Allowing sub domains

Trying to create a rule to allow cdn’s to load for tiktok.

They seem to be something random like tiktokcdn. Dot us or something.someone.tiktokcdn dor com

Etc.

How can i do a .tiktokcdn dot com gateway policy to allow traffic matching tiktok?