{"name":"sandbox.network.deniedDomains","slug":"sandbox-network-denieddomains","family":"setting","title":"Settings keys","noun":"settings key","description":"Block domains for [sandboxed](\/docs\/en\/sandboxing) commands, even inside an allowed wildcard","description_source":"docs","described_by":{"doc":"claude-code\/settings-reference","title":"All settings"},"presence":{"first_seen":null,"removed_in":null,"in_current_build":false,"newest_mined":"2.1.285","builds":0,"mined_builds":128,"first_cited":{"version":"2.1.284","released_at":"2026-09-28 17:11:59","spans":1}},"aliases":[],"entries":[{"version":"2.1.284","anchor":"sandbox-denieddomains-matches-the-canonicalised-host","heading":"Sandbox blocked-website rules now catch other spellings of the same host","line":"`deniedDomains` rules now also match a host written another way, such as a different IP address spelling or a trailing dot","released_at":"2026-09-28 17:11:59","reason":"named in this entry, found in this entry's text"},{"version":"2.1.224","anchor":"sandbox-network-rules-can-specify-a-port","heading":"Sandbox network rules can specify a port","line":"Sandbox allow and deny rules can now target a specific port instead of the whole host.","released_at":"2026-08-07 01:36:32","reason":"found in this entry's text"},{"version":"2.1.195","anchor":"monitor-tool-websocket-support","heading":"Monitor Tool WebSocket Support","line":null,"released_at":"2026-06-26 18:16:23","reason":"found in this entry's text"}],"entries_total":3,"docs":[{"source":"claude-code","path":"settings-reference","title":"All settings","documented":true},{"source":"claude-code","path":"tools-reference","title":"Tools reference","documented":false},{"source":"claude-code","path":"whats-new\/2026-w16","title":"Week 16 \u00b7 April 13\u201317, 2026","documented":false}],"docs_total":3,"gates":[],"related":[{"name":"sandbox.network","slug":"sandbox-network","description":"Control which hosts, ports, and sockets [sandboxed](\/docs\/en\/sandboxing#network-isolation) commands reach"},{"name":"sandbox.network.allowedDomains","slug":"sandbox-network-alloweddomains","description":"Pre-allow domains so [sandboxed](\/docs\/en\/sandboxing) commands don't prompt for them"},{"name":"sandbox.network.strictAllowlist","slug":"sandbox-network-strictallowlist","description":"Deny hosts outside the [allowlist](\/docs\/en\/sandboxing#network-isolation) instead of prompting"},{"name":"sandbox.network.tlsTerminate","slug":"sandbox-network-tlsterminate","description":"Have the [sandbox](\/docs\/en\/sandboxing#network-isolation) proxy terminate TLS so it can read HTTPS requests"}],"url":"https:\/\/changelogs.core-directive.com\/reference\/setting\/sandbox-network-denieddomains","family_url":"https:\/\/changelogs.core-directive.com\/reference\/setting.json"}