DDoS Attack Notifications Now Reach Your Inbox in Real Time
Cloudflare is rolling out real-time DDoS attack alerts for all paid plans at no additional cost. The alerts are designed to notify customers the moment their Internet property is targeted, closing the gap between autonomous attack mitigation and human awareness.
Cloudflare's DDoS protection systems have long operated without manual intervention, automatically detecting and blocking attacks such as the 654 Gbps botnet assault in July and the 754 Mpps event in June. While analytics dashboards provided post-incident visibility, customers wanted immediate notification when an attack was underway. The new alerting system addresses that request.
Alert Types and Eligibility
Two categories of DDoS alerts are available: HTTP DDoS alerts and L3/4 DDoS alerts. Which ones you can receive depends on the Cloudflare services you subscribe to, as outlined below.
Delivery methods by plan
Delivery method |
Plan | |||
|---|---|---|---|---|
| Free | Pro | Business | Enterprise | |
| ❌ | ✅ | ✅ | ✅ | |
| PagerDuty | ❌ | ❌ | ✅ | ✅ |
Alert types by service
Alert type |
Service | |||
|---|---|---|---|---|
| WAF/CDN | Spectrum | Spectrum BYOIP | Magic Transit | |
| HTTP DDoS alerts | ✅ | ❌ | ❌ | ❌ |
| L3/4 DDoS alerts | Coming soon | ✅ | ✅ | ✅ |
Setting Up an Alert Policy
To start receiving DDoS alerts, you must first create a notification policy from your Cloudflare account dashboard. The process takes only a few steps:
- Log in to your Cloudflare account dashboard at https://dash.cloudflare.com
- From the Account Home page, open the Notifications tab
- In the Notifications card, click Create
- Name the notification, add an optional description, and enter the email addresses of the recipients

Customers on the Business plan or higher can also route alerts to PagerDuty. You'll need to connect PagerDuty to Cloudflare prior to creating the alert policy, after which PagerDuty becomes available as a delivery option.
What the Alert Contains
Cloudflare designed the alert template after interviewing customers about what information matters most during an attack. The result is a deliberately concise notification with the subject line DDoS Attack Detected, sent only from the official address [email protected][dot]com. Users should add this address to their trusted senders list to avoid missing alerts.
Each alert includes the following details:
- A short description of the incident
- The date and time the attack was first detected and mitigated
- The attack type
- The maximum attack rate at the time the alert was triggered
- The attack target

Because an attack may still be in progress when the alert arrives, the email includes a direct link to view the attack in the Cloudflare dashboard, providing immediate visibility into ongoing protection efforts.
Feedback Loop
Recipients will also find a link to submit feedback on the protection and visibility they received. Cloudflare uses this feedback to measure user satisfaction, which it tracks as a key performance indicator for its DDoS protection service, and to inform future product improvements.



