Global policies
Cloudflare Zero Trust applies a set of global policies to all accounts.
DNS policies
| Criteria | Value | Action | Description | 
|---|
| Hostname | *.nel.cloudflare.com | allow | Allows SNI domains for WARP registration. | 
| Hostname | *.cloudflareclient.com | allow | Allows Zero Trust client. | 
| Hostname | *.cloudflare-gateway.com | allow | Allows Gateway proxy with PAC files. | 
| Hostname | dash.teams.cloudflare.com,help.teams.cloudflare.com,blocked.teams.cloudflare.com,api.cloudflare.com,cloudflarestatus.com,www.cloudflarestatus.com, andone.dash.cloudflare.com | allow | Allows Cloudflare Zero Trust services. | 
| Hostname | *.cloudflareaccess.com | allow | Allows Cloudflare Access applications. | 
Network proxy policies
| Criteria | Value | Action | Description | 
|---|
| Hostname | *.cloudflareaccess.com | allow | Allows Cloudflare Access applications. | 
| Hostname | help.teams.cloudflare.com | allow | Used by the WARP client to check if Gateway is on by inspecting the certificate and checking if it is properly installed on the client device. | 
| Content Category | Child Abuse | block | Blocks child abuse materials. | 
HTTP inspection policies
| Criteria | Value | Action | Description | 
|---|
| Hostname | *.cloudflareclient.com | bypass | Ensures users cannot accidentally block themselves from making account changes. | 
| Hostname | *.cloudflarestatus.com | bypass | Bypasses cloudflarestatus.comso users can reach the status page in case of a Gateway outage. | 
| Hostname | *.cloudflare-gateway.com | bypass | Ensures requests to the cloudflare-gateway.comDNS endpoint will not be inspected. | 
| Hostname | *.nel.cloudflare.com | bypass | Bypasses *.nel.cloudflarestatus.comfor Cloudflare’s network error logging feature. | 
| Hostname | api.cloudflare.com | bypass | Bypasses Cloudflare’s API endpoint. | 
| Hostname | dash.teams.cloudflare.com | bypass | Prevents users from being locked out of the Zero Trust dashboard. | 
| Hostname | *.dash.cloudflare.com | bypass | Bypasses the Cloudflare dashboard and subdomains. | 
| Hostname | blocked.teams.cloudflare.com | bypass | Prevents an infinite loop on the Gateway block page. | 
| Hostname | developers.cloudflare.comandhelp.cloudflarebrowser.com | noisolate | Prevents isolation of Cloudflare developer docs and help pages to help users troubleshoot configuration issues. | 
| Hostname | *.assets.browser.run | bypass | Required for Remote Browser Isolation (RBI). | 
| Hostname | *.edge.browser.runand*.cloudflarebrowser.com | bypass | Required for RBI. | 
| Hostname | *.edge.browser.runand*.cloudflarebrowser.com | isolate | Required for RBI. | 
| Hostname | speed.cloudflare.com | noscan | Allows files transferred by the Cloudflare speed test. | 
| Request Header | Accept: text/html | noisolate | Ensures only browsers will be isolated. Browsers issue an Accept:HTTP header that begins withtext/html. | 
| Application | Online Certificate Status Protocol | bypass | Enables OCSP stapling. |