How a DDoS Attack Can Cost $104,000 – and Why We Now Use Cloudflare

How a DDoS Attack Can Cost $104,000 – and Why We Now Use Cloudflare
by Zelkulon15 March 20261 min read

A Netlify user received a $104,000 bill – from a single DDoS attack. Cloudflare offers free protection with unlimited bandwidth. Setup in 20 minutes, no code required.

The problem: Pay-per-use and DDoS

A Netlify user received a bill for $104,000 in 2024 – caused by a single DDoS attack. Netlify charges for bandwidth above the free tier, and during an attack this can scale to enormous amounts within hours.

Most modern hosting platforms charge by usage. Vercel, Netlify, AWS, Google Cloud – all have free tiers, then the meter starts running. This works fine as long as traffic is legitimate.

Pay-per-Use Hosting + DDoS-Angriff

  Botnet (100.000 Anfragen/Sek.)
          β”‚
          β–Ό
  Hosting-Anbieter (Netlify / Vercel / AWS)
          β”‚
          β”œβ”€β”€ Bandbreite: β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆ Limit ΓΌberschritten
          β”œβ”€β”€ Requests:   β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆ Limit ΓΌberschritten
          └── Rechnung:   $104.000 πŸ’Έ

In a DDoS attack, thousands of compromised systems send requests simultaneously. And the insidious part: you don't need to be a big target. Attackers test their botnets, or someone simply hit the wrong IP. Even small websites can be affected.

How Cloudflare protects you

Cloudflare sits as a proxy between the internet and your actual server. All traffic first passes through Cloudflare's network – where it is filtered. Attack traffic is absorbed before it reaches the hosting provider.

Mit Cloudflare als Proxy

  Internet-Traffic
          β”‚
          β–Ό
  β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”
  β”‚   Cloudflare Edge       β”‚  ← DDoS-Filterung hier
  β”‚   300+ Rechenzentren    β”‚  ← Angriff wird absorbiert
  β”‚   unbegrenzte Bandbreiteβ”‚
  β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”¬β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜
               β”‚ nur legitimer Traffic
               β–Ό
  Hosting-Anbieter (Netlify / Railway / Server)
               β”‚
               └── Rechnung: normal βœ“
  • DDoS protection is included in the free plan – with no bandwidth limit
  • Cloudflare's network spans over 300 data centers worldwide
  • Attack traffic is absorbed before it reaches the hosting provider
  • Netlify, Vercel or your own server only sees filtered, legitimate traffic

Setup – Step 1: Account and domain

The setup requires no code. DNS changes at the domain registrar are all that's needed.

Cloudflare Free: no credit card required, no automatic upgrades. The free plan includes full DDoS protection and unlimited bandwidth.

1. cloudflare.com β†’ Account erstellen (kostenlos)
2. "Add a Site" β†’ Domain eingeben
3. Free Plan auswΓ€hlen
4. Cloudflare importiert bestehende DNS-EintrΓ€ge automatisch

Setup – Step 2: Change nameservers

After import, Cloudflare provides two nameservers. These are entered at the domain registrar. Existing DNS records remain intact – Cloudflare imported them automatically.

# Cloudflare zeigt zwei Nameserver an, z.B.:
aria.ns.cloudflare.com
bob.ns.cloudflare.com

# Diese beim Registrar eintragen:
# Strato:  Domain-Verwaltung β†’ Nameserver β†’ Benutzerdefinierte NS
# IONOS:   Domains β†’ DNS β†’ Nameserver Γ€ndern
# GoDaddy: My Domains β†’ DNS β†’ Nameserver

The change takes up to 24 hours, but usually takes effect within 1–2 hours. Cloudflare shows the status in the dashboard.

Setup – Step 3: Enable proxy

In Cloudflare's DNS management, each record shows a cloud icon. Orange means traffic passes through Cloudflare. Grey means direct pass-through, no proxy.

Cloudflare DNS-Verwaltung:

  Typ    Name   Wert                       Proxy
  ────────────────────────────────────────────────
  A      @      75.2.60.5 (Netlify)        🟠 aktiv   ← DDoS-Schutz
  CNAME  www    apex-loadbalancer.net...   🟠 aktiv   ← DDoS-Schutz
  MX     @      aspmx.l.google.com         βšͺ grau    ← E-Mail, kein Proxy!
  TXT    @      v=spf1 ...                 βšͺ grau    ← SPF, kein Proxy

Important: always leave mail records (MX, DKIM, SPF, DMARC) grey. Email traffic must not go through the HTTP proxy.

Setup – Step 4: Configure SSL/TLS

Cloudflare mediates between visitors and the hosting provider. The SSL/TLS mode determines how these connections are encrypted.

Cloudflare β†’ SSL/TLS β†’ Overview

  [ ] Off            – kein HTTPS
  [ ] Flexible       – nur Cloudflare ↔ Besucher verschlΓΌsselt ⚠
  [x] Full           – Ende-zu-Ende verschlΓΌsselt
  [x] Full (strict)  – Ende-zu-Ende + Zertifikat muss gΓΌltig sein βœ“

  β†’ Empfehlung: Full (strict)
    (Netlify und Vercel haben immer gΓΌltige Zertifikate)

What else Cloudflare offers (free)

Beyond DDoS protection, the free plan brings additional benefits:

  • Caching: static assets are cached at Cloudflare's edge – faster loading times worldwide
  • Bot protection: basic bot detection and filtering without configuration
  • Analytics: traffic overview without cookies or GDPR issues
  • Page Rules: redirects and cache rules per URL
  • Rate Limiting (paid): limit requests per IP for additional protection

Cloudflare is not a hosting provider. It doesn't replace Netlify, Railway or your own server – it sits in front of them. For business-critical applications with SLA requirements, Pro or Business plans are relevant.

Securing the hosting provider directly

For additional security: most server setups allow accepting incoming traffic only from Cloudflare's IP ranges. This prevents any attacker from reaching the hosting provider directly, even if they know the real IP.

# Netlify: nur Cloudflare-IPs erlauben
# β†’ In Netlify gibt es aktuell keine IP-Whitelist fΓΌr den Ingress.
# Stattdessen: Origin-Anfragen ΓΌber einen eigenen Server (z.B. Railway)
# absichern, der nur Cloudflare-IPs akzeptiert.

# FΓΌr eigene Server (nginx-Beispiel):
# Cloudflare IP-Ranges: https://www.cloudflare.com/ips/

# /etc/nginx/conf.d/cloudflare-only.conf
allow 173.245.48.0/20;
allow 103.21.244.0/22;
allow 103.22.200.0/22;
# [alle Cloudflare IP-Ranges]
deny all;

Cloudflare publishes all current IP ranges at cloudflare.com/ips – this list should be updated regularly.

Checklist: 20 minutes for lasting protection

For every publicly accessible website running on pay-per-use hosting:

  • Create a Cloudflare account – free, no credit card required
  • Add domain to Cloudflare – DNS import runs automatically
  • Change nameservers at the registrar – approx. 15 minutes
  • Enable proxy for all public records (orange cloud icon)
  • Set SSL/TLS to 'Full (strict)'

The one-time setup takes about 20 minutes. The risk it covers is a five-figure invoice. The $104,000 bill was preventable.

How a DDoS Attack Can Cost $104,000 – and Why We Now Use Cloudflare