{"version":"2.1.284","anchor":"sandbox-network-proxy-gains-a-resolved-address-check-cloud","canonical_anchor":"new-sandbox-network-setting-deniedresolvedaddresses","heading":"Sandbox network proxy checks what allowed hostnames resolve to, with a new deniedResolvedAddresses setting","tier":"use","area":"Sandbox","url":"https:\/\/changelogs.core-directive.com\/v\/2.1.284\/e\/sandbox-network-proxy-gains-a-resolved-address-check-cloud","release_url":"https:\/\/changelogs.core-directive.com\/v\/2.1.284","markdown":"### Sandbox network proxy checks what allowed hostnames resolve to, with a new deniedResolvedAddresses setting\n\nThe sandbox now refuses allowed hostnames that resolve to loopback, cloud-metadata and similar addresses, and deniedResolvedAddresses adds your own ranges\n\n**Unclear.** It is not clear whether `deniedResolvedAddresses` can be set from Claude Code's own sandbox settings, or only in the sandbox runtime's configuration.\n\n**What**\n\nThe sandbox can limit which websites commands run by Claude may reach. Its network proxy, the go-between that forwards those connections, now also checks the IP addresses an allowed hostname actually resolves to, not just the name.\n\n- Built-in check: a hostname that resolves only to loopback, unspecified, link-local, multicast, broadcast or cloud-metadata addresses (for example `100.100.100.200`, `168.63.129.16`, `fd00:ec2::\/32`), or to this machine's own addresses, is refused with the error `ERR_SRT_RESOLVED_ADDRESS_DENIED`. The proxy answers with HTTP 403 and the header `X-Proxy-Error: blocked-by-sandbox-runtime`.\n\n- Exception: such an address can still be reached when its IP literal is itself listed in `allowedDomains`.\n\n- New setting `deniedResolvedAddresses`: extra IP addresses or CIDR ranges (IPv4 or IPv6, unbracketed) that an allowed hostname must not resolve to, checked alongside the built-in set. A name that resolves only into them is refused as \"a listed address\".\n\n- Bad entries are rejected with \"Invalid IP address or CIDR range. Use an IPv4\/IPv6 literal or CIDR ...\".\n\n- The settings schema says this check is not applied to connections routed through `parentProxy` or `mitmProxy`.\n\n**Why**\n\nWithout this, an allowed domain whose DNS answer points at an internal address, such as a cloud metadata service, could be used to reach that address from inside the sandbox. Administrators can now add their own internal ranges to the refused set. A command that relied on an allowed name resolving to a local or internal address will now be refused unless that IP is itself allowed.\n\n- Area: Sandbox\n- Names: `allowedDomains`\n- Tier: Use it now\n- Useful: 5\/5\n- Signal: 2\/5"}