Ensuring only Cloudflare reaches your server.
WHAT IT DOES
Cloudflare presents a certificate when connecting to our server, and our server can be configured to accept only connections presenting it.
Traffic bypassing Cloudflare is then refused.
WHY IT IS USEFUL
It closes the gap where an attacker who learns the origin address sends traffic directly, bypassing every Cloudflare protection.
THE CAVEAT ON SHARED HOSTING
Configuring the origin side requires server-level changes that are not generally available on shared hosting.
Open a ticket and ask whether it can be arranged for your account.
WHAT YOU CAN DO WITHOUT IT
Review every DNS record and proxy everything serving web traffic Remove records you do not need Accept that mail hostnames must remain unproxied
THE HONEST POSITION
Complete origin protection is difficult on shared hosting, where the server address serves many sites and is discoverable.
Cloudflare's protection remains useful and is not absolute.
IF YOU ARE UNDER SUSTAINED DIRECT ATTACK
Tell us. We can apply server-side measures independent of Cloudflare.