The Security level setting on your Cloudflare CDN page controls how aggressively Cloudflare challenges suspicious visitors before they reach your server. Higher settings show more visitors a challenge page (a brief "verify you're human" interstitial); lower settings let more traffic through unchecked. If real visitors are getting challenged, turn it down a notch. If you're under attack, turn it up.
This setting lives entirely in your Flashcloud portal, under Cloudflare CDN in the sidebar, on the per-domain settings for the domain you want to adjust. There's no separate cloudflare.com dashboard to log into: everything is managed from our portal.
What the security level actually does
Cloudflare scores every incoming request using signals like IP reputation, request patterns, and known bad actor lists. The security level decides how high that threat score has to be before a visitor sees a challenge instead of your site. The options range from least aggressive to most aggressive:
- Essentially off: the least aggressive option. Use this if you're seeing false positives on legitimate visitors and traffic is otherwise normal.
- Low, Medium and High sit in between; Medium is the default and a sensible choice for most sites.
- I'm under attack: a temporary setting for active DDoS or bot floods, not something to leave on permanently.
A related toggle, Under attack mode, does roughly the same thing as the "I'm under attack" security level and is meant for the same short-term use: flip it on when you're actively getting hammered, then flip it back off once traffic normalizes.
Picking the right level
Start at a middle setting and watch what happens. If you're getting reports of visitors seeing challenge pages on a normal day, or you notice a drop in form submissions or checkout completions that lines up with a security level change, step it down toward Essentially off. If you're seeing a spike in traffic that looks automated (identical requests hammering the same URL, traffic from a narrow band of IPs, a spike with no matching marketing push behind it) step it up or switch on Under attack mode until it settles.
This setting works alongside the rest of your Cloudflare configuration, not in isolation. If you haven't looked at the other toggles on that page (SSL/TLS mode, Always Use HTTPS, Automatic HTTPS Rewrites, the AI Crawlers panel, and so on), the full walkthrough is in Every Cloudflare setting explained.
Before you change it during an actual attack
If you're mid-attack and traffic is climbing fast, Under attack mode is the quickest lever: it challenges everyone immediately rather than waiting on the threat scoring behind the graduated security levels (Essentially off, Low, Medium, High). Pair it with checking Purge cache if cached pages are serving stale content, and keep an eye on whether the proxy toggle for the domain is still on.
When to contact support
If you've adjusted the security level and you're still seeing either legitimate visitors getting blocked or attack traffic getting through, open a ticket from Support in the portal. Our team can look at the traffic pattern on our end and tell you whether the issue is the security level, a different Cloudflare setting, or something happening below the CDN layer. Support is real humans via ticket or live chat, no phone line.