Trust]]></category>
            <category><![CDATA[Cloudflare Gateway]]></category>
            <category><![CDATA[Security]]></category>
            <category><![CDATA[Product News]]></category>
            <category><![CDATA[DNS]]></category>
            <category><![CDATA[Resolver]]></category>
            <category><![CDATA[1.1.1.1]]></category>
            <guid isPermaLink="false">7nmm4XKti6UeqrWISOn3ds</guid>
            <dc:creator>Irtefa</dc:creator>
        </item>
        <item>
            <title><![CDATA[Encrypting DNS end-to-end]]></title>
            <link>https://blog.cloudflare.com/encrypting-dns-end-to-end/</link>
            <pubDate>Fri, 21 Dec 2018 16:00:59 GMT</pubDate>
            <description><![CDATA[ Over the past few months, we have been running a pilot with Facebook to test the feasibility of securing the connection between 1.1.1.1 and Facebook’s authoritative name servers.  ]]></description>
            <content:encoded><![CDATA[ <p>Over the past few months, we have been <a href="https://code.fb.com/security/dns-over-tls/">running a pilot with Facebook</a> to test the feasibility of securing the connection between 1.1.1.1 and Facebook’s authoritative name servers. Traditionally, the connection between a resolver and an authoritative name server is unencrypted i.e. over UDP.</p>
            <figure>
            
            <img src="https://cf-assets.www.cloudflare.com/zkvhlag99gkb/2Aw0fH5ga1YAaBhsEsiRYP/76eee714955f8ec94c38de7e8b19893a/Code-Blog-Pilot-Post-1.png" />
            
            </figure><p>In this pilot we tested how an encrypted connection using TLS impacts the end-to-end latency between 1.1.1.1 and Facebook’s authoritative name servers. Even though the initial connection adds some latency, the overhead is amortized over many queries. The resulting DNS latency between 1.1.1.1 and Facebook’s authoritative name servers is on par with the average UDP connections.</p><p>To learn more about how the pilot went, and to see more detailed results, check out the <a href="https://code.fb.com/security/dns-over-tls/">complete breakdown over on Code, Facebook's Engineering blog</a>.</p> ]]></content:encoded>
            <category><![CDATA[1.1.1.1]]></category>
            <category><![CDATA[DNS]]></category>
            <category><![CDATA[Resolver]]></category>
            <category><![CDATA[Speed & Reliability]]></category>
            <category><![CDATA[TLS]]></category>
            <guid isPermaLink="false">79Uh3HuEtL51HnXPZBT4Ef</guid>
            <dc:creator>Irtefa</dc:creator>
        </item>
        <item>
            <title><![CDATA[1 Thing You Can Do To Make Your Internet Safer And Faster]]></title>
            <link>https://blog.cloudflare.com/1-thing-you-can-do-to-make-your-internet-safer-and-faster/</link>
            <pubDate>Sun, 11 Nov 2018 13:00:00 GMT</pubDate>
            <description><![CDATA[ On April 1st, 2018, we announced 1.1.1.1, the fastest public DNS resolver in the world. Today, we are launching the 1.1.1.1 mobile app to make it incredibly easy to use 1.1.1.1 on your phone. ]]></description>
            <content:encoded><![CDATA[ <p></p><p>On April 1st, 2018, we announced <a href="/announcing-1111/">1.1.1.1</a>, the fastest public DNS resolver in the world ???. Today, we are launching the 1.1.1.1 mobile app to make it incredibly easy to use 1.1.1.1 on your phone.</p>
    <div>
      <h3>TL;DR</h3>
      <a href="#tl-dr">
        
      </a>
    </div>
    <p>Any time you are on a public internet connection people can see what sites you visit. Even worse, your Internet Service Provider is very possibly selling all of your browsing history to the highest bidder. We have a tool called 1.1.1.1 which makes it easy to get a faster, more private, Internet experience, but it’s historically been too complex for many people to use, particularly on mobile devices. Today, we’re launching an app you (and everyone you know) can use to use 1.1.1.1 every time your mobile phone connects to the Internet. It’s a free, it’s easy, download it now.</p>
            <figure>
            
