Get a free website with any plan

See how
CLOUDFLARE

Security level and challenges: what visitors see

Last updated

IN SHORT

Cloudflare security level in the Flashcloud portal controls how aggressively incoming traffic is challenged based on threat scores before reaching your server. Settings range from Essentially off to High, with Medium as the default. Raise it or use Under attack mode during traffic spikes, and lower it if legitimate visitors see verification prompts.

The Security level setting on your Cloudflare CDN page controls how aggressively Cloudflare challenges suspicious visitors before they reach your server. Higher settings show more visitors a challenge page (a brief "verify you're human" interstitial); lower settings let more traffic through unchecked. If real visitors are getting challenged, turn it down a notch. If you're under attack, turn it up.

This setting lives entirely in your Flashcloud portal, under Cloudflare CDN in the sidebar, on the per-domain settings for the domain you want to adjust. There's no separate cloudflare.com dashboard to log into: everything is managed from our portal.

What the security level actually does

Cloudflare scores every incoming request using signals like IP reputation, request patterns, and known bad actor lists. The security level decides how high that threat score has to be before a visitor sees a challenge instead of your site. The options range from least aggressive to most aggressive:

  • Essentially off: the least aggressive option. Use this if you're seeing false positives on legitimate visitors and traffic is otherwise normal.
  • Low, Medium and High sit in between; Medium is the default and a sensible choice for most sites.
  • I'm under attack: a temporary setting for active DDoS or bot floods, not something to leave on permanently.

A related toggle, Under attack mode, does roughly the same thing as the "I'm under attack" security level and is meant for the same short-term use: flip it on when you're actively getting hammered, then flip it back off once traffic normalizes.

Picking the right level

Start at a middle setting and watch what happens. If you're getting reports of visitors seeing challenge pages on a normal day, or you notice a drop in form submissions or checkout completions that lines up with a security level change, step it down toward Essentially off. If you're seeing a spike in traffic that looks automated (identical requests hammering the same URL, traffic from a narrow band of IPs, a spike with no matching marketing push behind it) step it up or switch on Under attack mode until it settles.

This setting works alongside the rest of your Cloudflare configuration, not in isolation. If you haven't looked at the other toggles on that page (SSL/TLS mode, Always Use HTTPS, Automatic HTTPS Rewrites, the AI Crawlers panel, and so on), the full walkthrough is in Every Cloudflare setting explained.

Before you change it during an actual attack

If you're mid-attack and traffic is climbing fast, Under attack mode is the quickest lever: it challenges everyone immediately rather than waiting on the threat scoring behind the graduated security levels (Essentially off, Low, Medium, High). Pair it with checking Purge cache if cached pages are serving stale content, and keep an eye on whether the proxy toggle for the domain is still on.

When to contact support

If you've adjusted the security level and you're still seeing either legitimate visitors getting blocked or attack traffic getting through, open a ticket from Support in the portal. Our team can look at the traffic pattern on our end and tell you whether the issue is the security level, a different Cloudflare setting, or something happening below the CDN layer. Support is real humans via ticket or live chat, no phone line.

Common questions

Why are my real visitors seeing a verification check?

Your security level is set too high for your traffic. Lower the setting toward Essentially off in your Flashcloud portal to stop challenging legitimate visitors.

What security level should I use on a normal day?

Medium is the default and a sensible choice for most websites. You can step it down toward Essentially off if you notice drops in form submissions or completed checkouts.

How do I stop an active DDoS attack right now?

Switch on Under attack mode in your Cloudflare CDN settings. This challenges everyone immediately rather than waiting on threat scoring. Turn it off once the attack settles.

Do I need to log into Cloudflare to change these settings?

No. You manage the security level directly inside the Flashcloud portal under Cloudflare CDN in the sidebar.

CAN'T FIND IT?

Real humans answer fast.

Hosting with us? Open a ticket and a real person replies - no scripts, no upsells. Still choosing a host? The same team is included with every plan, from day one.