Skip to content

Changelog

New updates and improvements at Cloudflare.

CASB and Email security

With Email security, you get two free CASB integrations.

Use one SaaS integration for Email security to sync with your directory of users, take actions on delivered emails, automatically provide EMLs for reclassification requests for clean emails, discover CASB findings and more.

With the other integration, you can have a separate SaaS integration for CASB findings for another SaaS provider.

Refer to Add an integration to learn more about this feature.

CASB-EmailSecurity

This feature is available across these Email security packages:

  • Enterprise
  • Enterprise + PhishGuard

Secure DNS Locations Management User Role

We're excited to introduce the Cloudflare Zero Trust Secure DNS Locations Write role, designed to provide DNS filtering customers with granular control over third-party access when configuring their Protective DNS (PDNS) solutions.

Many DNS filtering customers rely on external service partners to manage their DNS location endpoints. This role allows you to grant access to external parties to administer DNS locations without overprovisioning their permissions.

Secure DNS Location Requirements:

  • Mandate usage of Bring your own DNS resolver IP addresses if available on the account.

  • Require source network filtering for IPv4/IPv6/DoT endpoints; token authentication or source network filtering for the DoH endpoint.

You can assign the new role via Cloudflare Dashboard (Manage Accounts > Members) or via API. For more information, refer to the Secure DNS Locations documentation.

Cloudflare One Agent for Android (version 2.4)

A new GA release for the Android Cloudflare One Agent is now available in the Google Play Store. This release includes a new feature allowing team name insertion by URL during enrollment, as well as fixes and minor improvements.

Changes and improvements

  • Improved in-app error messages.
  • Improved mobile client login with support for team name insertion by URL.
  • Fixed an issue preventing admin split tunnel settings taking priority for traffic from certain applications.

Cloudflare IP Ranges List

Magic Firewall now supports a new managed list of Cloudflare IP ranges. This list is available as an option when creating a Magic Firewall policy based on IP source/destination addresses. When selecting "is in list" or "is not in list", the option "Cloudflare IP Ranges" will appear in the dropdown menu.

This list is based on the IPs listed in the Cloudflare IP ranges. Updates to this managed list are applied automatically.

Cloudflare IPs Managed List

Note: IP Lists require a Cloudflare Advanced Network Firewall subscription. For more details about Cloudflare Network Firewall plans, refer to Plans.

Cloudflare One Agent now supports Endpoint Monitoring

Digital Experience Monitoring (DEX) provides visibility into device, network, and application performance across your Cloudflare SASE deployment. The latest release of the Cloudflare One agent (v2025.1.861) now includes device endpoint monitoring capabilities to provide deeper visibility into end-user device performance which can be analyzed directly from the dashboard.

Device health metrics are now automatically collected, allowing administrators to:

  • View the last network a user was connected to
  • Monitor CPU and RAM utilization on devices
  • Identify resource-intensive processes running on endpoints
Device endpoint monitoring dashboard

This feature complements existing DEX features like synthetic application monitoring and network path visualization, creating a comprehensive troubleshooting workflow that connects application performance with device state.

For more details refer to our DEX documentation.

Gain visibility into user actions in Zero Trust Browser Isolation sessions

We're excited to announce that new logging capabilities for Remote Browser Isolation (RBI) through Logpush are available in Beta starting today!

With these enhanced logs, administrators can gain visibility into end user behavior in the remote browser and track blocked data extraction attempts, along with the websites that triggered them, in an isolated session.

{
	"AccountID": "$ACCOUNT_ID",
	"Decision": "block",
	"DomainName": "www.example.com",
	"Timestamp": "2025-02-27T23:15:06Z",
	"Type": "copy",
	"UserID": "$USER_ID"
}

User Actions available:

  • Copy & Paste
  • Downloads & Uploads
  • Printing

Learn more about how to get started with Logpush in our documentation.

New SAML and OIDC Fields and SAML transforms for Access for SaaS

Access for SaaS applications now include more configuration options to support a wider array of SaaS applications.

SAML and OIDC Field Additions

OIDC apps now include:

  • Group Filtering via RegEx
  • OIDC Claim mapping from an IdP
  • OIDC token lifetime control
  • Advanced OIDC auth flows including hybrid and implicit flows
OIDC field additions

SAML apps now include improved SAML attribute mapping from an IdP.

SAML field additions

SAML transformations

SAML identities sent to Access applications can be fully customized using JSONata expressions. This allows admins to configure the precise identity SAML statement sent to a SaaS application.

Configured SAML statement sent to application

Use Logpush for Email security detections

You can now send detection logs to an endpoint of your choice with Cloudflare Logpush.

Filter logs matching specific criteria you have set and select from over 25 fields you want to send. When creating a new Logpush job, remember to select Email security alerts as the dataset.

logpush-detections

For more information, refer to Enable detection logs.

This feature is available across these Email security packages:

  • Enterprise
  • Enterprise + PhishGuard

Check status of Email security or Area 1

Concerns about performance for Email security or Area 1? You can now check the operational status of both on the Cloudflare Status page.

For Email security, look under Cloudflare Sites and Services.

  • Dashboard is the dashboard for Cloudflare, including Email security
  • Email security (Zero Trust) is the processing of email
  • API are the Cloudflare endpoints, including the ones for Email security

For Area 1, under Cloudflare Sites and Services:

  • Area 1 - Dash is the dashboard for Cloudflare, including Email security
  • Email security (Area1) is the processing of email
  • Area 1 - API are the Area 1 endpoints
Status-page

This feature is available across these Email security packages:

  • Advantage
  • Enterprise
  • Enterprise + PhishGuard

Use DLP Assist for M365

Cloudflare Email security customers who have Microsoft 365 environments can quickly deploy an Email DLP (Data Loss Prevention) solution for free.

