All services / Security / DDoS Protection
๐ŸŒŠ
Security

DDoS Protection

Absorb the largest DDoSDDoSDistributed Denial of Service โ€” an attack that floods a site with junk traffic from many sources to knock it offline. attacks at the edgethe edgeโ€œThe edgeโ€ means Cloudflare's servers spread across the world, close to your users โ€” as opposed to one central data center., automatically and unmetered, so your originoriginYour own web server or host where your website actually lives. Cloudflare sits in front of it. never feels them.

What it is

Cloudflare sits in front of your application and absorbs DDoSDDoSDistributed Denial of Service โ€” an attack that floods a site with junk traffic from many sources to knock it offline. attacks across a network with hundreds of Tbps of capacity. Always-on, Cloudflare-managed rulesetsmanaged rulesetA set of security rules that Cloudflare writes and keeps up to date for you, so you don't have to maintain them. detect and mitigate both network-layerL3/4Layers 3 and 4 โ€” the Internet's โ€œplumbingโ€ layers, where raw volumetric network floods happen. (L3/4) and application-layerL7Layer 7 โ€” the application (HTTP) layer, where smart, web-specific attacks happen. (L7) floods automatically โ€” with unmetered mitigation on every plan.

Why it helps the client

  • Automatic, always-on mitigation โ€” attacks are stopped at the edge before reaching origin.
  • Unmetered protection โ€” you're never billed more for being attacked.
  • Coverage across all layers, from volumetric network floods to sophisticated HTTP attacks.
  • Tunable sensitivity and actions so legitimate traffic keeps flowing.

Why they'd want it

  • Confidence that a headline-grabbing attack won't take them offline.
  • No emergency scaling scramble or surprise bills during an attack.
  • Protection that's on by default, backed by one of the world's largest networks.

๐Ÿ”ฌ How it actually works

  • Protection is always-on and automatic across L3/4L3/4Layers 3 and 4 โ€” the Internet's โ€œplumbingโ€ layers, where raw volumetric network floods happen. (network floods) and L7L7Layer 7 โ€” the application (HTTP) layer, where smart, web-specific attacks happen. (HTTP floods). Attack traffic is absorbed at the edgethe edgeโ€œThe edgeโ€ means Cloudflare's servers spread across the world, close to your users โ€” as opposed to one central data center. across a network with hundreds of Tbps of capacity, dispersed over many data centers instead of hitting a single chokepoint.
  • Cloudflare-managed DDoSDDoSDistributed Denial of Service โ€” an attack that floods a site with junk traffic from many sources to knock it offline. rulesets fingerprint attack traffic in real time. L3/4L3/4Layers 3 and 4 โ€” the Internet's โ€œplumbingโ€ layers, where raw volumetric network floods happen. mitigation is fully automatic; the HTTP DDoS ruleset can be tuned for sensitivity and action (block vs managed challenge).
  • Mitigation is unmetered on every plan โ€” you're never billed more for being attacked โ€” and there's no 'reroute to a scrubbing center' delay because every PoPPoPPoint of Presence โ€” a physical Cloudflare data center location where our servers process traffic. More PoPs means we're closer to more users. is a scrubbing center.
  • Adaptive DDoSDDoSDistributed Denial of Service โ€” an attack that floods a site with junk traffic from many sources to knock it offline. protection learns your normal traffic profile to spot app-specific anomalies, and Advanced TCP Protection defends against stateful / state-exhaustion attacks.

๐Ÿ“– Key terms on this page hover any underlined term anywhere on the site for its definition

the edge
โ€œThe edgeโ€ means Cloudflare's servers spread across the world, close to your users โ€” as opposed to one central data center.
DDoS
Distributed Denial of Service โ€” an attack that floods a site with junk traffic from many sources to knock it offline.
origin
Your own web server or host where your website actually lives. Cloudflare sits in front of it.
managed ruleset
A set of security rules that Cloudflare writes and keeps up to date for you, so you don't have to maintain them.
L3/4
Layers 3 and 4 โ€” the Internet's โ€œplumbingโ€ layers, where raw volumetric network floods happen.
L7
Layer 7 โ€” the application (HTTP) layer, where smart, web-specific attacks happen.
PoP
Point of Presence โ€” a physical Cloudflare data center location where our servers process traffic. More PoPs means we're closer to more users.

Live demo walkthrough

5 steps

Screens below are annotated recreations of the Cloudflare dashboard. The numbered orange pin marks exactly where to click.

1

Select the website

๐Ÿ‘† Account Home โ†’ example.com
๐Ÿ”’dash.cloudflare.com

๐Ÿ‘‰ Do this

Open the site you want to protect.

๐Ÿ’ฌ Say this

โ€œDDoS protection turns on the instant traffic is proxied through Cloudflare. Let me show where the controls live.โ€

2

Open Security โ†’ DDoS

๐Ÿ‘† Left nav โ†’ Security โ†’ DDoS
๐Ÿ”’dash.cloudflare.com/example.com/security/ddos
example.com โ–พ
Test Account NickN

Security

DDoS

HTTP DDoS Attack ProtectionAlways-on, Cloudflare-managed ruleset that mitigates L7 floods automatically.
Enabled
Ruleset actionAction taken when an attack signature matches.
Managed challenge
Ruleset sensitivityHow aggressively attack traffic is flagged.
High
Network-layer (L3/4) DDoSAutomatic protection for all Cloudflare-proxied traffic.
Always on

๐Ÿ‘‰ Do this

Expand Security and click DDoS.

