Cloudflare One

SDNS, Cloudflare Zero Trust DNS for UniFi gateways

SDNS converts the DNS over HTTPS endpoint of a Cloudflare Zero Trust (Gateway) location into an SDNS stamp, so you can configure UniFi gateways to send every DNS query from your network through Cloudflare's filtering.

What it does

Paste the DNS over HTTPS endpoint of your Cloudflare Zero Trust location, and SDNS returns the matching SDNS stamp. Add that stamp as a custom DNS server on your UniFi gateway, and the whole network resolves through Cloudflare Gateway.

When it helps

  • Offices and sites with devices that cannot run the WARP client: printers, cameras, IoT, guest devices.
  • Small teams that want Cloudflare DNS filtering at the network edge without extra hardware.

Getting it

Talk to us and we help you set up Zero Trust DNS filtering across your sites.

Independent tools built by Noraina, a Cloudflare Authorized Service Delivery Partner. Not made or operated by Cloudflare. Cloudflare is a trademark of Cloudflare, Inc.

Frequently asked questions

Why do UniFi gateways need an SDNS stamp?

UniFi gateways accept custom encrypted DNS servers as SDNS stamps, a compact sdns:// string that describes the resolver. Cloudflare Zero Trust gives you a DNS over HTTPS URL, so it has to be converted before UniFi can use it.

What do I get by pointing a UniFi gateway at Cloudflare Zero Trust?

Every device on the network, including ones that cannot run the WARP client, has its DNS queries filtered by your Cloudflare Gateway policies, logged in your Cloudflare account and encrypted on the way.