Cloudflare DNS Firewall

Cloudflare DNS Firewall is a firewall-as-a-service that helps secure DNS infrastructure against online attacks while increasing uptime and ensuring lightning-fast performance.

Get DNS Firewall

Control What Hits Your Network

With robust rate limiting capabilities, DNS Firewall shields your infrastructure from malicious and unwanted traffic. Rate limits are configurable over API, so you can easily configure them based on the health of your origin servers.


Automatically Mitigate DDoS Attacks

DDoS attacks on DNS infrastructure are becoming increasingly more common. Cloudflare reroutes malicious traffic away from your origin nameservers and absorbs it across our global network. DNS Firewall also comes with a dedicated automatic mitigation system that stops random prefix attacks.


Hide Your Origin IP From Attackers

DNS Firewall masks the origin IP addresses of providers’ nameservers behind Cloudflare’s IP addresses, keeping them safe from being targeted by attackers.

Want DNS Firewall?

Easy Setup

With a simple change of your nameservers’ IP addresses, your DNS infrastructure can be protected in as little as 5 minutes.


DNS Firewall vs. Authoritative DNS

With Cloudflare, you have two options for securing your DNS infrastructure:

Cloudflare DNS Firewall allows you to run your own infrastructure and keep your DNS records on your own nameservers while leveraging Cloudflare's global network and features like DDoS mitigation, rate limiting, caching and more. We recommend DNS Firewall for hosting and cloud providers, ISPs, registrars, and anyone running a large authoritative DNS infrastructure.

Cloudflare Authoritative DNS is an enterprise-grade, fully managed and hosted DNS service that also offers built-in DDoS protection and DNSSEC. We recommend our authoritative DNS solution for anyone who wants to use Cloudflare as their primary or secondary DNS provider. Learn more.

Key Features

DDoS mitigation
High availability
Global distribution
Enhanced performance
Bandwidth savings
DNS caching
Random prefix attack mitigation
Rate limiting per data center
Specify minimum and maximum TTL
Block queries of type ANY

Trusted by millions of Internet properties

Logo doordash trusted by gray
Logo garmin trusted by gray
Logo 23andme trusted by gray
Logo lending tree trusted by gray
NCR logo
Thomson Reuters logo
Logo zendesk trusted by gray