Skip to content

Cloudflare Zero Trust Connector

Have I Been Squatted creates and maintains its own domain list in your Cloudflare Zero Trust account. Rules with the Block in Cloudflare Zero Trust response add the lookalike domains they flag to that list for seven days. You reference the list from a Gateway policy, and those domains are blocked on your network.

The connector creates one Gateway list and only ever writes to that list. Its name is haveibeensquatted- followed by a short identifier for your organization and -noedit, for example haveibeensquatted-a1b2c3d4-noedit. Leave the name as it is: if the connector has to reconnect, the name is how it recognises its own list, and the identifier keeps it apart from lists other Have I Been Squatted organizations create in the same Cloudflare account. It does not read, modify, or remove any list you created, and it does not create or change Gateway policies: you stay in control of what the list actually does.

Every entry it adds carries a description such as hibs:1;rule=<rule id>;exp=<expiry> | Blocked by a Have I Been Squatted rule until it expires. The hibs: prefix is how the connector recognises its own entries, and exp is when the entry expires, in Unix seconds. Leave the description in place. An entry without the prefix is treated as yours and is never removed, even when it names a domain a rule flags.

  1. In Cloudflare, go to Manage Account > API Tokens and create a token with the Zero Trust: Write permission for the account you want to protect.
  2. Copy your Account ID from the overview page of the Cloudflare dashboard.
  3. In the app, open Connectors > Cloudflare Zero Trust.
  4. Paste the Account ID and the token value, then click Connect.
  5. In Cloudflare, create a Gateway policy that references the new list: see Enforcement below.
  1. Create or edit a rule and open the Response tab.
  2. Select Add action > Block in Cloudflare Zero Trust.
  3. Select the Gateway list destination.
  4. Save the rule.

The response needs at least one domain condition in the rule, because only cited lookalike domain records produce entries; the builder does not save it on a rule with only email or canary conditions.

For each active rule alert that cites lookalike domain records, Have I Been Squatted adds each distinct cited domain to the list, up to 10 domains per alert.

  • Only domains from cited domain (lookalike permutation) records are added.
  • The monitored domain and its subdomains are never blocked.
  • Alerts that are resolved, ignored, or marked as false positives add nothing.
  • Email and canary evidence never produce entries.

Each delivery reads the whole list, removes Have I Been Squatted entries that have expired, makes its changes, and reads the list back to confirm every entry it added. A domain already in the list through an entry you added is left alone.

Entries expire seven days after they are added. Cloudflare list entries have no expiry of their own, so Have I Been Squatted removes its expired entries itself: on every delivery to the list, and whenever you click Test connection. An expired entry can therefore stay in the list until the next delivery or connection test.

A later alert for the same domain renews the entry once it has less than half of its seven days left. Renewing removes the entry and adds it again with a new expiry, so the domain is unlisted for the moment between the two requests. Nothing renews an entry while its finding stops alerting.

Creating the list does not block anything on its own. A Gateway policy has to reference it:

  1. In Cloudflare, go to Gateway > Firewall policies and create a DNS policy.
  2. Set the selector to Host, the operator to in list, and choose the haveibeensquatted-…-noedit list.
  3. Set the action to Block.

The integration page checks for this and reports one of:

Status Meaning
OK An enabled policy blocks traffic matching the list.
Not enforcing No policy references the list, the policy is disabled, or its action is not Block. Entries are stored but nothing is blocked.
Permission denied The token cannot read Gateway policies, so enforcement cannot be confirmed.

Cloudflare allows 1,000 entries per list on Standard plans and 5,000 on Enterprise. The API does not report which applies to your account, so the connector uses 1,000, which is safe on both.

When the list is full, adding a new domain replaces the Have I Been Squatted entry closest to expiry, one entry per new domain: never an entry you added yourself. If the list is full of your own entries, the new domain is not added and the delivery records it as skipped. A list sitting at capacity is expected rather than a fault, and the integration page reports it as At capacity.

  • Cloudflare allows 100 Gateway lists per account. Connecting fails if the account is already at that limit.
  • Domain lists do not accept wildcards. example.com is added as an exact hostname; subdomains are listed individually as they are flagged.
  • Internationalised domains are converted to their punycode form before being added, because Cloudflare compares entries in that form.

The integration page shows four checks, refreshed when you connect and whenever you click Test connection, which also removes expired Have I Been Squatted entries:

  • Credential: Cloudflare still accepts the stored token for this account.
  • Gateway list: the managed list still exists and is still a domain list.
  • Capacity: how much of the list is used.
  • Enforcement: whether a Gateway policy references the list.

For each alert and response, Have I Been Squatted records the delivery status, the domains it added, renewed, found already blocked, or skipped, the entries it replaced, how many expired entries it removed, the expiry, and, when a delivery fails, a short error code. The API token and Cloudflare response bodies are not stored.

If a delivery removed entries but then failed to add the new ones, it is recorded as failed with the entries it removed. Deliveries are not retried.

Deactivating the integration stops Have I Been Squatted from adding and expiring entries. The Gateway list and everything already in it stay in your Cloudflare account, so anything currently blocked stays blocked until you remove it. Delete the list in Cloudflare if you want the entries removed.