[Cloudflare One] DNS Policies ELI5#28883
Merged
Oxyjun merged 10 commits intoproductionfrom Mar 24, 2026
Merged
Conversation
…itions and context Add plain-language introductions, spell out acronyms (DNSSEC, EDNS, DoH, DoT, EAR, OFAC, ITAR), define evaluation phases for selectors, clarify Allow/Override action descriptions, expand prerequisites in test page, and add pitfall callouts for timed policy duration and timezone inference.
Contributor
|
This pull request requires reviews from CODEOWNERS as it changes files that match the following patterns:
|
Replace /cloudflare-one/policies/gateway/ (does not exist) with /cloudflare-one/traffic-policies/ (correct Gateway overview page).
Contributor
Oxyjun
commented
Mar 10, 2026
Oxyjun
commented
Mar 10, 2026
Oxyjun
commented
Mar 10, 2026
Oxyjun
commented
Mar 10, 2026
- Allow action: qualify with first-match principle and link to order of enforcement, instead of oversimplified precedence claim - Evaluation phases: correct Override restriction to include both 'during' and 'after' phases (not just 'after'), add link to order of enforcement - Authoritative nameserver: revert inline definition per reviewer request (adds clutter) - EDNS client subnet: clarify /24 is Cloudflare's implementation choice, fix 'upstream DNS resolver' to 'authoritative DNS nameservers' per RFC 7871
…traffic-policies/dns/eli5
marciocloudflare
approved these changes
Mar 10, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Improves clarity across the 4 pages in
/cloudflare-one/traffic-policies/dns-policies/by adding inline definitions, spelling out acronyms, and surfacing non-obvious behavior. Generated via ELI5 analysis of all sections.index.mdxA/AAAArecord types with (IPv4)/(IPv6) in the block page sectioncommon-policies.mdx.comor.ru")test-dns-filtering.mdxdigandnslookuptools for readers unfamiliar with themREFUSED/NOERRORappear indigoutputREFUSEDandNOERRORDNS response codestimed-policies.mdx:::cautioncallout for the non-obvious duration timer behavior (absolute end time, not a pausable countdown):::notecallout for VPN/proxy timezone inference pitfall