Secure Internet and SaaS Access (ZIA)
About URL Categories
Zscaler organizes URLs into a hierarchy of categories for granular filtering and policy creation. There are six predefined classes, which are then each divided into predefined super categories, and then further divided into predefined categories.
For example, the Bandwidth Loss class includes categories such as video and music streaming because they are are typically known to consume more bandwidth than other categories. These classes are also customizable, so if you think that video streaming should not be classified under Bandwidth Loss, you can manually move it to another classification that works best for you and your organization.
The six predefined classes are:
- Bandwidth Loss
Super Category: News and Media Categories and Definitions Examples News and Media: Sites that report information or commentary on current events or contemporary issues, including newspapers, newswire services, news magazines, and radio news stations. www.cnn.com,
www.asiaone.comCloseSuper Category: User-Defined Categories and Definitions You can populate this category with sub-categories or URLs that you manually create. - Business Use
Super Category: Education Categories and Definitions Examples Continuing Education/Colleges: Sites related to institutions and colleges offering formal courses of advanced studies for adults. www.duke.edu,
www.ox.ac.ukHistory: Sites that offer a systematic recording of past events or analysis and commentary on causes and effects, motives, or connections relating to events. www.hyperhistory.com,
www.besthistorysites.netK-12: Sites related to the education of children. www.k12.com,
www.ilacademy.netOther Education: Other sites related to education that is not included in the defined categories. students-tut.ru,
formasup-npc.orgReference Sites: Sites that offer scholars and academics source documents and research assistance. www.wikipedia.org,
www.dictionary.comScience/Tech: Sites related to science and technology. www.scitechdaily.com,
www.livescience.comSuper Category: Information Technology Categories and Definitions Examples Advertising: Sites that provide service links, banners, or ads for websites. www.buysellads.com,
www.fusionads.netGenerative AI and ML Applications: Sites that provide tools, services, or information related to generative AI (i.e., a subfield of artificial intelligence that can generate new text, images, videos, or audio.). openai.com,
bard.google.comCDN: Sites that use content delivery networks to optimize the delivery of localized content to end users. cdn.espn.com,
bighost.beDNS Over HTTPS Services: Sites that provide DNS resolution over an encrypted and secure connection with the DNS over HTTPS service. This category includes DNS server URLs that support DNS resolution using the HTTPS protocol. dns.google/dns-query,
cloudflare-dns.com/dns-queryFile Converters: Sites and services that allow users to convert files from one format to another. www.freepdfconvert.com,
www.freeconvert.comFileHost: Sites that offer hosting, backup, and sharing of files on the internet. It also includes sites that allow you to upload files for online processing such as file conversion. www.dropbox.com,
www.pdftoimage.comGeneral AI and ML Applications: Sites that offer non-generative AI and ML applications and services. This category include websites for AI research labs, AI-powered solution providers, AI/ML app demonstrations and tutorials, and that enable automation with AI and ML. aimagazine.com,
www.aitrends.comImage Host: Sites that provide video or image hosting, linking, or sharing. www.flickr.com,
www.imgur.comOperating System and Software Updates: Sites and links that are used for downloading operating systems such as Windows, iOS, etc. and software updates. swcdn.apple.com,
windowsupdate.microsoft.comOther Information Technology: Other sites related to information technology that are not included in the defined categories. kwonnam.pe.kr,
bellsouthemailsettings.comPortals: Sites that offer multiple web-based services to assist a user's experience on the internet. qq.com,
naver.comSafe Search Engine: Sites that provide internet search services geared specifically for families and children and prevent the discovery of objectionable material. www.safesearchkids.com,
fragfinn.deShareware Download: Sites that are related to or offer downloading of a large number of legal third party software. www.download.cnet.com,
www.filehippo.comTranslators: Sites that offer translation services for web pages, URLs, or other text strings. translate.google.com,
www.freetranslation.comWeb Host: Sites that offer web hosting services, as well as domain names and web space, to host end-user web pages. www.siteground.com,
www.myown.euWeb Search: Sites that offer search services for the internet, indices, and directories. www.google.com,
www.yahoo.comSuper Category: Internet Communication Categories and Definitions Examples Blogs: Sites related to online journals, diaries, or newsletters that express personal thoughts and opinions about social or political issues. www.tumblr.com,
