Profile Options

A guide to every setting in Profile Options.

Open Profile Options

Go to Profiles, edit a Profile, and select Profile Options. These settings apply wherever that Profile is enforced. Changing a shared Profile can therefore affect more than one Endpoint.

A toggle being off does not always mean a feature is unavailable. For example, Disable DNSSEC being off leaves DNSSEC validation enabled, and a TTL override being off leaves the normal TTL behavior in place.

Profile settings

  • Profile Name: Change the name used to identify the Profile in the dashboard.
  • Default Rule: Choose what happens when no Custom Rule, Service Rule, or Filter matches.
  • Disable: Temporarily stop enforcing this Profile without deleting its settings.
  • Lock Profile: Protect the Profile against unwanted changes.

Security and content

  • AI Malware Filter: Use machine learning to block potentially malicious domains. Choose Minimal, Standard, or Aggressive.
  • Block DNS Attacks: Block or rewrite DNS patterns associated with exfiltration and payload delivery. This experimental option is intended for client devices, not servers.
  • Safe Search: Enforce supported search engines' mature-content restrictions.
  • Restricted Youtube: Enforce YouTube Restricted Mode and disable comments.
  • DNS Rebind Protection: Block public DNS answers that point to protected private or local address ranges.
  • Disable DNSSEC: Turn off DNSSEC validation for compatibility troubleshooting.

DNS responses and caching

  • Block TTL: Set how long blocked DNS answers may be cached.
  • Redirect TTL: Set how long redirected DNS answers may be cached.
  • Bypass TTL: Override the TTL of normally resolved DNS answers.
  • Block Response: Choose the response to blocked queries, including Custom and Branded block pages.
  • EDNS Client Subnet: Choose No ECS, Auto, or a Custom subnet for upstream DNS requests.
  • Compatibility Mode: Allow cross-stack IPv4/IPv6 answers for redirected traffic. Leave this off unless needed.
  • Enable DNS64: Synthesize IPv6 answers for IPv4 destinations on an IPv6-only network with a NAT64 gateway.
  • CNAME Flattening: Return the target IP address in place of a CNAME chain for supported answers.

Organization sharing

  • Shared Profile: Make a Main Organization's Profile available to its Sub-Organizations. This option appears only in the Main Organization.

Which rule wins?

Profile Options are not a way to rearrange Custom Rules, Services, and Filters. See Matching Order for rule priority, explicit Bypass actions, and how multiple enforced Profiles are combined.


Did this page help you?