Email Security Joins Cloudflare's Paid Self-Serve Plans
Cloudflare's pattern of taking enterprise-grade security tools and packaging them for a broader audience has a new chapter. Following its expected acquisition of Area 1 in early Q2 2022, the company says it will include Area 1's email security technology in all paid self-serve plans at no extra cost. The level of control, customization, and analytics will scale with the plan tier, with the highest flexibility and support reserved for Enterprise customers.
The move addresses a gap in Cloudflare's Zero Trust offering. The company notes that email security is a necessary component of any Zero Trust architecture, particularly given that more than 90% of successful cyber attacks originate from a phishing email. By bundling Area 1's technology, Cloudflare aims to make Zero Trust more complete without requiring additional purchases.
Existing self-serve customers can join a waitlist by logging into dash.cloudflare.com, selecting their domain, navigating to the Email tab, and clicking "Join Waitlist." Access will be granted in the order requests are received once the acquisition closes and integration is complete.
One-Click DNS and Email Security Setup
For organizations already using Cloudflare for authoritative DNS—which the company says is nearly 100% of non-Enterprise customers—deployment will be a single click. Doing so will change the MX records returned for the domain so all inbound email routes through Area 1's filtering models, where messages may be quarantined or flagged. Microsoft Office 365 customers can additionally leverage APIs for deeper integration, including post-delivery message redaction.
Cloudflare will also handle DNS email security records automatically, covering SPF, DKIM, and DMARC. The company says it plans to expand on the tool it launched last year for this purpose, making it more comprehensive and easier to use.
Zero Trust Product Integration
Email security is being designed to work alongside other Zero Trust components. For customers using Gateway and Remote Browser Isolation (RBI), suspicious domains and links detected in email will be routed through those protective layers automatically. Cloudflare's data loss prevention (DLP) technology will also be connected to Area 1 in deployments where outbound email visibility is available.
The companies also plan to share threat intelligence in both directions. Phishing infrastructure discovered through Area 1's Internet-wide scans will appear in Cloudflare's Security Center, while data from 1.1.1.1's trillions of monthly queries can help Area 1 identify newly registered domains or near-miss lookalike domains—both common precursors to phishing campaigns.
Enterprise customers who want immediate access can fill out a form or contact their Customer Success Manager, while Pro and Business plan users can reserve their spot via the waitlist.