www.wordpress.orgDiscussion Forums: Sites related to Usenet, Usenet news, forums, newsgroups, or online bulletin board systems. www.cellar.org,
www.wsc-forum.deInternet Services: Sites that offer online utility applications or services that assist in internet communication. www.singnet.com.sg,
www.imagin.comOnline Chat: Sites that offer access to, software for, or participation in any internet chat forum. Chat is defined as any online conversation taking place in real-time. finnchat.com,
msngr.comOther Internet Communication: Other sites related to internet communications that are not included in the defined categories. softyupdates.com,
ipixo.comPeer-to-Peer Site: Sites that provide client software to enable peer-to-peer file sharing and transfers. www.bittorrent.com, www.limewire.com Remote Access Tools: Sites that provide information or software to enable authorized access to a desktop computer or private network from a remote location. www.teamviewer.com,
www.logmein.comWebmail: Sites that provide email accounts, free or otherwise. www.mail.google.com,
www.hotmail.comWeb Conferencing: Sites that assist in conducting video conferencing or provide software to enable virtual meetings. www.webex.com,
www.zoom.usZscaler Proxy IPs: This category includes IP addresses owned by Zscaler's data centers and services such as IP addresses of the Public Service Edge on a cloud and global VIP service. Super Category: Job/Employment Search Categories and Definitions Examples Job/Employment Search: Sites that provide employment services, assistance in finding employment, or tools for locating employers. www.monster.com,
www.indeed.comCloseSuper Category: Microsoft Office 365 (Applicable only for SSL Inspection Policy) Categories and Definitions Examples MS O365 Allow: Sites that are required but are not as sensitive to network performance and latency as those in the Optimize category.
Microsoft recommends bypassing these sites from SSL inspection and authentication.
smtp.office365.com MS O365 Default: Sites that do not require any optimization and can be treated as regular Internet traffic. ssw.live.com,
storage.live.comMS O365 Optimize: Sites that are required for connectivity to every Office 365 service. These sites are very sensitive to network performance, latency, and availability.
Ensure to bypass these sites from SSL inspection and authentication.
outlook.office.com,
outlook.office365.com - General Surfing
Super Category: Miscellaneous Categories and Definitions Miscellaneous or Unknown: Sites that have not yet been classified by Zscaler. Newly Registered and Observed Domains: Sites whose domains were created in the last 30 days and are currently not categorized by Zscaler. This category also includes domains that we encounter for the first time. Domains under this category are considered suspicious until they are categorized or better understood by Zscaler.
This category is a subset of the Miscellaneous or Unknown category. To determine if a Miscellaneous or Unknown URL belongs in the Newly Registered and Observed Domain (NROD) category, when a URL is found in the Miscellaneous or Unknown category, it is checked against Zscaler's NROD database. If there’s a match, the URL is categorized as a Newly Registered and Observed Domain. To enable the use of this category, select Enable Suspicious New Domains Lookup in your Advanced URL Policy Settings.
This category can only be used in URL Filtering rules.
Non Categorizable: Sites that Zscaler has not been able to categorize. Some of the reasons a site may appear here are that the site is a login page without any other details, it no longer exists, it is parked or available for sale, or it is unresolvable on the internet. Other Miscellaneous: Other sites that are not included in the defined categories. Super Category: Travel Categories and Definitions Examples Travel: Sites related to travel planning, information, or activities, including reservation services, destination listings, and special event promotion. www.contiki.com,
www.singaporeair.comCloseSuper Category: Vehicles Categories and Definitions Examples Vehicles: Sites that provide information about or promote vehicles, or offer for purchase vehicle parts or maintenance. www.toyota.com,
www.volkswagen.com - Legal Liability
Super Category: Drugs Categories and Definitions Examples Other Drugs: Sites associated with the use or advocacy of illegal drugs or the illegal use of prescribed drugs, except those sites related to Marijuana. livwell.com,
buyecstasy.comMarijuana: Sites that promote or discuss the cultivation, manufacture, distribution or sale of marijuana for recreational or medicinal purposes. It includes web pages on legalizing marijuana, using marijuana for medicinal purposes, marijuana facts and info pages, and sites that mention hemp, cannabis, blunts, panama red, etc. www.leafly.com,
