The short answer: Cloudflare sits as an intermediary between visitors and your server – provided the traffic is actually routed through Cloudflare. The service can intercept a large part of attack traffic before it reaches your server and also provides HTTPS, caching and firewall rules.
It does not protect against outdated software, weak passwords, a poorly secured server or missing backups, among other things. DDoS protection is an important building block, but it doesn’t replace updates and secure access.
What is a DDoS attack?
In a DDoS attack (Distributed Denial of Service), a very large number of devices send requests to a website at the same time. These are often hijacked computers or devices joined together in a so-called botnet. The goal: to overload the server so that the website becomes slow or unreachable.
Put simply, there are two types:
- Network-level floods: a huge amount of traffic is meant to clog the connection.
- Application-level attacks: many seemingly normal page requests are meant to overload the server.
It isn’t only large companies that can be affected. Many attacks and unwanted requests are automated and also hit smaller websites.
How Cloudflare works
Without Cloudflare, visitors reach your server directly. With Cloudflare, traffic first passes through Cloudflare’s network:
- A visitor opens your website.
- The request reaches Cloudflare instead of going directly to your server.
- Cloudflare checks the request and filters out suspicious traffic.
- Cloudflare delivers cached content directly and forwards all other requests to your server.
According to the Cloudflare documentation, DDoS protection is included in all plans, including the free one. Further features such as advanced firewall rules are available depending on the plan.
The protection described only applies to traffic that is routed through Cloudflare. In the dashboard, such DNS records are marked as “Proxied”, recognisable by the orange cloud. If a record is set to “DNS only”, requests reach your server directly and without this protection. Cloudflare also recommends not using DNS-only records that reveal your server’s address. Learn more in Cloudflare’s guide to protecting your origin server.
What Cloudflare protects
- Large floods of traffic: attack traffic is intercepted in Cloudflare’s network before it reaches your server.
- Suspicious requests: firewall rules can restrict access, for example to login areas or from certain regions.
- Encryption: the connection between visitors and Cloudflare runs over HTTPS.
- Relief: cached content such as images or stylesheets doesn’t have to be loaded from your server on every request.
What Cloudflare doesn’t protect
Cloudflare filters traffic. It doesn’t solve problems that lie in your website, your server or your access credentials:
| Risk | Why Cloudflare isn’t enough | What helps |
|---|---|---|
| Outdated software | security holes are in the website itself | regular updates of the system and extensions |
| Weak passwords | a login with real credentials looks inconspicuous | strong passwords, two-factor login, lockout after failed attempts |
| Direct server access | if the server address is known, Cloudflare can be bypassed | only allow connections from Cloudflare to the server |
| Unencrypted route to the server | in “Flexible” mode, only the route to the visitor is encrypted | SSL mode “Full (strict)” with a valid certificate |
| Data loss | Cloudflare doesn’t store backups of your website | regular backups in a separate location |
| Email abuse | emails don’t pass through the website protection | set up SPF, DKIM and DMARC |
Cloudflare explains how the encryption modes work in detail in its documentation on SSL modes.
A website is only well secured when several measures work together: protection against overload, up-to-date software, secure access, encryption and backups.
Examples from my work
On my own website, myfortipage.de, traffic runs through Cloudflare, and requests via unencrypted HTTP are automatically redirected to HTTPS.
The staublos Gebäudereinigung project shows how important security within the website is. There, measures that Cloudflare can’t take over provide protection:
- The admin area temporarily blocks logins after several failed attempts.
- Passwords are not stored in plain text, but as a hash.
- Forms in the admin area are protected against forged requests.
- The access key for the AI chatbot stays on the server and never reaches the browser.
- The number of chat requests per time period is limited.
Checklist: is your website secured?
- The website is only reachable via HTTPS.
- Cloudflare’s SSL mode is set to “Full (strict)”.
- The website’s DNS records are routed through Cloudflare (“Proxied”), and no DNS-only record reveals the server address.
- The server only accepts website requests via Cloudflare.
- The system and extensions are updated regularly.
- Access is protected with strong passwords and, where possible, two-factor login.
- The login area is additionally secured.
- There are regular backups in a separate location.
- Security headers are set.
- SPF, DKIM and DMARC are set up for your email domain.
The free website check covers several of these points, including HTTPS, the SSL certificate, selected security headers as well as SPF and DMARC. It doesn’t replace a full security audit, though.