You can now route private traffic to Cloudflare Tunnel based on a hostname or domain, moving beyond the limitations of IP-based routing. This new capability is free for all Cloudflare One customers.
Previously, Tunnel routes could only be defined by IP address or CIDR range. This created a challenge for modern applications with dynamic or ephemeral IP addresses, often forcing administrators to maintain complex and brittle IP lists.
What’s new:
- Hostname & Domain Routing: Create routes for individual hostnames (e.g.,
payroll.acme.local) or entire domains (e.g.,*.acme.local) and direct their traffic to a specific Tunnel. - Simplified Zero Trust Policies: Build resilient policies in Cloudflare Access and Gateway using stable hostnames, making it dramatically easier to apply per-resource authorization for your private applications.
- Precise Egress Control: Route traffic for public hostnames (e.g.,
bank.example.com) through a specific Tunnel to enforce a dedicated source IP, solving the IP allowlist problem for third-party services. - No More IP Lists: This feature makes the workaround of maintaining dynamic IP Lists for Tunnel connections obsolete.
Get started in the Tunnels section of the Zero Trust dashboard with your first private hostname or public hostname route.
Learn more in our blog post.
Source: Cloudflare
Latest Posts
- [Action Required] Update scripts using Get-MailDetailTransportRuleReport and Get-MailTrafficPolicyReport [MC1323250]
![[Action Required] Update scripts using Get-MailDetailTransportRuleReport and Get-MailTrafficPolicyReport [MC1323250] 2 pexels earano 3608311](data:image/svg+xml;base64,PHN2ZyB3aWR0aD0iMSIgaGVpZ2h0PSIxIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciPjwvc3ZnPg==)
- Amazon SageMaker HyperPod Slurm clusters now support specifying minimum capacity requirements with continuous provisioning

- (Updated) Microsoft Teams: Rule-based enablement of Microsoft 365 third-party apps in the Teams admin center [MC1085133]
![(Updated) Microsoft Teams: Rule-based enablement of Microsoft 365 third-party apps in the Teams admin center [MC1085133] 4 pexels tirachard kumtanom 112571 347139](data:image/svg+xml;base64,PHN2ZyB3aWR0aD0iMSIgaGVpZ2h0PSIxIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciPjwvc3ZnPg==)
- Dynamics 365 Contact Center – Update to provide greater granularity to session rejection reasons [MC1324072]
![Dynamics 365 Contact Center – Update to provide greater granularity to session rejection reasons [MC1324072] 5 puppet 1636124 1920](data:image/svg+xml;base64,PHN2ZyB3aWR0aD0iMSIgaGVpZ2h0PSIxIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciPjwvc3ZnPg==)

![[Action Required] Update scripts using Get-MailDetailTransportRuleReport and Get-MailTrafficPolicyReport [MC1323250] 2 pexels earano 3608311](https://mwpro.co.uk/wp-content/uploads/2024/08/pexels-earano-3608311-150x150.webp)

![(Updated) Microsoft Teams: Rule-based enablement of Microsoft 365 third-party apps in the Teams admin center [MC1085133] 4 pexels tirachard kumtanom 112571 347139](https://mwpro.co.uk/wp-content/uploads/2024/08/pexels-tirachard-kumtanom-112571-347139-150x150.webp)
![Dynamics 365 Contact Center – Update to provide greater granularity to session rejection reasons [MC1324072] 5 puppet 1636124 1920](https://mwpro.co.uk/wp-content/uploads/2025/06/puppet-1636124_1920-150x150.webp)
![Legacy TLS cipher suites will be deprecated in M365 services on October 20, 2025 [MC1155427] 8 Legacy TLS cipher suites will be deprecated in M365 services on October 20, 2025 [MC1155427]](https://mwpro.co.uk/wp-content/uploads/2024/08/pexels-thepaintedsquare-820904-150x150.webp)