thcbiomed.comSuper Category: Gambling Categories and Definitions Examples Gambling: Sites that provide online gambling or are related to gambling assistance, training information, or advocacy. www.casino.com,
www.singaporepools.com.sgSuper Category: Illegal or Questionable Categories and Definitions Examples Anonymizer: Sites that allow users to surf the internet or send email anonymously by providing proxy bypass functionality or information or instructions on how to do so. www.anonymizer.com,
www.your-freedom.netComputer Hacking: Sites related to the promotion of illegal tools and mechanisms to crack passwords, generate and distribute malicious software, or gain unauthorized access to computer systems. www.cellphonehacks.com,
www.hayy.netCopyright Infringement: Sites related to bootlegged or otherwise illegally available copyrighted material, such as program, DVD movies, and CD or MP3 music. sci-hub.tw,
bingemachine.comMature Humor: Sites that contain humor and mature themes unsuitable for teenagers and children, but no pornography or strong profanity. thejokeyard.com,
badmovies.orgOther Illegal or Questionable: Other sites related to illegal or questionable activities that are not classified in the defined categories. salesreceiptstore.com,
katcr.coProfanity: Sites that contain generally acknowledged profanity but do not fall under a more specific category such as "Pornography." www.yourfuckingpollingplace.com Questionable: Sites that are generally related to illegal activities but do not fall under a more specific category. www.joyofsatan.org,
www.satanicchurch.comSuper Category: Militancy/Hate Extremism Categories and Definitions Examples Militancy/Hate and Extremism: Sites that promote divisive rhetoric or action, describe certain populations as dangerous, evil, or promote intolerance of individuals or groups. www.newnation.org,
www.klanparenthood.comSuper Category: Tasteless Categories and Definitions Examples Tasteless: Sites related to torture, human and animal degradation, and other behavior generally considered too inappropriate for a public audience such as actively aggressive, attacking content, and so on. www.morticom.com, www.gore2gasm.com Super Category: Violence Categories and Definitions Examples Violence: Sites that depict, promote, or feature violence. stranakrovi.com,
serienkillers.deCloseSuper Category: Weapons/Bombs Categories and Definitions Examples Weapons/Bombs: Sites that promote the use, making, or distribution of weapons. dsparmory.co,
nragungiveaway.org - Productivity Loss
Super Category: Health Categories and Definitions Examples Health: Sites related to an individual’s physical and mental well-being. multiformelegym.com,
ochsstaywell.comSuper Category: Religion Categories and Definitions Examples Alt/New Age: Sites related to non-traditional or nonreligious spiritual belief systems, or related to the practice or advocacy of affecting events through supernatural means. thetarotguide.com,
mirsularii.comCult: Sites related to groups or movements whose membership is marked by zeal, passion, and obedience to a degree generally considered excessive by the mainstream. theflatearthsociety.org,
medaglia-miracolosa.itOther Religion: Other sites related to religion that is not classified in the defined categories. stmarkstn.org,
qcforjesus.comTraditional Religion: Sites related to traditionally organized religious activities, participation, and belief. www.chc.org.sg,
www.buddhanet.netSuper Category: Shopping and Auctions Categories and Definitions Examples Online Auctions: Sites that offer participation in online auctions or support the offer and purchase of goods between individuals. www.quibids.com,
www.onlineauction.comOnline Shopping: Sites that provide, or advertise ways to purchase products or services over the internet or by telephone. www.overstock.com,
www.amazon.comOther Shopping and Auctions: Other sites related to shopping and auctions that are not included in the defined categories. thecholmeleyarms.co.uk,
shoppiego.comReal Estate: Sites that offer information or services related to buying, selling, renting, or financing a property. www.redas.com,
www.propnex.comSuper Category: Social and Family Issues Categories and Definitions Examples Family Issues: Sites related to issues specific to the family such as divorce, adoption, infertility, domestic violence, and so on. maritallaws.com,
resetting-the-family.comOther Social and Family Issues: Other sites related to social and family issues that are not classified in the defined categories. hopecle.org,
familiesforfamilies.netSocial Issues: Sites related to issues generally considered to engender controversies, such as abortion, euthanasia, legalization of drugs, and so on. kandoo.me,
robindiangelo.comSuper Category: Society and Lifestyle Categories and Definitions Examples Alcohol/Tobacco: Sites related to the use of alcohol and tobacco products, excluding those that inform on the hazards of alcohol and tobacco. www.martell.com,