๐Ÿ’ฌ Say this

โ€œHere's the DDoS protection surface. Notice it's already enabled โ€” there's nothing to switch on and no attack size you need to plan capacity for.โ€

3

Review the managed ruleset

๐Ÿ‘† DDoS โ†’ HTTP DDoS Attack Protection โ†’ Configure
๐Ÿ”’dash.cloudflare.com/example.com/security/ddos
example.com โ–พ
Test Account NickN

Security

DDoS

HTTP DDoS Attack ProtectionAlways-on, Cloudflare-managed ruleset that mitigates L7 floods automatically.
Enabled
Ruleset actionAction taken when an attack signature matches.
Managed challenge
Ruleset sensitivityHow aggressively attack traffic is flagged.
High
Network-layer (L3/4) DDoSAutomatic protection for all Cloudflare-proxied traffic.
Always on

๐Ÿ‘‰ Do this

Click Configure on the HTTP DDoS Attack Protection ruleset.

๐Ÿ’ฌ Say this

โ€œThe HTTP DDoS managed ruleset is operated by Cloudflare and always on. We can tune sensitivity and the action it takes, but most customers never need to touch it โ€” network-layer L3/4 protection is fully automatic.โ€

4

Adjust sensitivity if needed

๐Ÿ‘† DDoS โ†’ HTTP DDoS ruleset โ†’ Sensitivity
๐Ÿ”’dash.cloudflare.com/example.com/security/ddos
example.com โ–พ
Test Account NickN

Security

DDoS

HTTP DDoS Attack ProtectionAlways-on, Cloudflare-managed ruleset that mitigates L7 floods automatically.
Enabled
Ruleset actionAction taken when an attack signature matches.
Managed challenge
Ruleset sensitivityHow aggressively attack traffic is flagged.
High4
Network-layer (L3/4) DDoSAutomatic protection for all Cloudflare-proxied traffic.
Always on

๐Ÿ‘‰ Do this

Point to the sensitivity and action controls (Essentially Off / Low / Medium / High).

๐Ÿ’ฌ Say this

โ€œThe only knobs most teams ever touch: sensitivity and action. If a legitimate traffic spike ever looks attack-shaped, we dial sensitivity down or switch the action to a challenge instead of a block โ€” all without opening a support ticket.โ€

5

Show mitigations in Events

๐Ÿ‘† Left nav โ†’ Security โ†’ Events
๐Ÿ”’dash.cloudflare.com/example.com/security/events
example.com โ–พ
Test Account NickN

Security

Events

Add filter โ–พ5
Sampled logs
ActionServiceHostSource IPRule
BlockWAFexample.com203.0.113.9SQLi โ€“ Managed
BlockRate limitingapi.example.com198.51.100.2Login throttle
Managed challengeBot Managementexample.com192.0.2.44Score < 30
BlockAPI Shieldapi.example.com203.0.113.5Schema violation
BlockWAFexample.com203.0.113.77XSS โ€“ Managed

๐Ÿ‘‰ Do this

Open Events to show real, mitigated attack traffic.

๐Ÿ’ฌ Say this

โ€œAnd every mitigation is fully visible in Security Events with source, service, and rule โ€” great for the post-incident report that proves the attack never reached the origin.โ€

Questions clients ask

Tap a question to reveal the answer to say
What size attack can you actually stop?โ€บ
Cloudflare has mitigated some of the largest attacks ever recorded โ€” tens of millions of requests per second and multi-Tbps floods. Capacity is hundreds of Tbps, well above any single attack to date, and it's shared automatic protection, not a per-customer box.
Will we be billed more during an attack?โ€บ
No. DDoSDDoSDistributed Denial of Service โ€” an attack that floods a site with junk traffic from many sources to knock it offline. mitigation is unmetered on all plans. Not paying a penalty for being targeted is a core promise.
Does mitigation slow down real users?โ€บ
Negligibly. Protection runs inline at the PoPPoPPoint of Presence โ€” a physical Cloudflare data center location where our servers process traffic. More PoPs means we're closer to more users. the user already hits, so there's no rerouting to a distant scrubbing center like legacy on-demand DDoSDDoSDistributed Denial of Service โ€” an attack that floods a site with junk traffic from many sources to knock it offline. services.
Do we have to do anything during an attack?โ€บ
Usually nothing โ€” it's automatic. For sophisticated L7L7Layer 7 โ€” the application (HTTP) layer, where smart, web-specific attacks happen. attacks you can raise sensitivity or add a rule, and Security Events show what's being mitigated in real time.
Are we covered at both the network and application layers?โ€บ
Yes โ€” network-layerL3/4Layers 3 and 4 โ€” the Internet's โ€œplumbingโ€ layers, where raw volumetric network floods happen. floods are handled automatically; application-layerL7Layer 7 โ€” the application (HTTP) layer, where smart, web-specific attacks happen. HTTP floods are handled by a tunable managed rulesetmanaged rulesetA set of security rules that Cloudflare writes and keeps up to date for you, so you don't have to maintain them.. Magic Transit and Spectrum extend this to whole networks and non-HTTP services.