DDOS Attack today and increased Security Level

What is the name of the domain?

What is the error number?

What is the error message?

What is the issue you’re encountering

Crashed front- and backend due to increased security level . Cannot lower it manually. Have to switch on the developer cache and purge the cache.

AND RIGHT NOW: have to switch off all domains “florida-scout.com” at the DNS settings

Hello Cloudflare Support,

Our domain was under a DDoS attack earlier today. Cloudflare automatically increased the Security Level and enabled automated mitigation.

As a result, legitimate users are being blocked and we are unable to lower the Security Level manually. The attack has stopped.

Please disable the automated mitigation and restore manual control over the Security Level for our domain.

Was the site working with SSL prior to adding it to Cloudflare?

Yes

What is the current SSL/TLS setting?

Off

What are the steps to reproduce the issue?

just call the URL

In case if you cannot remember in which interface under the Cloudflare Dashboard have you enabled such feature for your Website, I’d suggest to cross-check multiple settings and disable it following the instructions from the article below:

  1. Check the main Dashboard
  2. Check Custom Rules under Security menu → WAF tab
  3. Check Security Level under Security menu → WAF tab
  4. Check Configuration Rules under the Rules tab

Thank you fritex for your answer. However I have not switched “On” the “I’m Under Attack” mode. It’s about the security level which is always on now and I can not lower this by myself so that the domain can run with Cloudflare without having “forbidden” when someone tried to access the page.

Hello Cloudflare Support Team,

I have submitted a ticket (#01438236) regarding automated mitigation and “Always Protected” security level on multiple domains (developmentscout.com, florida-scout.com, presseservicebuero.de). Legitimate users are receiving 403 Forbidden errors, and we urgently need to regain manual control.

The DDoS attack has stopped, but the system still enforces automatic protection.

Please prioritize this ticket. Thank you!

Could you share a screenshot of this 403 error? :thinking:

if you have received an email related to your zone having potentially abusive behaviour, please reply to the email that you’ve received from Cloudflare team.
Otherwise, please reach out directly to [email protected].
This issue has to be checked and solved by the Trust&Safety team.
Thank you for patience.

Please, do acknowledge below if it’s related to your case as well:

I’d suggest you to double-check the Security → Events at Cloudflare dashboard under your Cloudflare account for your zone, or via direct link https://dash.cloudflare.com/?to=/:account/:zone/security/events.

You should be able to see the challenged or blocked event under the Security tab → Events at Cloudflare dashboard for your zone and know exactly which security option was triggered.

Once you find them, click on a particular one to find more details about it (user-agent, IP, HTTP version …). If yes, could you share some details which service was triggered that blocked you?

This topic was automatically closed 15 days after the last reply. New replies are no longer allowed.