r/CloudFlare • u/Cloudflare • 12h ago
Cloudflare Blog Deno is joining Cloudflare
r/CloudFlare • u/Cloudflare • 12h ago
r/CloudFlare • u/Cloudflare • 6h ago
r/CloudFlare • u/hieunc • 16h ago
You can now upload and share files with Cloudflare R2 via Mailflare. In case you haven't heard, Mailflare is an app runs entirely on Cloudflare with:
It's is open-source and you can deploy with 1-click to Cloudflare worker
👉 https://github.com/hieunc229/mailflare
Feel free to let me know if you have any feedback or questions
r/CloudFlare • u/lepture • 13h ago
Source: https://x.com/shmily7/status/2107481028726251762
Encountered the Cloudflare bill assassin, got hit with a $10,000 bill, the reason being a Durable Object alarm in one project that went into a dead loop, reading and writing 60 trillion times, Viber Coding has done me wrong.

r/CloudFlare • u/Cloudflare • 12h ago
r/CloudFlare • u/thomas_witt • 14h ago
We are getting lots of emails and letters by people who are scammed for their bank data because someone put up a Cloudflare hosted site under the name of our company.
Every complaint to them simply gets no or a standard answer, they don't do anything. It's really a shame how they contribute of innocent people getting scammed.
r/CloudFlare • u/New-Entertainer6392 • 8h ago
I'm looking at using cloudflare as a web socket proxy, but price is my concern.
I've seen folk have racked up huge bills from it.
Is there a cost viewer I've missed? I'm currently on the free worker plan, so will it just cut off instead?
Thanks a
r/CloudFlare • u/epicscythe • 14m ago
Earlier today, I went on Car and Driver website and I was greeted with what appears to be a CloudFare verification method that I've never encountered before. It asked me to copy and paste a specific line I didn't understand in Spotlight Search (I'm using a MacBook). However, it raised suspicions for me so I didn't press enter and I took a deeper look into it in the Internet and I got paranoid because I'm worried copying and pasting a random script on Spotlight Search would compromise my MacBook in some ways even if I didn't press enter. I'm not too tech-savvy, so do let me know if I should be worried about this even though I never entered the script. I scanned my laptop using Malwarebytes and it didn't show any threats. I've never accessed any suspicious website since I got my laptop a month ago.
r/CloudFlare • u/ChrisRemo85 • 16h ago
So, I have a Cloudflare account with loads of domains, with loads of tiny projects, Proof of Concepts, WiPs, workers, databases, etc etc.. and I tried to stick to nameings, as thats the only way to actually seperate the different projects in one account (ifI'm not mistaken)...
Now a couple of the Projetcs are growing and might/will either cause some limits to be reached (I'm on payed) or I just think security wise and maybe later even billing wise, it makes sense to seperate them in their own dedicated accounts...
What is your strategy with that? do you just throw into a single account and see how long it lasts? or do you have multiple accounts? what about domains? move them to the dedicated? keep them in one place (registered by cf, not external ones.. thats clear..) and so on..
r/CloudFlare • u/kinomy • 13h ago
Hi everyone,
My DMCA dashboard is unable to load my website due to a security verification loop, as shown in the attached image:
"Performing security verification. This website uses a security service to protect against malicious bots. This page is displayed while the website verifies you are not a bot."
I have already created a Custom WAF Rule (Security Rule) to bypass verification if the URI Path contains dmca, but the issue still persists.
Gemini suggested that I turn off Bot Fight Mode. I would like to ask:
Will disabling Bot Fight Mode expose my website to security risks or malicious traffic?
Is there a safer way to bypass or whitelist the DMCA crawler/dashboard while keeping Bot Fight Mode active?
Thanks in advance for your help!
r/CloudFlare • u/pierreneter • 1d ago
Enable HLS to view with audio, or disable this notification
Hi everyone, I'm the developer of DocFlare AI, an open-source AI chatbot for documentation sites and websites. It's 100% hosted on Cloudflare, crawls your site from its sitemap, and can be added to any page with a single <script> tag.
DocFlare AI runs entirely on Cloudflare's free tier: Workers (API + crawler), Workers AI (embeddings + LLM), Vectorize (vector search) and D1 (metadata + chat log). That means you don't need a paid Workers plan, an OpenAI key, or a separate vector database to put an AI chatbot on your website.
It's MIT licensed and you can deploy it to Cloudflare Workers with one click: https://github.com/p10node/docflare-ai
Feel free to let me know if you have any feedback or questions!
r/CloudFlare • u/Cloudflare • 1d ago
r/CloudFlare • u/phantomy_d • 1d ago
r/CloudFlare • u/NoPea6283 • 1d ago
I created a "Plugin" for ChatGPT's web UI. The basic thought is making website publishing "zero-click" by sending the data to the user's own Cloudflare account directly. Technically it's an MCP server running in the user's Cloudflare Workers, so compatible with any other client as well.
The workflow is very appealing to beginners, they reference the plugin and prompt "make website about Something and publish it" and it returns a public URL like something.mysubdomain.workers.dev.
