MORE POSTS
November 13, 2021 2:33 PM
Cloudflare blocks an almost 2 Tbps multi-vector DDoS attack
Earlier this week, Cloudflare automatically detected and mitigated a DDoS attack that peaked just below 2 Tbps — the largest we’ve seen to date....
November 12, 2021 12:59 PM
Five Great (free!) Ways to Get Started With Cloudflare
New to Cloudflare and don’t know where to begin? Here are five things you can do to get started with Cloudflare right now......
October 08, 2021 3:16 PM
What happened on the Internet during the Facebook outage
Today, we're going to show you how the Facebook and affiliate sites downtime affected us, and what we can see in our data....
October 04, 2021 9:08 PM
Understanding how Facebook disappeared from the Internet
Today at 1651 UTC, we opened an internal incident entitled "Facebook DNS lookup returning SERVFAIL" because we were worried that something was wrong with our DNS resolver 1.1.1.1. But as we were about to post on our public status page we realized something else more serious was ...
September 27, 2021 12:59 PM
Tackling Email Spoofing and Phishing
Today we’re announcing a new tool to tackle email spoofing and phishing. We’ll warn users about insecure configurations and provide an easy-to-use wizard to create required DNS records....
March 20, 2021 2:00 PM
Moving k8s communication to gRPC
How we use gRPC in combination with Kubernetes to improve the performance and usability of internal APIs....
March 08, 2021 2:00 PM
The benefits of serving stale DNS entries when using Consul
We use Consul for service discovery, and we’ve deployed a cluster that spans several of our data centers. We were aware from the start that the DNS query latencies were not great from certain parts of the world that were furthest away from these data centers....
December 08, 2020 12:00 PM
Helping build the next generation of privacy-preserving protocols
Today, we’re making several announcements around improving Internet protocols with respect to something important to our customers and Internet users worldwide: privacy....
December 08, 2020 12:00 PM
Improving DNS Privacy with Oblivious DoH in 1.1.1.1
Oblivious DoH (ODoH) makes secure DNS over HTTPS (DoH) queries into private queries which prevent the leakage of client IP addresses to resolvers. The new proposed ODoH standard addresses this problem and today we are enabling users to use this protocol with 1.1.1.1...
December 08, 2020 12:00 PM
Good-bye ESNI, hello ECH!
A deep dive into the Encrypted Client Hello, a standard that encrypts privacy-sensitive parameters sent by the client, as part of the TLS handshake....
November 30, 2020 1:14 PM
Improving the Resiliency of Our Infrastructure DNS Zone
We've improved the resiliency and management of our infrastructure DNS zone. In this post, we guide you through some of the "whats", "whys" and "hows" we encountered along the way. ...
November 13, 2020 7:06 PM
SAD DNS Explained
Researchers from UC Riverside and Tsinghua University found a new way to revive a decade-old DNS cache poisoning attack. Read our deep dive into how the SAD DNS attack on DNS resolvers works, how we protect against this attack in 1.1.1.1, and what the future holds for DNS cache p...
October 30, 2020 12:00 PM
Unwrap the SERVFAIL
We recently released a new version of Cloudflare Resolver, which adds a piece of information called “Extended DNS Errors” (EDE) along with the response code under certain circumstances. This will be helpful in tracing DNS resolution errors and figure out what went wrong behind th...
October 02, 2020 7:35 AM
DNS Flag Day 2020
October 1 is DNS Flag Day, an initiative by the DNS community to make DNS more secure, reliable and robust. This year the focus is on problems around IP fragmentation of DNS packets....