Cloudflare Area 1 Email Security: What’s New in the Platform

Cloudflare’s acquisition of Area 1 Security, announced in February 2022, followed two years of the company using the technology internally, during which time phishing attacks all but disappeared from employee inboxes. The core value proposition remains unchanged: Area 1’s proactive approach identifies and blocks phishing campaigns before they reach users, addressing the more than 90% of cyberattacks that begin with email, according to Deloitte research. What has evolved is how the product is delivered, managed, and extended across Cloudflare's broader security platform.

Email Security on the Cloudflare Dashboard

A dedicated Email Security section is now available on the Cloudflare dashboard, giving customers a direct path to trial and adopt the technology. From this section, customers can request a 30-day full product trial, with Cloudflare’s team assisting with setup that takes only minutes.

Unlike a traditional Secure Email Gateway (SEG), there is no hardware, appliance, or agent to install or tune. Area 1 can be configured inline or connected via API, journaling, or other connectors, without disrupting mail flow or the end-user experience. During the trial, customers gain access to real-time detection metrics and forensics, along with direct incident updates from the Area 1 team. At the conclusion of the trial, Cloudflare provides a Phishing Risk Assessment walking through the impact of mitigated attacks and answering any questions.

For those not ready to commit to a trial, the Email Security section also offers an interactive demo. This places users inside the Area 1 portal of a fictitious company, allowing hands-on exploration of the full feature set, including message classifiers, Business Email Compromise (BEC) protections, real-time spoofed domain views, and message search capabilities.

Expanded Threat Intelligence and Detection Capabilities

Area 1’s cloud-native architecture enables a distinctive approach to phishing detection: scanning the internet for attacker infrastructure, sources, and delivery mechanisms to stop campaigns days before they reach inboxes. The machine-learning models behind this capability have been trained on nine years of Area 1 threat data, and now also incorporate intelligence from Cloudflare’s network, which blocks 124 billion cyber threats daily and handles 1.7 trillion DNS queries each day.

Because no local appliances are involved, these datasets and models are deployed simultaneously across every customer and apply to the full range of email attack types (URLs, payloads, BEC), vectors (email, web, network), and channels (external, internal, trusted partners). The threat observables and Indicators of Compromise (IOC) gathered through this process now feed into Cloudflare Gateway as part of the Zero Trust platform, extending protection beyond email and covering converged or blended threats.

Cloudforce One: Threat Research and Operations

Building on Area 1’s threat research and operations expertise, Cloudflare has launched Cloudforce One, a large-scale initiative to protect all Cloudflare customers and the broader internet. The team is organized into five subteams: Malware Analysis, Threat Analysis, Active Mitigation and Countermeasures, Intelligence Analysis, and Intelligence Sharing. Their collective experience includes tracking sophisticated cybercriminals while at the National Security Agency (NSA), USCYBERCOM, and Area 1 Security, alongside work with governments and similar organizations to disrupt threat actors.

The Cloudforce One team works with existing Cloudflare product, engineering, and security teams to improve products based on observed tactics, techniques, and procedures (TTPs) in the wild. All customers benefit from these improvements automatically without any action required.

Customers can also subscribe to Cloudforce One, which is now generally available. Subscribers gain access to threat data and briefings, dedicated security tools, and the ability to submit requests for information (RFIs) to the threat operations staff. This includes the Malware Analysis team accepting potential malware uploads for technical analysis, with responses provided in a timely manner.

Email Authentication: The Foundation of Anti-Spoofing

While Area 1’s detection engines address malicious inbound messages, SPF, DKIM, and DMARC policies remain essential for preventing email spoofing. These standards have always been part of Area 1’s threat models, and customers already receive weekly DMARC sender reports to assess configuration effectiveness. What was missing was guidance on setting up these records correctly.

Cloudflare’s Email Security DNS Wizard now addresses this need, walking customers through their initial SPF, DKIM, and DMARC configuration. The wizard is available immediately to all customers using Cloudflare DNS, with support for Cloudflare Area 1 customers on third-party DNS expected soon. Given the complexity of getting these records right, the wizard aims to provide a solid foundation for email security.

Additional feature expansions for Area 1 are planned. In the meantime, customers can experience the product firsthand by requesting a Phishing Risk Assessment or exploring the interactive demo directly from the Email Security section of the Cloudflare dashboard.