Security Architecture Overview: cloudflare.com
Cloudflare is a global leader in web security, DDoS mitigation, and edge compute. Cloudflare.com features strict DMARC p=reject with strict alignment (aspf=s, adkim=s), DNSSEC signing, and post-quantum cryptography support.
Key Anti-Spoofing & Cryptographic Highlights
Frequently Asked Questions
What makes Cloudflare's DMARC policy unique?
Cloudflare enforces strict alignment (aspf=s and adkim=s), which requires exact domain matching rather than relaxed subdomain matching.
What is DMARC strict alignment (aspf=s, adkim=s)?
Strict alignment means the domain in the From: header must exactly match the SPF envelope sender domain and the DKIM d= tag — no subdomain inheritance is allowed. Relaxed alignment (the default) permits subdomain matches like mail.cloudflare.com for a From: cloudflare.com message. Strict mode eliminates this flexibility.
Does cloudflare.com support DNSSEC?
Yes. Cloudflare.com enables DNSSEC (Domain Name System Security Extensions) on its authoritative nameservers, adding cryptographic signatures to DNS responses. This prevents DNS cache poisoning attacks where an attacker substitutes legitimate DNS records with fraudulent entries.
What is TLS 1.3 Zero-RTT and does cloudflare.com use it?
Zero Round-Trip Time (0-RTT) resumption is a TLS 1.3 feature that allows returning visitors to resume encrypted sessions without a full handshake, reducing latency to near-zero for repeat connections. Cloudflare supports 0-RTT across all its edge nodes, including cloudflare.com itself.
What SSL certificate type does cloudflare.com use?
Cloudflare.com uses ECC (Elliptic Curve Cryptography) certificates issued by Cloudflare Inc ECC CA-3. ECC keys at P-256 provide security equivalent to RSA-3072 at dramatically smaller key sizes, enabling faster TLS handshakes globally.
How does Cloudflare protect its own domain from DDoS?
Cloudflare.com is protected by Cloudflare's own Magic Transit and DDoS mitigation infrastructure — a recursive case of eating their own dog food. All traffic is scrubbed at the Anycast edge before reaching origin, with automatic traffic diversion for volumetric attack mitigation.