DDoS Protection

What is it?

DDoS (Distributed Denial-of-Service) protection defends websites and networks against attacks that try to overwhelm them with fake traffic, making them unreachable for legitimate users. Cloudflare provides DDoS protection at every layer of the network stack (L3, L4, and L7) — and it's included free on every plan, including the free tier.

What problem does it solve?

A DDoS attack is like thousands of people trying to cram through a single doorway at once — nobody gets through. These attacks can:

  • Take entire websites offline for hours or days.
  • Cost businesses millions in lost revenue and recovery.
  • Be launched cheaply — attack-for-hire services cost as little as $10/hour.
  • Scale massively — modern attacks can exceed 1 Tbps (terabit per second).

Without DDoS protection, even large organizations can be knocked offline.

How does it work?

Cloudflare's DDoS protection works at three layers:

  1. L3/L4 (Network layer): Absorbs volumetric attacks (massive floods of packets) using the sheer capacity of Cloudflare's 300+ Tbps global network. Every data center can mitigate attacks — there's no single "scrubbing center" bottleneck.

  2. L7 (Application layer): Detects and blocks more sophisticated attacks that look like legitimate HTTP requests but come in at overwhelming volumes. Cloudflare uses machine learning and fingerprinting to distinguish real users from attack traffic.

  3. Autonomous mitigation: Cloudflare doesn't require human intervention. Its systems detect and mitigate attacks automatically, typically within seconds, at the edge — before attack traffic ever reaches the customer's origin server.

Key stats:

  • Cloudflare mitigates one of the largest volumes of DDoS attacks in the world.
  • Average time to mitigate: under 3 seconds.
  • No extra charge — DDoS protection is "unmetered," meaning customers aren't penalized for being attacked.

Why it matters strategically

DDoS protection is a table-stakes product that every serious internet property needs. By offering it free and unlimited on every plan, Cloudflare uses DDoS protection as a powerful land motion — it brings customers onto the platform. Once they're protected, they discover and adopt paid products (WAF, Bot Management, etc.). It also demonstrates the power of Cloudflare's network, which is the company's core competitive moat.

Learn more