Skip to content

Cloudflare network security checks

IP allow-lists, TLS, DNS and edge settings that keep the application reachable only from where it should be.

On Cloudflare, Black Cat runs 3 checks in this area on every scan. Each one below lists its severity, how to fix it, and the compliance controls it satisfies where a control applies. See what access the Cloudflare connector needs.

Checks (3)

severity: medium DNS Wildcard Record fix difficulty: medium #

Review and remove unnecessary DNS wildcard records to reduce the attack surface

  1. Log in to the Cloudflare Dashboard and select the zone
  2. Navigate to DNS > Records
  3. Identify wildcard records (starting with *.)
  4. Replace wildcard records with specific subdomain records where possible

Vendor docs ↗

Satisfies: NIS2 Directive NIS2-21.a.2 DORA (SaaS Security) DORA-9.9

severity: medium DNS Record Points to Private IP fix difficulty: easy #

Remove or correct DNS A records pointing to RFC 1918 private IP addresses

  1. Log in to the Cloudflare Dashboard and select the zone
  2. Navigate to DNS > Records
  3. Identify A records pointing to private IP ranges (10.x, 172.16-31.x, 192.168.x)
  4. Update the record to point to a public IP or remove it if no longer needed

Vendor docs ↗

Satisfies: NIS2 Directive NIS2-21.a.2 DORA (SaaS Security) DORA-9.9

severity: low DNS Record Not Proxied fix difficulty: easy #

Enable Cloudflare proxy for A/AAAA DNS records to hide the origin server IP address

  1. Log in to the Cloudflare Dashboard and select the zone
  2. Navigate to DNS > Records
  3. Click the grey cloud icon next to the record to enable proxying (orange cloud)
  4. Verify the origin IP is no longer exposed via DNS lookup

Vendor docs ↗

Satisfies: NIS2 Directive NIS2-21.a.2 DORA (SaaS Security) DORA-9.9

More Cloudflare checks

The information on this page is provided for general informational purposes and is believed to be accurate as of its most recent update. Product names, logos, and trademarks are the property of their respective owners and are used for identification purposes only; their use does not imply any affiliation with or endorsement by those owners. Descriptions of third-party applications and of compliance frameworks are based on publicly available documentation and may change over time.

See these checks run on your stack

Start a free 14-day trial — no credit card required.

Start Free Trial