Cloudflare adds email protection to its free political campaign security package

Cloudflare has expanded its Cloudflare for Campaigns offering to include Email Security, making the anti-phishing and spoofing protection available at no cost to US political campaigns and parties. The addition comes through the company's ongoing partnership with Defending Digital Campaigns (DDC), the non-profit organization approved by the Federal Election Commission to facilitate free and discounted cybersecurity services for political operations.

Cloudflare for Campaigns launched in 2020 with DDoS protection and web security tools. Since then, more than 250 US campaigns and political parties of all affiliations have used the package. Campaigns frequently requested help with malicious email targeting staff, which the company says is now addressed with the integration of its Area 1 Security technology, acquired in 2022.

Email as a vector of political interference

Phishing attacks against campaigns have produced some of the most damaging political security incidents of the past decade. In 2016, attackers breached Democratic National Committee staff inboxes with spear phishing emails disguised as Google security alerts, accessing thousands of messages. In 2018, Russian intelligence agents targeted Senator Claire McCaskill's re-election campaign with password-change prompts sent to staff. The Republican Party of Wisconsin lost $2.3 million to a 2020 phishing attack.

These attacks hit smaller operations out of proportion to their resources. During the 2022 US midterm elections, Cloudflare protected inboxes for more than 100 campaigns, election officials, and public organizations. In the three months before those elections, Cloudflare processed over 20 million emails and blocked roughly 150,000 phishing attempts.

During the 2024 US election cycle, Cloudflare extended protection to state and local election offices, political campaigns, state parties, independent media, and voting rights groups. The full-year figures for campaigns and parties included:

  • 5.7 million emails scanned
  • 400,000 malicious messages blocked before delivery
  • 21,000 suspicious emails detected and stopped
  • 14,000 unique spoofing attempts prevented

What the expanded package covers

Cloudflare Email Security under Cloudflare for Campaigns becomes available starting today. The service features:

  • Phishing protection: AI-based threat detection that identifies and blocks malicious emails before delivery
  • Email authentication: Built-in support for DMARC, DKIM, and SPF standards to prevent spoofing
  • Real-time monitoring: Continuous scanning for suspicious activities and anomalies
  • Seamless integration: Works with existing email providers without disrupting workflows
  • Insightful reporting: Analytics and reports for tracking security events and improving defenses

Background on the program's structure

US campaign finance law prohibits corporations from donating money or services directly to federal candidates or parties. Cloudflare routes its offerings through DDC, which is FEC-approved to distribute these protections. Area 1 Security had previously provided low-cost email security to campaigns under its own FEC approval before the Cloudflare acquisition.

"DDC is thrilled that Cloudflare is expanding their product offerings to campaigns with the addition of Email Security. This will expedite robust protections from the real and serious threats posed by phishing. Now campaigns, in concert with the DDoS protection Cloudflare provides via Cloudflare for Campaigns, will be able to easily enable a suite of core protections."

– Michael Kaiser, President & CEO of Defending Digital Campaigns

How campaigns can get access

Campaigns already enrolled in Cloudflare for Campaigns will receive an email with instructions for enabling Email Security. New applicants can request the full product suite through the Cloudflare for Campaigns page.