Cloudflare Best Practice

Minimum TLS 1.2 https://developers.cloudflare.com/ssl/edge-certificates/additional-options/minimum-tls/

Enable CSAM Scanning Tool

Enable HSTS

Set Up Always Online

Enable HTTPS Enforcement

Enable DNSSEC for Record Integrity

Turn On HTTP/3 (QUIC) Support

Set Security Level to Medium

Implement Rate Limiting

Enabled HSTS

Block traffic from the Tor network

  1. Go to the Cloudflare dashboard.
  2. Expand the Security section.
  3. Select WAF.
  4. Select Create rule.
  5. For Rule name, enter a relevant name.
  6. For If incoming requests match, for Field, select Continent.
  7. For Operator, select equals.
  8. For Value, select Tor.
  9. For Then take action, select Block.
  10. For Place at, select First.
  11. Select Deploy.
Screenshot of the create rule dialog.

Bot protection

  1. Go to the Cloudflare dashboard.
  2. Expand the Security section.
  3. Under Configure Super Bot Fight Mode, for Definitely automated, select Block.
  4. For Likely automated, select Managed Challenge.
  5. For Verified bots, select Allow.
(No Ratings Yet)