Cloudflare Docs
Support
Support
Visit Support on GitHub
Set theme to dark (⇧+D)

Understanding the Cloudflare Security Level

​​ Overview



​​ Understanding the Cloudflare Security Level

​​ Overview

Security Level uses the IP reputation of a visitor to decide whether to present a Managed Challenge page. Once the visitor enters the correct Managed Challenge, they receive the appropriate website resources. 

IP Reputation is calculated based on Project Honeypot, external public IP information, as well as internal threat intelligence from our WAF managed rules and DDoS.

Security LevelThreat ScoresDescription
Off (Enterprise customers only)N/ADoes not challenge IP addresses
Essentially offgreater than 49Only challenges IP addresses with the worst reputation
Lowgreater than 24Challenges only the most threatening visitors
Mediumgreater than 14Challenges both moderate threat visitors and the most threatening visitors
Highgreater than 0Challenges all visitors that exhibit threatening behavior within the last 14 days
I’m Under Attack!N/AOnly for use if your website is currently under a DDoS attack

Cloudflare sets Security Level to Medium by default.  Change the Security Level settings in Security > Settings. Also, the Threat Score values mentioned above are useful as Field criteria within firewall rules or custom rules. Security Level is also configurable via Cloudflare Page Rules.

To prevent bot IPs from attacking a website, a new website owner might set a Medium or High Security Level and lower  Challenge Passage 5 to 30 minutes to ensure that Cloudflare is constantly protecting the site.  Alternatively, an experienced website administrator that is confident in their security settings might set Security Level to Essentially Off or Low while setting a higher  Challenge Passage for a week, month, or even year to provide a less obtrusive visitor experience.

Only use  I’m Under Attack! mode when a website is under a DDoS attack.  I’m Under Attack! mode may affect some actions on your domain, such as your API traffic.  Set a custom Security Level for your API or any other part of your domain by creating a  Page Rule for that portion of your site traffic.