This article explains how to reduce the risk of Cloudflare bypass by preventing visitors from reaching the origin server directly.
Overview
A website is not fully protected by Cloudflare if the origin IP address can be used directly. Origin protection means the server accepts web traffic only through Cloudflare or through a private tunnel.
Recommended Steps
- Confirm that the website DNS records are proxied in Cloudflare.
- Remove unnecessary A, AAAA, or CNAME records that reveal the origin IP.
- Check old subdomains such as
dev,staging,cp,panel,webmail, ordirectthat may point to the same server. - On VPS or dedicated servers, allow ports 80 and 443 only from Cloudflare IP ranges.
- On managed hosting, check with Libyan Spider support before applying restrictions.
- Consider Authenticated Origin Pulls for stronger origin validation.
- Use Cloudflare Tunnel when the origin should not accept public inbound web traffic.
Common Mistakes to Avoid
- Blocking all traffic before confirming Cloudflare IP ranges.
- Forgetting IPv6 rules if the server has IPv6 enabled.
- Leaving an unprotected subdomain pointing to the same web root.
- Assuming WAF rules alone block direct IP access, direct traffic does not pass through Cloudflare.