
A Netlify user received a $104,000 bill β from a single DDoS attack. Cloudflare offers free protection with unlimited bandwidth. Setup in 20 minutes, no code required.
The problem: Pay-per-use and DDoS
A Netlify user received a bill for $104,000 in 2024 β caused by a single DDoS attack. Netlify charges for bandwidth above the free tier, and during an attack this can scale to enormous amounts within hours.
Most modern hosting platforms charge by usage. Vercel, Netlify, AWS, Google Cloud β all have free tiers, then the meter starts running. This works fine as long as traffic is legitimate.
Pay-per-Use Hosting + DDoS-Angriff
Botnet (100.000 Anfragen/Sek.)
β
βΌ
Hosting-Anbieter (Netlify / Vercel / AWS)
β
βββ Bandbreite: ββββββββββββββββ Limit ΓΌberschritten
βββ Requests: ββββββββββββββββ Limit ΓΌberschritten
βββ Rechnung: $104.000 πΈIn a DDoS attack, thousands of compromised systems send requests simultaneously. And the insidious part: you don't need to be a big target. Attackers test their botnets, or someone simply hit the wrong IP. Even small websites can be affected.
How Cloudflare protects you
Cloudflare sits as a proxy between the internet and your actual server. All traffic first passes through Cloudflare's network β where it is filtered. Attack traffic is absorbed before it reaches the hosting provider.
Mit Cloudflare als Proxy
Internet-Traffic
β
βΌ
βββββββββββββββββββββββββββ
β Cloudflare Edge β β DDoS-Filterung hier
β 300+ Rechenzentren β β Angriff wird absorbiert
β unbegrenzte Bandbreiteβ
ββββββββββββββ¬βββββββββββββ
β nur legitimer Traffic
βΌ
Hosting-Anbieter (Netlify / Railway / Server)
β
βββ Rechnung: normal β- DDoS protection is included in the free plan β with no bandwidth limit
- Cloudflare's network spans over 300 data centers worldwide
- Attack traffic is absorbed before it reaches the hosting provider
- Netlify, Vercel or your own server only sees filtered, legitimate traffic
Setup β Step 1: Account and domain
The setup requires no code. DNS changes at the domain registrar are all that's needed.
Cloudflare Free: no credit card required, no automatic upgrades. The free plan includes full DDoS protection and unlimited bandwidth.
1. cloudflare.com β Account erstellen (kostenlos)
2. "Add a Site" β Domain eingeben
3. Free Plan auswΓ€hlen
4. Cloudflare importiert bestehende DNS-EintrΓ€ge automatischSetup β Step 2: Change nameservers
After import, Cloudflare provides two nameservers. These are entered at the domain registrar. Existing DNS records remain intact β Cloudflare imported them automatically.
# Cloudflare zeigt zwei Nameserver an, z.B.:
aria.ns.cloudflare.com
bob.ns.cloudflare.com
# Diese beim Registrar eintragen:
# Strato: Domain-Verwaltung β Nameserver β Benutzerdefinierte NS
# IONOS: Domains β DNS β Nameserver Γ€ndern
# GoDaddy: My Domains β DNS β NameserverThe change takes up to 24 hours, but usually takes effect within 1β2 hours. Cloudflare shows the status in the dashboard.
Setup β Step 3: Enable proxy
In Cloudflare's DNS management, each record shows a cloud icon. Orange means traffic passes through Cloudflare. Grey means direct pass-through, no proxy.
Cloudflare DNS-Verwaltung: Typ Name Wert Proxy ββββββββββββββββββββββββββββββββββββββββββββββββ A @ 75.2.60.5 (Netlify) π aktiv β DDoS-Schutz CNAME www apex-loadbalancer.net... π aktiv β DDoS-Schutz MX @ aspmx.l.google.com βͺ grau β E-Mail, kein Proxy! TXT @ v=spf1 ... βͺ grau β SPF, kein Proxy
Important: always leave mail records (MX, DKIM, SPF, DMARC) grey. Email traffic must not go through the HTTP proxy.
Setup β Step 4: Configure SSL/TLS
Cloudflare mediates between visitors and the hosting provider. The SSL/TLS mode determines how these connections are encrypted.
Cloudflare β SSL/TLS β Overview
[ ] Off β kein HTTPS
[ ] Flexible β nur Cloudflare β Besucher verschlΓΌsselt β
[x] Full β Ende-zu-Ende verschlΓΌsselt
[x] Full (strict) β Ende-zu-Ende + Zertifikat muss gΓΌltig sein β
β Empfehlung: Full (strict)
(Netlify und Vercel haben immer gΓΌltige Zertifikate)What else Cloudflare offers (free)
Beyond DDoS protection, the free plan brings additional benefits:
- Caching: static assets are cached at Cloudflare's edge β faster loading times worldwide
- Bot protection: basic bot detection and filtering without configuration
- Analytics: traffic overview without cookies or GDPR issues
- Page Rules: redirects and cache rules per URL
- Rate Limiting (paid): limit requests per IP for additional protection
Cloudflare is not a hosting provider. It doesn't replace Netlify, Railway or your own server β it sits in front of them. For business-critical applications with SLA requirements, Pro or Business plans are relevant.
Securing the hosting provider directly
For additional security: most server setups allow accepting incoming traffic only from Cloudflare's IP ranges. This prevents any attacker from reaching the hosting provider directly, even if they know the real IP.
# Netlify: nur Cloudflare-IPs erlauben
# β In Netlify gibt es aktuell keine IP-Whitelist fΓΌr den Ingress.
# Stattdessen: Origin-Anfragen ΓΌber einen eigenen Server (z.B. Railway)
# absichern, der nur Cloudflare-IPs akzeptiert.
# FΓΌr eigene Server (nginx-Beispiel):
# Cloudflare IP-Ranges: https://www.cloudflare.com/ips/
# /etc/nginx/conf.d/cloudflare-only.conf
allow 173.245.48.0/20;
allow 103.21.244.0/22;
allow 103.22.200.0/22;
# [alle Cloudflare IP-Ranges]
deny all;Cloudflare publishes all current IP ranges at cloudflare.com/ips β this list should be updated regularly.
Checklist: 20 minutes for lasting protection
For every publicly accessible website running on pay-per-use hosting:
- Create a Cloudflare account β free, no credit card required
- Add domain to Cloudflare β DNS import runs automatically
- Change nameservers at the registrar β approx. 15 minutes
- Enable proxy for all public records (orange cloud icon)
- Set SSL/TLS to 'Full (strict)'
The one-time setup takes about 20 minutes. The risk it covers is a five-figure invoice. The $104,000 bill was preventable.