melbournehookah.com.auLifestyle: Sites related to lifestyle activities such as parties and so on for all orientations. www.lambda.org,
www.clubmask.comArt/Culture: Sites related to the mores, activities, organizations, and collective behavior of peoples that define various cultures around the world. www.artandculture.com,
www.metmuseum.orgDining/Restaurant: Sites that list, discuss, review, advertise, or promote dining and restaurants. www.mcdonalds.com,
www.hungrygowhere.comHobbies/Leisure: Sites related to hobbies and leisure, or pursuits or interests engaged in for pleasure and relaxation. jenniemasterson.com,
takemefishing.orgOther Society and Lifestyle: Other sites related to society and lifestyle that are not classified in the defined categories. carolineandmichael2020.com,
ashlandandblake.comSocial Networking: Sites that enable the creation of online communities or the facilitation of personal introductions, dating, and networking. www.facebook.com,
www.linkedin.comSuper Category: Special Interests/Social Organizations Categories and Definitions Examples Special Interests/Social Organizations: Sites related to charitable organizations, community or environmental interest groups, or social advocacy. www.greenpeace.org,
www.audi-denkwerkstatt.deCloseSuper Category: Sports Categories and Definitions Examples Sports: Sites related to sports or recreation. espn.go.com,
www.nba.com - Privacy RiskClose
Super Category: Security Categories and Definitions Examples Custom Encrypted Content: Sites that use custom encryption for protecting users’ data. Zscaler can inspect the HTTP headers of such sites but not the body content. mask.icloud.com,
app.stupendo.coDynamic DNS Host: Sites that dynamically update the IP address of the hostname and provide DNS resolution. This category includes DNS server URLs that support Dynamic DNS resolution. dyndns.com,
no-ip.comNewly Revived Domains: Sites that were reactivated after a brief period of inactivity for about 10 days. Some of these websites were originally active with a legitimate reputation.
To enable the use of this category, select Enable Suspicious New Domains Lookup in your Advanced URL Policy Settings.
Other Security: Other sites related to security that are not included in the defined categories. trustwave.ctscloud.com,
microsoftinternetsafety.netSpyware/Adware: Sites that are known to distribute or contain code that displays unwanted advertisements or that gathers user information without the user’s knowledge. www.spywareremove.com,
www.virusspy.com
You can download the preceding list: Download
The URL category provides the following benefits and enables you to:
- Accurately categorize websites based on their content.
- Control access to websites more effectively.
- Properly use URL classification which complements our existing policies (Data Loss Prevention (DLP), Sandbox, Filetype, and SSL Policies).
- Create custom URL categories that provide greater flexibility while creating URL Filtering rules.
You cannot add new classes, nor can you edit or delete the predefined classes. Each class has super categories. You cannot add or delete super categories, but you can move them from one class to another for easier management. For example, your organization is in the entertainment field and your users often visit entertainment sites. You can move the Entertainment/Recreation super category to the Business Use class. You can also add additional custom categories to the super category by clicking the Add icon that appears next to the super category in Administration > URL Categories.
For the predefined categories, you can add URLs or IP addresses, keywords, and IP ranges for websites you want to be included in that category. You can also enter subdomains (for example, mail.google.com
). This can be done by clicking the Edit icon that appears next to it in the list of URL categories found in Administration > URL Categories. If you manually add a URL or subdomain to an existing super category, category, or custom category, you can also specify whether you want it to retain its original parent category. For example, if you manually add www.google.com
to a User-Defined category, you can specify whether you want google.com also to retain its original Web Search category. You cannot delete any category that is actively used in a URL Filtering rule. To delete a category, deselect it in the URL Filtering rule.
You can look up a URL or IP address's categorization by using Site Review or by looking up URLs in the ZIA Admin Portal. Since a single IP address is capable of running multiple hosts or applications, Zscaler does not typically place IP addresses into the predefined URL categories. However, if a SaaS or cloud provider dedicates an IP address or IP range to an application, the Zscaler service categorizes it. For example, 13.107.6.152/31 is used for Office 365 and is categorized as Professional Services and Office 365.
You can also use Web Insights and its filters to learn more about how URL categories are being used in your network.
