Do the firewall rules work only for the records that has proxy status enabled or do they work for the entire domain regardless of proxy status?

Firewall rules only work for proxied records because the DNS server itself does not receive the real IP address of visitors (so it couldn’t reliably block IPs or geolocate them).

