If you use domain based policy, the domain need to be solved locally. So it cannot resolve your private domain.