            <img src="https://cf-assets.www.cloudflare.com/zkvhlag99gkb/6mDDCWpzXKLTIzY4JfSncM/91df9a707705b2671710f51676fb8963/1.1.1.1-Screen-Record.gif" />
            
            </figure><div>
<a href="https://play.google.com/store/apps/details?id=com.cloudflare.onedotonedotonedotone">

</a>
<a href="https://itunes.apple.com/us/app/1-1-1-1-faster-internet/id1423538627?mt=8">
</a>
</div>
    <div>
      <h3>Fastest Public Resolver</h3>
      <a href="#fastest-public-resolver">
        
      </a>
    </div>
    
            <figure>
            
            <img src="https://cf-assets.www.cloudflare.com/zkvhlag99gkb/6YrDCxkfXtonK0ecAVKEsB/f63d7e6213b1a8f6da3df29714047e1f/DNS-Perf.png" />
            
            </figure><p><a href="https://www.dnsperf.com/#!dns-resolvers">DNSPerf</a> data</p><p>We launched 1.1.1.1 on April 1st. Frankly, we’ve been blown away by how many people actually made the switch. Changing your network settings is not easy, but if our traffic amount is any indication, many of you made the effort. Thank you!</p><p>That said, even more people are not able to make those changes, particularly on mobile devices. We want everyone to have access to faster and more private Internet, and the millions of sites on Cloudflare value the performance boost they get when visited by 1.1.1.1 users.</p><p>A month ago, we <a href="https://twitter.com/1111Resolver/status/1049785508342030336">announced</a> the public beta of a new, easier, way to install 1.1.1.1, a mobile app.</p>
    <div>
      <h3>What did we learn from the beta?</h3>
      <a href="#what-did-we-learn-from-the-beta">
        
      </a>
    </div>
    <p>We learned a lesson it seems we discover again with every product we launch: our beta customers are incredible! They discovered bugs and configuration issues, not just with the app but also with mobile carriers.</p><p>Particularly given its role as the first app we will release on any mobile app store, we were energized (and shocked) by the excitement we received. We saw what we always hoped for, a faster Internet, all around the world:</p><blockquote><p>Damn <a href="https://twitter.com/Cloudflare?ref_src=twsrc%5Etfw">@Cloudflare</a> your 1.1.1.1 app is incredible. Things that normally takes 5 to 7 seconds to load in Vietnam are taking 3.</p><p>— Chris Walton (@ChrisWalton10) <a href="https://twitter.com/ChrisWalton10/status/1058040496528928769?ref_src=twsrc%5Etfw">November 1, 2018</a></p></blockquote><p>Our heartfelt thanks to every user who showed us ❤️and helped us make 1.1.1.1 available to the world.</p>
    <div>
      <h3>1 App, Free for Everyone</h3>
      <a href="#1-app-free-for-everyone">
        
      </a>
    </div>
    <p>The 1.1.1.1. app makes your Internet faster and more private. It is darn easy to set up. And, the best part: it’s free!</p><p>It is the right thing to do. We are making it easier for everyone to make their experience when they use the Internet more private. People should not have to pay to have a more private Internet.</p><p>Beyond that, millions of websites rely on Cloudflare for performance and security. By getting more users on 1.1.1.1, we make those sites faster. That makes Cloudflare better, and it makes the <a href="https://blog.cloudflare.com/50-years-of-the-internet-work-in-progress-to-a-better-internet/">Internet better</a>, a win-win.</p><p>Download today to have a safer and faster Internet ✌️✌️.</p><div>
<a href="https://play.google.com/store/apps/details?id=com.cloudflare.onedotonedotonedotone">

