Back to blog
dns Published: AEU DNS Newsroom

Cloudflare for Teams Now Helps Remote Workers Reach Internal Hostnames Securely

Cloudflare for Teams Now Helps Remote Workers Reach Internal Hostnames Securely

Cloudflare's May 2020 announcement shows how its Zero Trust platform can answer DNS queries for private, internal hostnames, letting remote employees access company resources without traditional VPNs.

On May 19, 2020, Cloudflare published a blog post by Sam Rhea titled Resolve internal hostnames with Cloudflare for Teams. The post is tagged with Cloudflare Gateway, Cloudflare Zero Trust, DNS Filtering, DNS Security, Product News, Security, and Zero Trust. It draws attention to a practical capability that many organisations need as their teams work from home and branch offices: the ability to resolve internal hostnames through Cloudflare's cloud-based security platform. For businesses that rely on private servers, internal web applications, and corporate tools reachable only by name, this is a meaningful step toward simpler and safer remote access.

To understand why this matters, it helps to review what DNS and internal hostnames actually are. The Domain Name System (DNS) is often called the phonebook of the internet. When you type a web address like example.com into a browser, your device sends a DNS query to a resolver, which translates that human-friendly name into the numeric IP address that computers use to find each other. Most DNS lookups use public resolvers that know about public domain names. But many companies also run internal services, such as hr.intranet.company.com or files.office.local, that are not listed in public DNS. These are internal hostnames. On a corporate office network, a local DNS server usually answers those queries, so employees can reach internal tools by name. However, when working remotely, those same employees often lose that internal name resolution, because their home or coffee shop network does not have access to the company's private DNS server.

That gap has become more visible as remote and hybrid work has expanded. Without internal name resolution, remote workers may have to remember IP addresses, use a VPN that routes all traffic through the office, or rely on IT teams to publish internal names in a separate tool. A VPN (Virtual Private Network) can work, but it often slows down connections and may force all internet traffic through a corporate pipe. Cloudflare for Teams, which is part of Cloudflare's Zero Trust platform, approaches this differently. Zero Trust means that no user or device is trusted automatically, even if it is inside the corporate network. Instead, every request is checked before access is granted. Cloudflare Gateway, the secure DNS filtering component of Cloudflare for Teams, can apply security policies to DNS queries and, as this announcement highlights, can also help resolve internal hostnames for authorised users.

The security angle is significant. Internal hostnames are often not protected by public certificates, and their resolution can leak information about an organisation's internal structure if done over plain text. Cloudflare has tagged this post with DNS Security and DNS Filtering, signalling that the capability is part of a broader push to secure DNS traffic. When users rely on unencrypted DNS, their queries travel across the internet in plain text, where they might be read, modified, or redirected by attackers. Techniques such as DNS hijacking or cache poisoning can send a user to a fake version of an internal site to steal credentials. By handling internal hostname resolution through a cloud service that also offers encrypted DNS and filtering, organisations can reduce that risk while giving employees a consistent experience whether they are in the office or on a home network.

For IT teams and business owners, the announcement is a reminder to review how remote and hybrid employees reach internal resources. Rather than maintaining a complicated VPN setup just to access a few internal web pages, teams can consider DNS-based approaches that resolve names securely and apply policies per user. This is especially relevant for small and mid-sized companies that may not have dedicated networking staff. The Cloudflare for Teams platform, which later evolved into Cloudflare Zero Trust, combines access controls, DNS filtering, and security logging in one dashboard. The May 2020 post, while brief in its headline, points to a capability that has become standard in modern remote-access toolkits.

For readers who want to protect their own browsing and DNS queries while working remotely, using a private, encrypted DNS service helps keep lookups confidential and free from tampering. In Europe, services like AEU DNS (https://aeu-dns.com) provide privacy-first encrypted DNS over HTTPS and TLS, which can be used on personal devices and often inside organisations that want an extra layer of DNS privacy. While AEU DNS is a public resolver and does not replace an internal DNS server, it demonstrates how encrypted DNS protects the queries that everyone makes every day. For companies that need help designing secure remote access or internal name resolution, AEU's security-first IT consulting arm, AEU-I (https://aeu-i.com), can advise on implementing the right mix of Zero Trust, DNS filtering, and encrypted DNS for your infrastructure.

Terms explained

DNS
The Domain Name System, which translates website names into the numeric IP addresses computers use to communicate.
Internal hostname
A website or service name that only works on a company's private network, such as hr.intranet.company.com.
DNS filtering
A security feature that blocks or redirects domain name lookups based on rules, often used to stop malware, phishing, or unwanted content.
Zero Trust
A security model where no user or device is trusted by default, even inside the company network, and every request must be verified.
Cloudflare Gateway
Cloudflare's secure DNS filtering service that applies security policies to domain name requests and can resolve internal names for authorised users.
Encrypted DNS
A way of sending DNS lookups over an encrypted connection such as DNS over HTTPS or DNS over TLS so that outsiders cannot read or change the queries.
VPN
A Virtual Private Network that creates a secure, encrypted tunnel from your device to another network, often used for remote access but sometimes slower.

How to protect yourself

  1. If you work from home and need access to internal company websites, ask your IT department whether they offer a secure DNS-based remote access method like Cloudflare for Teams instead of a traditional VPN.
  2. Turn on encrypted DNS (DNS over HTTPS or DNS over TLS) in your browser or device settings so your website lookups cannot be easily read or modified by others on the same network.
  3. When you visit an internal website, always check that the web address begins with https:// and shows a padlock icon before entering your username or password, to avoid fake sites.
  4. Keep your computer and phone updated, because DNS and browser security fixes are often included in routine updates.
  5. For personal browsing, choose a privacy-respecting DNS service like AEU DNS to reduce tracking and block malicious domains.

Source: blog.cloudflare.com

Get private, encrypted DNS