Skip to content
Cloudflare Docs

Security settings

This page describes the settings available in Security > Settings for a given domain.

Security modules

Web application exploits module

In the Web application exploits security module you can enable and configure the following managed rulesets and detections:

Refer to each linked page for details.

DDoS attacks module

The DDoS protection security module shows the multiple DDoS mitigation services provided by Cloudflare. You can create rules to override these mitigation tools. DDoS attack protection overrides are only available to Enterprise customers with the Advanced DDoS Protection subscription.

To learn more about DDoS protection overrides, refer to the following resources:

Bot traffic module

In the Bot traffic security module you can perform the following tasks:

API abuse module

In the API abuse security module you can perform the following tasks:

Client-side abuse module

In the Client-side abuse security module you can perform the following tasks:

All settings

This section allows you to configure multiple security-related settings. The following table links to additional information about each setting:

SettingLocation in previous dashboard navigation
Endpoint labelsSecurity > Settings > Labels
Session identifiersSecurity > API Shield > Settings
Schemas default actionSecurity > API Shield > Schema Validation
Uploaded schemasSecurity > API Shield > Schema Validation
Learned schemasSecurity > API Shield > Schema Validation
Token configurationSecurity > API Shield > Settings
Client-side resource alertsSecurity > Page Shield > Settings
Account Home > Notifications
Reporting endpointSecurity > Page Shield > Settings
Data processingSecurity > Page Shield > Settings
IP listsAccount Home > Manage Account > Configurations
Custom username and password locationSecurity > Settings
Custom content locationSecurity > Settings
Custom sensitive data deploymentSecurity > Sensitive Data
Block definitely automated trafficSecurity > Bots > Configure Super Bot Fight Mode
Security
> Bots > Configure Bot Management
Block likely botsSecurity > Bots > Configure Super Bot Fight Mode
Security
> Bots > Configure Bot Management
Managed robots.txtSecurity > Bots > Configure Bot Fight Mode
Security
> Bots > Configure Super Bot Fight Mode
Security
> Bots > Configure Bot Management
Allow verified botsSecurity > Bots > Configure Super Bot Fight Mode
Security
> Bots > Configure Bot Management
Static resource protectionSecurity > Bots > Configure Super Bot Fight Mode
Security
> Bots > Configure Bot Management
Optimize for WordPressSecurity > Bots > Configure Super Bot Fight Mode
Security
> Bots > Configure Bot Management
JavaScript detectionsSecurity > Bots > Configure Super Bot Fight Mode
Security
> Bots > Configure Bot Management
Auto-update machine learning modelSecurity > Bots > Configure Bot Management
Enable Security.txtSecurity > Settings
Challenge PassageSecurity > Settings
Browser Integrity CheckSecurity > Settings
Replace insecure JavaScript librariesSecurity > Settings
Security LevelSecurity > Settings