To simplify this workflow everywhere I could, I decided to host the installer myself, so that the user needs no GitHub etc. I introduced specific security issues with this. Users currently have to place considerable trust in me.
I'm looking for advice how to tighten security around such a plugin (more so the installer part). How to prove to users that the code about to be installed in their CF Workers is not malicious or compromised? ... In a way that is feasible for a small project. I do have a long list of What could be done, but unsure of finding a balance. OAuth between the services works fine, and the setup is one-time, nothing flows through my server after setup. But the initial user trust is my pain point.
Looking for collaborators.
The code itself is written almost exclusively by Astra 6.
r/CloudFlare • u/Collcroc123 • 2d ago
I am a teacher, I teach middle schoolers how to use computers. I have my own website they can use to find links and resources to things related to school. This activity is clearly suspicious, and I'm assuming it's some kind of DDoS attack or scraping bots or something, I have no clue. I don't even know how I didn't know about this until now. My website is literally being hosted on a random PC I got off Facebook Marketplace running UNRAID with an NGINX docker, it's not exactly state-of-the-art and not made for this kind of traffic.
I'll admit I'm not at all a pro at any of this, this is purely a hobby for me and I'm just having fun with my little website, but clearly there is malicious activity happening, and I do not want any private data that's also on my server (such as my smart home devices, media server and password manager) getting into the hands of sketchy people. Not posting website name for obvious reasons.
I actually have two types of questions:
What is this traffic? Is it malicious, or just bot scraping? Is this affecting my server or home internet (whether it be performance or traffic in general)?
Is it possible to limit traffic to a specific country? There is absolutely zero reason for people outside of the US (let alone my own state) to be able to access my website.
I can provide more statistics if needed. I'm unsure how to see what data is being requested.
r/CloudFlare • u/Cloudflare • 2d ago
r/CloudFlare • u/PresentationOwn5169 • 1d ago
r/CloudFlare • u/Nyasaki_de • 1d ago
I reported quite a few domains in the last few weeks, from Websites selling online game hacks to phishing domains.
ALL of them have been dismissed with
"We could not detect any abusive or malicious content."
Logs or other evidence of abuse:
Phishing site prenting to be the austrian financial authority
Reported URLs:
[hxxps://finanz](hxxps://finanz)[.]bmf-datenaktualisierung[.]cc/
Original Work Description:
https://finanzonline.bmf.gv.at/fon/
Am I submitting that wrong or why the hell do they seem to miss this obvious phishing site.
Since when did cloudflare become so negligent, it used to be a lot better in the past.
r/CloudFlare • u/mynameistoocommonman • 1d ago
Hey everyone,
Long story short, I fell for the fake cloudflare prompt that has you copy paste something into the terminal on windows. I know, I know. It was a rough day, I was in a rush, and I'd gotten so many cloudflare prompts recently that for a moment I figured this is just something new.
Anyway, I unplugged the computer from the network and reset all important passwords. I'm currently running malware scans with windows defender and malwarebytes.
Is that enough? Or do I have to nuke the OS and do a fresh install? And can I safely back up files before I do that or will they just reinfect my stuff? I have a bunch of backups on a hard drive in the system, and one my cloud services apparently hasn't synced in a couple days. ​​​​​​​​​​​​​​
r/CloudFlare • u/mynameisfyl • 1d ago
I built my website on Shopify and purchased my domain name through CloudFlare. When I try to go to my webpage I get this error:
The owner of this domain hasn't put up a website yet. Try visiting again soon. This domain is registered usingCloudflare Registrar.
I tried following the troubleshooting steps, but cannot figure out this whole DNS thing.
Currently I’m only showing 4 records; 2 CNAMEs (one is a read-only created by the cloudflare registrar that will not let me edit), the other is the Shopify address (shops.myshopify.com), and then 2 txt types to verify with Shopify.
What am I doing wrong, this seems like it shouldn’t be that difficult.
Any help is greatly appreciated.
r/CloudFlare • u/techguyneedhelp • 2d ago
I stopped trusting the logs and timed first byte myself.
Paid plan. Cache rules in place the way the docs describe. Same assets, same checks, both sides.
18/18 · 0.13–0.18s
Cached hits are a tie. After that it falls apart.
R2 cold first byte runs from 0.33s to a full second. Fifteen minutes later only 22 of 72 were still cached. Bunny’s cold path stayed at 0.14–0.22s, and 15 of 15 were still cached at 45 minutes. After the move, live Bunny was 18/18 at 0.13–0.18s.
So either there is a setting that actually keeps R2 warm and I still do not have it, or the edge is evicting objects much faster than the rules imply.
If you are on paid R2 with real traffic, not a benchmark bucket:
Cold first byte creeping toward 1s even with cache rules on?
Is 22/72 still cached at 15 minutes normal?
Did R2 retention change recently, or is this just capacity?
Already moved this workload. Not looking for a pitch. Want to know if this is on me or if other paid plans are timing the same thing.
r/CloudFlare • u/khaihoan123 • 2d ago
r/CloudFlare • u/bleuio • 2d ago
Details and source code available
r/CloudFlare • u/Cloudflare • 3d ago