What
The sandbox can limit which websites commands run by Claude may reach. Its network proxy, the go-between that forwards those connections, now also checks the IP addresses an allowed hostname actually resolves to, not just the name.
- Built-in check: a hostname that resolves only to loopback, unspecified, link-local, multicast, broadcast or cloud-metadata addresses (for example
100.100.100.200,168.63.129.16,fd00:ec2::/32), or to this machine's own addresses, is refused with the errorERR_SRT_RESOLVED_ADDRESS_DENIED. The proxy answers with HTTP 403 and the headerX-Proxy-Error: blocked-by-sandbox-runtime. - Exception: such an address can still be reached when its IP literal is itself listed in
allowedDomains. - New setting
deniedResolvedAddresses: extra IP addresses or CIDR ranges (IPv4 or IPv6, unbracketed) that an allowed hostname must not resolve to, checked alongside the built-in set. A name that resolves only into them is refused as "a listed address". - Bad entries are rejected with "Invalid IP address or CIDR range. Use an IPv4/IPv6 literal or CIDR ...".
- The settings schema says this check is not applied to connections routed through
parentProxyormitmProxy.
Why
Without this, an allowed domain whose DNS answer points at an internal address, such as a cloud metadata service, could be used to reach that address from inside the sandbox. Administrators can now add their own internal ranges to the refused set. A command that relied on an allowed name resolving to a local or internal address will now be refused unless that IP is itself allowed.
It is not clear whether `deniedResolvedAddresses` can be set from Claude Code's own sandbox settings, or only in the sandbox runtime's…