MyFortiPage MyFortiPage DE Free Consultation
Security

DDoS protection for business websites: what Cloudflare protects – and what it doesn’t

Cloudflare is part of every website package I offer. Even so, the service isn’t all-round protection. In this article, I explain what a DDoS attack is, what Cloudflare can intercept and which additional security measures are needed.

The short answer: Cloudflare sits as an intermediary between visitors and your server – provided the traffic is actually routed through Cloudflare. The service can intercept a large part of attack traffic before it reaches your server and also provides HTTPS, caching and firewall rules.

It does not protect against outdated software, weak passwords, a poorly secured server or missing backups, among other things. DDoS protection is an important building block, but it doesn’t replace updates and secure access.

What is a DDoS attack?

In a DDoS attack (Distributed Denial of Service), a very large number of devices send requests to a website at the same time. These are often hijacked computers or devices joined together in a so-called botnet. The goal: to overload the server so that the website becomes slow or unreachable.

Put simply, there are two types:

  • Network-level floods: a huge amount of traffic is meant to clog the connection.
  • Application-level attacks: many seemingly normal page requests are meant to overload the server.

It isn’t only large companies that can be affected. Many attacks and unwanted requests are automated and also hit smaller websites.

How Cloudflare works

Without Cloudflare, visitors reach your server directly. With Cloudflare, traffic first passes through Cloudflare’s network:

  1. A visitor opens your website.
  2. The request reaches Cloudflare instead of going directly to your server.
  3. Cloudflare checks the request and filters out suspicious traffic.
  4. Cloudflare delivers cached content directly and forwards all other requests to your server.

According to the Cloudflare documentation, DDoS protection is included in all plans, including the free one. Further features such as advanced firewall rules are available depending on the plan.

Using Cloudflare only as a DNS provider is not enough

The protection described only applies to traffic that is routed through Cloudflare. In the dashboard, such DNS records are marked as “Proxied”, recognisable by the orange cloud. If a record is set to “DNS only”, requests reach your server directly and without this protection. Cloudflare also recommends not using DNS-only records that reveal your server’s address. Learn more in Cloudflare’s guide to protecting your origin server.

Simulated illustration of typical attack paths – not real-time data. You can rotate the globe with your mouse or finger.

What Cloudflare protects

  • Large floods of traffic: attack traffic is intercepted in Cloudflare’s network before it reaches your server.
  • Suspicious requests: firewall rules can restrict access, for example to login areas or from certain regions.
  • Encryption: the connection between visitors and Cloudflare runs over HTTPS.
  • Relief: cached content such as images or stylesheets doesn’t have to be loaded from your server on every request.

What Cloudflare doesn’t protect

Cloudflare filters traffic. It doesn’t solve problems that lie in your website, your server or your access credentials:

Typical risks that DDoS protection alone doesn’t cover.
RiskWhy Cloudflare isn’t enoughWhat helps
Outdated softwaresecurity holes are in the website itselfregular updates of the system and extensions
Weak passwordsa login with real credentials looks inconspicuousstrong passwords, two-factor login, lockout after failed attempts
Direct server accessif the server address is known, Cloudflare can be bypassedonly allow connections from Cloudflare to the server
Unencrypted route to the serverin “Flexible” mode, only the route to the visitor is encryptedSSL mode “Full (strict)” with a valid certificate
Data lossCloudflare doesn’t store backups of your websiteregular backups in a separate location
Email abuseemails don’t pass through the website protectionset up SPF, DKIM and DMARC

Cloudflare explains how the encryption modes work in detail in its documentation on SSL modes.

DDoS protection is one building block

A website is only well secured when several measures work together: protection against overload, up-to-date software, secure access, encryption and backups.

Examples from my work

On my own website, myfortipage.de, traffic runs through Cloudflare, and requests via unencrypted HTTP are automatically redirected to HTTPS.

The staublos Gebäudereinigung project shows how important security within the website is. There, measures that Cloudflare can’t take over provide protection:

  • The admin area temporarily blocks logins after several failed attempts.
  • Passwords are not stored in plain text, but as a hash.
  • Forms in the admin area are protected against forged requests.
  • The access key for the AI chatbot stays on the server and never reaches the browser.
  • The number of chat requests per time period is limited.

Checklist: is your website secured?

  • The website is only reachable via HTTPS.
  • Cloudflare’s SSL mode is set to “Full (strict)”.
  • The website’s DNS records are routed through Cloudflare (“Proxied”), and no DNS-only record reveals the server address.
  • The server only accepts website requests via Cloudflare.
  • The system and extensions are updated regularly.
  • Access is protected with strong passwords and, where possible, two-factor login.
  • The login area is additionally secured.
  • There are regular backups in a separate location.
  • Security headers are set.
  • SPF, DKIM and DMARC are set up for your email domain.

The free website check covers several of these points, including HTTPS, the SSL certificate, selected security headers as well as SPF and DMARC. It doesn’t replace a full security audit, though.

Questions about this article?I’ll answer you personally – free and non-binding.

Ask a question

FAQ

Questions about DDoS protection and Cloudflare

Is Cloudflare free?
Cloudflare offers a free plan which, according to the provider, already includes DDoS protection. Advanced features are paid. Whether you need them and what costs arise, we agree in advance.
Does Cloudflare make my website slower?
Usually not. Thanks to caching, content can even be delivered faster. A suitable setup is important so that, for example, changes become visible reliably.
Does Cloudflare protect against hackers?
Partly. Cloudflare can filter suspicious traffic and restrict access. Security holes in the website, weak passwords or an unprotected server are not fixed by it.
Do I need DDoS protection for a small website too?
Smaller websites also receive automated and unwanted requests. With me, DDoS protection via Cloudflare is included in every website package, together with SSL encryption.
Is my website completely secure with Cloudflare?
No. The measures reduce certain risks. Regular updates and securing the website, server and access remain necessary.

Free & non-binding

How well is your website protected?

Send me your website address and tell me which hosting you use. Together we clarify which protective measures make sense.

Request website security
MyFortiPage AI Assistant AI · instant replies

👋 Hello! I’m the MyFortiPage AI assistant — you’re chatting with an artificial intelligence. I can answer all your questions about our website packages, services and pricing.

How can I help you?