</a>
<a href="https://itunes.apple.com/us/app/1-1-1-1-faster-internet/id1423538627?mt=8">
</a>
</div><p></p> ]]></content:encoded>
            <category><![CDATA[1.1.1.1]]></category>
            <category><![CDATA[Resolver]]></category>
            <category><![CDATA[DNS]]></category>
            <category><![CDATA[Privacy]]></category>
            <category><![CDATA[Product News]]></category>
            <category><![CDATA[Mobile]]></category>
            <category><![CDATA[Speed & Reliability]]></category>
            <guid isPermaLink="false">5ZF7Rob2S6AnDhgQCwJQ6K</guid>
            <dc:creator>Irtefa</dc:creator>
        </item>
        <item>
            <title><![CDATA[Refresh Stale DNS Records on 1.1.1.1]]></title>
            <link>https://blog.cloudflare.com/refresh-stale-dns-records-on-1-1-1-1/</link>
            <pubDate>Tue, 21 Aug 2018 21:58:00 GMT</pubDate>
            <description><![CDATA[ You can now refresh 1.1.1.1’s DNS cache for domain names by using the purge cache tool. This is useful for domain owners who have updated their DNS records and want to make sure it is reflected for people who are using 1.1.1.1 as their public DNS resolver. ]]></description>
            <content:encoded><![CDATA[ <p>You can now refresh <a href="https://1.1.1.1">1.1.1.1</a>’s DNS cache for domain names by using the <a href="https://cloudflare-dns.com/purge-cache/">purge cache tool</a>. This is useful for domain owners who have just updated their DNS records and want to make sure it is reflected for everyone using 1.1.1.1 as their public DNS resolver.</p>
            <figure>
            
            <img src="https://cf-assets.www.cloudflare.com/zkvhlag99gkb/5BBLdPQGUZg5MmY9Hja51A/2784505a54f4dbaff3d8928ab07073ea/image2-3.png" />
            
            </figure><p></p>
            <figure>
            
            <img src="https://cf-assets.www.cloudflare.com/zkvhlag99gkb/7A5t7Y9XCv4EpC0kEKilbk/63d938fe9cf5953769324c5e37061c56/image1-2.png" />
            
            </figure><p>When a client queries for a domain against 1.1.1.1, the resolver returns the IP address from its cache.1.1.1.1 caches DNS entries for up to 3 hours, if the specified record has TTL that is shorter than 3 hours, the resolver respects that. This means, when a domain owner changes the DNS host from one to another, in the worst case, she will have to wait for at least 3 hours before the old IP address expires from 1.1.1.1’s cache. With the help of the purge cache tool, a domain owner can now easily refresh 1.1.1.1’s DNS cache and will not have to wait for the cached entry to expire.</p><p>To purge a DNS record, you enter the name of your domain, pick the DNS record type and hit the ‘Purge Cache’ button.</p>
            <figure>
            
            <img src="https://cf-assets.www.cloudflare.com/zkvhlag99gkb/3KDbqBxGKRUZWAsupqHMeh/5203f70e55a2ad9270a21bdb937a6269/image3-2.gif" />
            
            </figure><p>You can pick from one of the following DNS records: A, AAAA, CNAME, DNSKEY, DS, MX, NAPTR, NS, PTR, SPF, SRV, SSHFP, TLSA, and TXT. Once you hit the purge button it takes a few seconds to propagate the cache purge to all of Cloudflare’s data centers.</p><p>Check out the <a href="https://cloudflare-dns.com/purge-cache/">purge cache tool</a> here and let us know what you think in the comments!</p> ]]></content:encoded>
            <category><![CDATA[Resolver]]></category>
            <category><![CDATA[1.1.1.1]]></category>
            <category><![CDATA[DNS]]></category>
            <category><![CDATA[Cache]]></category>
            <category><![CDATA[Product News]]></category>
            <guid isPermaLink="false">1xjyf60aDja3LXvO0iw7mV</guid>
            <dc:creator>Irtefa</dc:creator>
        </item>
        <item>
            <title><![CDATA[Cloudflare Workers is now on Open Beta]]></title>
            <link>https://blog.cloudflare.com/cloudflare-workers-is-now-on-open-beta/</link>
            <pubDate>Thu, 01 Feb 2018 17:00:00 GMT</pubDate>
            <description><![CDATA[ Cloudflare Workers Beta is now open!

