blog.cloudflare.com 2 Oct 2026, 13:00 UTC

Cloudflare Quick Tunnels Add Accountless Email Access Controls

Cloudflare Quick Tunnels Add Accountless Email Access Controls
CyberSIXT Evidence Panel Source marked as original reporting

CLOUDFLARE has expanded its Quick Tunnels feature with a protected, accountless authentication option. Starting with cloudflared version 2026.9.3, users can attach an --allowed-mail rule to a Quick Tunnel, limiting access to specific email addresses or domains. Visitors sign in via Cloudflare Access using a one-time PIN sent to their email, but the decision about who is allowed to reach the local service is made on the user’s machine, not in a central policy service.

This keeps the guest list and rules effectively local, while leaving the public tunnel path unchanged. The system uses a lightweight, stateless authentication broker running on Cloudflare Workers to issue a short‑lived, signed handoff, which cloudflared then validates in memory against the user’s configured rules. Importantly, the guest list itself never leaves the user’s machine.

The article details the end‑to‑end flow: a visitor is redirected to login.trycloudflare[.]com, receives a PIN via email, and the broker returns a signed assertion tied to the tunnel hostname. The visitor’s browser posts this assertion back, cloudflared confirms it against the configured rules, and a local session is created for up to four hours. If authentication fails, the request is blocked before reaching the local service, and there is no central lookup.

The post also notes practical usage notes, such as adding multiple --allowed-mail entries or wildcard domains, and references alternative paths for more complex access control using Cloudflare Access or Cloudflare Mesh. The feature was shipped by two Cloudflare interns and is freely available for Quick Tunnels and developer demonstrations. 18 September 2026.

View full article

Article by CyberSIXT