Traffic Forwarding: Destination Translation (D-NAT)

we have a brand new instance for one of our customers. As we just prepare it, we do not have any traffic - except for some tests.

Now I see several transactions in weblogs from unknown public IPs directed to the dedicated proxy port (according to location) that have “traffic forwarding” = “Destination Translation (D-NAT)”

Does anyone know, what “Destination Translation (D-NAT)” means in Zscaler context?
We have “pure ZIA” and we do not use Z-App, standard or NG Firewall. IPSec tunnels are not yet established.