Simply deploy our add-in, create a DLP policy in Cloudflare, and configure Outlook to trigger behaviors like displaying a banner, alerting end users before sending, or preventing delivery entirely.

Refer to Outbound Data Loss Prevention to learn more about this feature.

In GUI alert:

DLP-Alert

Alert before sending:

DLP-Pop-up

Prevent delivery:

DLP-Blocked

This feature is available across these Email security packages:

  • Enterprise
  • Enterprise + PhishGuard

Configure your Magic WAN Connector to connect via static IP assignment

You can now locally configure your Magic WAN Connector to work in a static IP configuration.

This local method does not require having access to a DHCP Internet connection. However, it does require being comfortable with using tools to access the serial port on Magic WAN Connector as well as using a serial terminal client to access the Connector's environment.

For more details, refer to WAN with a static IP address.

Open email links with Security Center

You can now investigate links in emails with Cloudflare Security Center to generate a report containing a myriad of technical details: a phishing scan, SSL certificate data, HTTP request and response data, page performance data, DNS records, what technologies and libraries the page uses, and more.

Open links in Security Center

From Investigation, go to View details, and look for the Links identified section. Select Open in Security Center next to each link. Open in Security Center allows your team to quickly generate a detailed report about the link with no risk to the analyst or your environment.

For more details, refer to Open links.

This feature is available across these Email security packages:

  • Advantage
  • Enterprise
  • Enterprise + PhishGuard

Block files that are password-protected, compressed, or otherwise unscannable.

Gateway HTTP policies can now block files that are password-protected, compressed, or otherwise unscannable.

These unscannable files are now matched with the Download and Upload File Types traffic selectors for HTTP policies:

  • Password-protected Microsoft Office document
  • Password-protected PDF
  • Password-protected ZIP archive
  • Unscannable ZIP archive

To get started inspecting and modifying behavior based on these and other rules, refer to HTTP filtering.

Escalate user submissions

After you triage your users' submissions (that are machine reviewed), you can now escalate them to our team for reclassification (which are instead human reviewed). User submissions from the submission alias, PhishNet, and our API can all be escalated.

Escalate

From Reclassifications, go to User submissions. Select the three dots next to any of the user submissions, then select Escalate to create a team request for reclassification. The Cloudflare dashboard will then show you the submissions on the Team Submissions tab.

Refer to User submissions to learn more about this feature.

This feature is available across these Email security packages:

  • Advantage
  • Enterprise
  • Enterprise + PhishGuard

Increased transparency for phishing email submissions

You now have more transparency about team and user submissions for phishing emails through a Reclassification tab in the Zero Trust dashboard.

Reclassifications happen when users or admins submit a phish to Email security. Cloudflare reviews and - in some cases - reclassifies these emails based on improvements to our machine learning models.

This new tab increases your visibility into this process, allowing you to view what submissions you have made and what the outcomes of those submissions are.

Use the Reclassification area to review submitted phishing emails

Establish BGP peering over Direct CNI circuits

Magic WAN and Magic Transit customers can use the Cloudflare dashboard to configure and manage BGP peering between their networks and their Magic routing table when using a Direct CNI on-ramp.

Using BGP peering allows customers to:

  • Automate the process of adding or removing networks and subnets.
  • Take advantage of failure detection and session recovery features.

With this functionality, customers can:

  • Establish an eBGP session between their devices and the Magic WAN / Magic Transit service when connected via CNI.
  • Secure the session by MD5 authentication to prevent misconfigurations.
  • Exchange routes dynamically between their devices and their Magic routing table.

Refer to Magic WAN BGP peering or Magic Transit BGP peering to learn more about this feature and how to set it up.

Generate customized terraform files for building cloud network on-ramps

You can now generate customized terraform files for building cloud network on-ramps to Magic WAN.

Magic Cloud can scan and discover existing network resources and generate the required terraform files to automate cloud resource deployment using their existing infrastructure-as-code workflows for cloud automation.

You might want to do this to:

  • Review the proposed configuration for an on-ramp before deploying it with Cloudflare.
  • Deploy the on-ramp using your own infrastructure-as-code pipeline instead of deploying it with Cloudflare.

For more details, refer to Set up with Terraform.

Find security misconfigurations in your AWS cloud environment

You can now use CASB to find security misconfigurations in your AWS cloud environment using Data Loss Prevention.

You can also connect your AWS compute account to extract and scan your S3 buckets for sensitive data while avoiding egress fees. CASB will scan any objects that exist in the bucket at the time of configuration.

To connect a compute account to your AWS integration:

  1. In Cloudflare One, go to Cloud & SaaS findings > Integrations.
  2. Find and select your AWS integration.
  3. Select Open connection instructions.
  4. Follow the instructions provided to connect a new compute account.
  5. Select Refresh.

Improved non-English keyboard support

You can now type in languages that use diacritics (like á or ç) and character-based scripts (such as Chinese, Japanese, and Korean) directly within the remote browser. The isolated browser now properly recognizes non-English keyboard input, eliminating the need to copy and paste content from a local browser or device.

Use Logpush for Email security user actions

You can now send user action logs for Email security to an endpoint of your choice with Cloudflare Logpush.

Filter logs matching specific criteria you have set or select from multiple fields you want to send. For all users, we will log the date and time, user ID, IP address, details about the message they accessed, and what actions they took.

When creating a new Logpush job, remember to select Audit logs as the dataset and filter by:

  • Field: "ResourceType"
  • Operator: "starts with"
  • Value: "email_security".
Logpush-user-actions

For more information, refer to Enable user action logs.

This feature is available across all Email security packages:

  • Enterprise
  • Enterprise + PhishGuard