Cloudflare WARP
Cloudflare, Inc. · Cloudflare’s Mac network client for encrypted DNS and WARP traffic, with separate consumer and organization-managed Zero Trust modes.
紹介
Cloudflare WARP is a network client that connects a device to Cloudflare's network. The Mac application can be used for consumer 1.1.1.1 with WARP or enrolled into an organization's Cloudflare Zero Trust deployment, now documented as the Cloudflare One Client. These modes have different accounts, settings and policy controls; installing the client alone does not enroll a device into a company or purchase a Zero Trust plan.
Connection modes
- DNS-only mode encrypts DNS queries to Cloudflare's 1.1.1.1 resolver without tunneling all device traffic.
- Traffic-and-DNS mode routes selected device traffic through WARP and uses the configured DNS mode.
- Traffic-only mode tunnels traffic while leaving DNS resolution to the operating system.
- Desktop local-proxy mode tunnels only applications explicitly configured to use its proxy.
- Consumer options include connection preferences and optional 1.1.1.1 for Families filtering.
- Organizational deployments can apply device policies, split tunneling, private-network routing and access controls.
Current documentation describes MASQUE for traffic encryption; do not assume every connection uses the legacy WireGuard protocol. The configured mode, protocol, exclusions and organizational policies determine actual coverage. DNS-only mode is not full traffic encryption, and local-proxy mode leaves other applications on their normal connection.
Install and connect
Install with brew install --cask cloudflare-warp, or use Cloudflare's official Mac PKG. Follow the installer, operating-system network/VPN prompts and privacy-policy acceptance. The package installs a background network service and updater as well as the application. Open Cloudflare WARP and enable the connection toggle for consumer use, then inspect its connection status and preferences.
For organizational use, follow your administrator's enrollment instructions and authenticate with the organization's identity provider. The administrator can require device posture, control connection settings and apply filtering or private-resource access policies. A personal WARP connection is not equivalent to organizational enrollment, and managed deployments may restrict disconnection or settings. Do not remove registrations or change organization policies merely to troubleshoot a personal connectivity problem.
The cask conflicts with cloudflare-warp@beta; choose stable or beta instead of overlapping installations. Other VPNs, DNS filters, proxies or security clients can interact with WARP's routes and DNS. Consult compatibility guidance and the organization administrator before changing managed network settings.
Privacy and limitations
WARP does not provide anonymity or prevent websites from identifying you through accounts, cookies, browser fingerprints or other information. Cloudflare states that its replacement IP represents your approximate location; WARP does not offer arbitrary country selection or promise access to geographically restricted content. It can change network performance in either direction, and some location-sensitive services may not work as expected.
Encryption protects the covered path to Cloudflare, not every endpoint or application behavior. Cloudflare and, in managed deployments, your organization's configured services participate in traffic handling. Review the applicable privacy policy and organization notices. Diagnostic logs can contain network or device information; submit them only through appropriate support processes.
Systems and resources
This captured cask allows macOS 14 or later. Cloudflare's current official support table is more restrictive: macOS Sequoia 15.1 or later (15.0.x is not supported), Tahoe 26 or later, and Golden Gate 27 or later, on Intel or M-series Macs. The cask's installation gate is not a guarantee of vendor support on Sonoma. Check the current official support table before deploying.
Cloudflare lists at least 3 CPU cores, 4 recommended, 8 GB RAM and 1 GiB disk space for the current Mac client. A Wi-Fi or LAN connection is required; the support table recommends MTU 1381 bytes, with documented lower-MTU requirements and path discovery guidance. Network administrators should manage these settings for their environment rather than assuming any VPN works on every restricted network.
The current 2026.8.2100.0 Mac installer is 165,866,465 bytes, verified by official HTTP metadata. This is download size, not installed space. Separate Windows, Linux, iOS and Android clients are available; this cask installs the Mac distribution only. The client needs network access to establish its connection, enroll and update; it provides no offline Internet service.
Cost, accounts and license
Cloudflare provides basic consumer WARP without a paid subscription. Ordinary consumer use does not require a Zero Trust organization account. WARP+ Unlimited is an optional monthly consumer subscription purchased through mobile app stores; its availability, price and device entitlement follow current Cloudflare terms. It is not required for basic WARP, does not promise a speed increase on every network, and is separate from enterprise Zero Trust licensing.
Zero Trust enrollment requires an organization and its configured identity flow. Cloudflare offers organization plans with different free or paid limits; a plan's features and policy entitlements depend on the organization's subscription. The Mac client is proprietary software governed by Cloudflare's applicable software terms, privacy policy and third-party notices, not an open-source VPN application.
Sources: Consumer Mac setup, Modes and WARP+, Consumer FAQ, Official download and support table, Mac client changelog.
新バージョン 2026.8.2100.0の更新内容 10月7日 · OpenNavo編集部
- RoutingKeeps learned split-tunnel exclusions across reconnects.
- DNSShares one hosts-file read across DNS resolvers.
- Client fixesImproves reauthentication without forcing new registration.