Custom Categories
In addition to the predefined categories, you can create custom categories. Custom categories can be based on URLs or IP addresses, keywords, and IP ranges. With URLs or IP addresses, you can block specific websites. With IP ranges, you can block a specific range of IP addresses for websites. With keywords, you can block websites based on any words that may appear in a URL. For example, imagine you want to block all websites with the term "gambling" in the URL. If you create a category with the custom keyword "gambling" and use it in a policy set to Block, websites such as www.gambling.com and www.gambling101.com are blocked. As custom keywords are applicable to the entire URI, if you went to www.google.com and searched for "gambling" the search results would also be blocked since the word gambling appears in the URI (https://www.google.com/search?q=gambling&oq=gambling&aqs=chrome..69i57j0l4.2767j0j8&sourceid=chrome&ie=UTF-8). You can also add custom URLs and keywords to a predefined URL category.
You can add up to 25K custom URLs or IP addresses (across all policies that use custom URLs or IP addresses), and up to 64 custom categories. You can add up to 256 keywords per category, and up to 2,048 across all categories. You can add up to 2,048 custom IP ranges (across all policies that use custom IP ranges). To learn more, see Ranges & Limitations.
You can also control who creates and manages custom URL categories. You might want to do this if, for example, you have dedicated personnel managing your custom URL categories, or if you would like to enable administrators in specific departments or locations to manage their own categories. These categories can only be managed by super admins, admins with the Custom URL Management role, or admins with the Custom URL Management and Override Existing URLs role. To learn more, see Adding Admin Roles.
When enforcing URL Filtering policy rules containing a wildcard, a Zscaler Internet Access (ZIA) Public Service Edge always looks for a specific match first. For example, you have Custom Category 1 containing the wildcard entries .example.com and .example.com/abc/, and Custom Category 2 containing abc.example.com and example.com/abc/def. Also, your URL Filtering policy rule states, "For Location X, block everything in Custom Category 1". In this example, if a user tries to access abc.example.com or example.com/abc/def from Location X, they won't be blocked because those exact domain names are in Custom Category 2, which is not blocked.
Changing Categorization
If you think that a website has been incorrectly categorized, there are three ways to request its re-categorization.
- Submit a change request Support ticket.
- Use Site Review to look up a URL, then select the Modify Categories option. This service is available for all users going through the Zscaler service. To learn more, see Using Site Review to Lookup URLs.
- Submit a review of a URL from the End User Notification.
About the URL Categories Page
On the URL Categories page (Administration > URL Categories), you can do the following:
- See the maximum limit of custom URLs or TLDs that are allowed and the number of custom URLs or TLDs used in your policies. For a complete list of ranges and limits per feature, see Ranges & Limitations.
- See the number of Predefined and Custom URL categories that are available.
The count of the Predefined and Custom URL categories dynamically changes based on the number of URL categories that match the search term.
- Configure a Custom URL category.
- Expand or collapse all URL categories.
- Filter the URL categories based on the following filters:
- URL: Select this filter to view the list of URL categories that contain the matching term in the No. of Custom URLs or No. of URLs Retaining Parent Category field.
- Keyword: Select this filter to view the list of URL categories that contain the matching term in the No. of Custom Keywords or No. of Keywords Retaining Parent Category field.
- URL Category Name: Select this filter to view the list of URL categories that contain the matching term in the Name field.
- All: Select this filter to view the list of URL categories that contain the matching term in any of the fields.
- IP Ranges: Select this filter to view the list of URL categories that contain the matching term in the No. of Custom IP Ranges or No. of IP Ranges Retaining Parent Category field.
- Search for a term.
The search term must contain at least 3 characters.
- View a list of all configured URL categories. For each URL category, you can view the following information:
- Name: The name of the URL category listed under the respective super category.
- No. of Custom URLs: The number of custom URLs or IP addresses in the category.
- No. of URLs Retaining Parent Category: The number of URLs or IP addresses that retain their parent category.
The Custom URLs and URLs Retaining Parent Category fields support IPv6 addresses.
- No. of Custom Keywords: The number of custom keywords in the category.
- No. of Keywords Retaining Parent Category: The number of keywords that retain their parent category.
- No. of Custom IP Ranges: The number of custom IP ranges in the category.
- No. of IP Ranges Retaining Parent Category: The number of IP ranges that retain their parent category.
The number under each column displays up to 20 values when you click it. You can view the complete list of values in the edit mode of the URL category page.
- Add a URL category under the super category.
- Edit a predefined URL category.
