
7/7/2025 · Ankur Aggarwal, Sharon Goldberg, João Paiva, Alyssa Wang
What this post added
This post introduces egress policies by hostname, domain, content category, and application within Cloudflare's SASE platform. Previously, egress policies were limited to user groups and destination IP addresses, making it difficult to manage access to external services with dynamic IP addresses. The new feature leverages Cloudflare's DNS resolver and a 'synthetic IP' mechanism to associate DNS queries with network connections, enabling L4 egress policy evaluation based on L7 information like hostnames. This significantly simplifies policy management for organizations and enhances security by providing more granular control over outbound traffic.