Say Hello to the New macOS UI for the Cloudflare One Client!
Hey there, it's Shiichan! Today I found a nice little update for Mac users, so let me walk you through it.
Cloudflare ChangelogWhat was announced?
From Cloudflare's Changelog, a new Beta of the macOS Cloudflare One Client, version 2026.5.1155.1, has landed. The headline is the brand-new client UI for macOS! It's cleaner and more intuitive, with quicker access to the actions and info you use most. You can grab it from the beta releases downloads page.
The new UI adds a right-click context menu for common client actions and a built-in captive portal login experience (that Wi-Fi sign-in screen).
The story so far
The previous macOS client was capable, but some of the controls were a little hard to find. This refresh brings the common actions up front and makes things much easier to use. Also, VNETs (virtual networks) used to be visible to every device in the org — that changes now too.
What changes
There's a lot here for administrators.
- The client now applies the DNS search suffixes configured in your device profile or network policy, appending search domains to single-label queries.
- From profile settings in the Zero Trust dashboard, you can now scope which VNETs each user sees, so people only see the networks relevant to them.
- Emergency Disconnect gains a local-file signal source. Even when both Cloudflare and your own infrastructure are unreachable, the presence of a file on disk can trigger a disconnect.
Dive Deep
A few small-but-handy items.
- The local DNS proxy now supports DNSSEC passthrough. DO/AD bits and RRSIG records are forwarded intact, so tools that validate DNSSEC locally — like
diganddrill— work correctly through the client. - A new MDM format for organization-wide settings was added, including a cleaner way to set the compliance environment (e.g. FedRAMP). See the updated Cloudflare One MDM documentation for details.
- Client Certificate posture checks now accept template variables like
${serial_number}and${device_uuid}in the Subject Alternative Name field, not just the Common Name. - Fixed a proxy-mode bug where hostnames with underscores (e.g. ai_app.com) were rejected, which had broken apps such as ChatGPT sandbox apps.
- Fixed the in-client captive portal rendering a blank page on some airline Wi-Fi (United inflight Wi-Fi was the reported case).
Heads up on known issues: registration can hang at "Checking your organization configuration" (a reboot fixes it), and split tunnel list config isn't in the new UI yet, so use CLI commands like warp-cli tunnel ip.
Wrap-up
- The macOS Cloudflare One Client gets a new UI (Beta, 2026.5.1155.1)
- Adds DNS search suffix support, per-profile VNET visibility, and a file-based Emergency Disconnect
- Plenty of quiet wins: DNSSEC passthrough, a new MDM format, and template variables in the SAN field
- Fixes for underscore hostnames and airline Wi-Fi captive portals
If you run Cloudflare One / Zero Trust on Macs, this update is right up your alley!