Here's the map for today β then we're 100% live in the dashboard
One network instead of five vendors. Nothing reaches your infrastructure until it's actually safe to.
π
Visitorbrowser / API client
β
β
request / response
Cloudflare Network
One network β DNS, encryption, and security checks all happen here, before traffic ever reaches you
β
β
only if it's safe to
π₯οΈ
Your Originweb app / API
DNS Onboarding
Two ways onto Cloudflare
The difference is whether Cloudflare becomes your authoritative DNS provider β the system that holds the real, final answer for every query about your domain β or just proxies specific hostnames while someone else stays authoritative.
Most common
Full (Primary) Setup
Cloudflare becomes your authoritative DNS provider
Change nameservers at your registrar β one-time step
Manage all DNS records in Cloudflare going forward
DNS-layer DDoS protection included (Cloudflare sees all query traffic)
Available on every plan, including Free
Business/Enterprise only
CNAME (Partial) Setup
Keep your existing authoritative DNS provider
No nameserver change β add CNAME records instead
Only the specific hostnames you point get proxied
No DNS-layer DDoS protection β Cloudflare isn't authoritative
Apex domain needs CNAME flattening support from your provider
π‘ Most customers go Full Setup: full protection, one place to manage DNS, zero ongoing coordination with a second provider.
FullEncrypted end-to-end, origin cert not validated
Full (strict)Encrypted end-to-end, origin cert cryptographically validated
π‘ "Encrypted" alone isn't a compliance answer. Full (strict) is the difference between encrypted and actually verified end-to-end β the posture auditors and regulated data actually require.
βοΈRemote Code ExecutionAttempts to run arbitrary code on your server
Managed RulesCloudflare-maintained, covers known CVEs and OWASP Top 10 patterns β updated continuously, no effort from you
Custom RulesYour own logic β specific paths, headers, or business rules unique to your application
π‘ The real question isn't "can we block this" β it's the cost of one breach or one hour of downtime versus the cost of the control that prevents it.
Every request gets scored 1-99. The action taken depends on where it lands β not a binary allow/block.
1Block Definite bot
2-29Challenge Likely bot β not blocked outright
30-99Allow Likely human
π‘ The gray zone gets challenged, not blocked β so you're not losing real customers to false positives while still shutting the door on automated abuse.
Cloudflare NetworkAbsorbed & filtered at the edge, globally distributed
β
Your OriginNever sees the attack traffic at all
ποΈ Under Attack Mode β a manual dial for the application layer during an active incident: adds an extra interstitial check for every visitor. Not the first line of defense β the always-on network layer is.
π‘ Uptime matters most during the exact moment it's hardest to guarantee β an active attack, not a normal Tuesday. That's precisely when this stays passive and automatic.