Cloudflare Workers lets you run JavaScript on Cloudflare’s edge, deploying globally to over 120+ data centers around the world in less than 30 seconds. Your code can intercept and modify any request made to your website. ]]></description>
            <content:encoded><![CDATA[ <p>Cloudflare Workers Beta is now open!</p><p><a href="/introducing-cloudflare-workers/">Cloudflare Workers</a> lets you run JavaScript on Cloudflare’s edge, deploying globally to over 120+ data centers around the world in less than 30 seconds. Your code can intercept and modify any request made to your website, make outbound requests to any URL on the Internet, and replace much of what you might need to configure your CDN to do today. Even better, it will do this from all our edge locations around the world, closer to many of your users than your origin servers can ever be. You will have a fully functional Turing-complete language in your fingertips which will allow you to build powerful applications on the edge. The only limit is your imagination.</p>
            <figure>
            
            <img src="https://cf-assets.www.cloudflare.com/zkvhlag99gkb/6AaPlK00VtBiP9qpWLzvXm/1359c7153f10c4cc8cb355aef8cec143/Screenshot-2018-02-01-09.20.49_preview.png" />
            
            </figure><p>To get started:</p><ul><li><p>Sign in to your account on <a href="https://cloudflare.com/">cloudflare.com</a>.</p></li><li><p>Visit the Workers tab.</p></li><li><p>Launch the editor.</p></li><li><p>Write <a href="https://developers.cloudflare.com/workers/">some code</a> and save it.</p></li><li><p>Go to the routes tab and prescribe on what requests you want to run Workers for</p></li></ul><p>That’s it!</p><p>You can start by writing a simple <a href="https://developers.cloudflare.com/workers/writing-workers/">‘hello world’</a> script, but chances are that you are going write Workers that are more complicated. You can check out our page with recipes to:</p><ul><li><p><a href="https://developers.cloudflare.com/workers/recipes/a-b-testing/">Run A/B tests on the edge</a></p></li><li><p><a href="https://developers.cloudflare.com/workers/recipes/conditional-routing/">Perform conditional routing on the edge</a></p></li><li><p><a href="https://developers.cloudflare.com/workers/recipes/return-403/">Filter requests based on headers/IP address/URL parameters</a></p></li><li><p><a href="https://developers.cloudflare.com/workers/recipes/aggregating-multiple-requests/">Aggregate responses from multiple endpoints and send it back to the client</a></p></li><li><p><a href="https://developers.cloudflare.com/workers/recipes/hotlink-protection/">Protect your assets against hot-linking</a></p></li></ul><p>We will keep adding new recipes to our <a href="https://developers.cloudflare.com/workers/">docs</a>. All the recipes are in a <a href="https://github.com/cloudflare/worker-examples">Github repository</a>; if you'd like to add your own, send us a pull request.</p><p>Check out the <a href="https://community.cloudflare.com/tags/workers">Workers Community</a> to see what other people are building. Please share your feedback and questions!</p><p>Cloudflare Workers is completely free during the open beta. We do intend on charging for Workers, but we will notify you of our plans at least thirty days before any changes are made.</p> ]]></content:encoded>
            <category><![CDATA[Product News]]></category>
            <category><![CDATA[Beta]]></category>
            <category><![CDATA[Developers]]></category>
            <category><![CDATA[Serverless]]></category>
            <category><![CDATA[Cloudflare Workers]]></category>
            <category><![CDATA[JavaScript]]></category>
            <category><![CDATA[Developer Platform]]></category>
            <guid isPermaLink="false">5GaYWUU2oc9ua5FKW0Z9Bd</guid>
            <dc:creator>Irtefa</dc:creator>
        </item>
    </channel>
</rss>