Cloudflare protects a website best when requests pass through it and the application can handle the traffic that remains. Turning on one setting does not protect every path to your server.
Imagine an online shop. Attackers might flood product images, repeatedly call an expensive search endpoint, or contact the server directly. These consume different resources, so the setup needs several layers.
1. Put Cloudflare in the request path
Enable the proxied status for the website's supported DNS records. Visitors then reach Cloudflare before the origin, which is the server actually running your website. A DNS-only record provides name resolution; it does not send the website's HTTP traffic through this protection path.
