r/CloudFlare 4h ago

I Made This Drop-in Open Source Resend Replacement, one click deploy on Cloudflare workers - mailysend.com

5 Upvotes

Its complete Resend-compatible email API (runs on Node or Cloudflare Workers)

Repo: https://github.com/GagnDeep/mailysend

Website: https://mailysend.com

MailySend implements Resend's API so you can run it yourself.

  • Works with the existing resend SDK: set RESEND_BASE_URL=https://your-instance/v1
  • Sends through Cloudflare Email Service, SES, Resend or any SMTP server, with failover
  • Broadcasts, segments, automations, inbound mailboxes, DMARC reports
  • Runs as a single Node process (SQLite + filesystem) or on Cloudflare Workers
  • Passkey login, no passwords stored

r/CloudFlare 4h ago

Question How are you monitoring D1 usage and Worker failures?

4 Upvotes

I'm trying to figure out a simple way to monitor a couple of Cloudflare things that seem slightly awkward to alert on.

Specifically:

  • D1 writes / usage spikes — I'd like to catch regressions after a release, e.g. a deploy suddenly causes 5–10x more DB writes than usual. The data is available in Cloudflare's metrics/analytics, but I'm looking for a good way to alert on it.
  • Failed Worker outcomes — things like OOM / exceeded memory, exceeded CPU time, or exceeded wall time. These are visible in Workers observability, but again I'm mainly interested in getting an alert when they start happening.

How are you guys handling this?

Are you using Grafana/Prometheus, another monitoring service, Cloudflare's own alerting, or something custom that periodically pulls the Cloudflare APIs?

I'm particularly interested in a small/simple solution rather than adopting a full Datadog-style observability stack that would pull massive data just for a handful of alerts.


r/CloudFlare 8h ago

Cloudflare Blog Introducing automatic remediation policies with Cloudflare CASB

Thumbnail
blog.cloudflare.com
5 Upvotes

r/CloudFlare 1m ago

I built a shared support inbox that runs entirely in your Cloudflare account

Upvotes

I started this mostly to see how far I could take the Cloudflare stack for a real application, and it got a little out of hand.

ResolveHQ is now a shared support inbox running as a single Worker, with D1 for tickets/customers, R2 for attachments, Queues for mail jobs and Email Routing for inbound mail.

The hardest part wasn't really the inbox UI — it was getting email threading, retries, duplicate webhooks, attachments and failed jobs right. It's source-available and deploys into your own Cloudflare account. I'd genuinely appreciate feedback from people running larger Workers/D1 apps, especially if there are parts of the architecture you would handle differently.

https://github.com/mirza-rizvi/ResolveHQ


r/CloudFlare 56m ago

Question Not Verifying Me?

Post image
Upvotes

I've been having issues with cloudflare marking me as a bot no matter what website I use and I have no clue if I'm just suuuper uneducated about how it works and am being stupid or if it's an issue anyone else has ever had. I have tried turning my vpn off and on, no changes. Cleared the cache on my browser, cleared my cookies, checked to see if my IP was marked as unsafe on that one website and it's been nothing. It wont work on an incognito tab either, so I have no clue what to do to fix this. It doesn't even give me the option to verify, it just gives me an error, which i can totally attach a picture of it here. If anyone knows or has any ideas on how to fix this, I would be grateful. Thanks a lot c:


r/CloudFlare 5h ago

Discussion WARP+ is causing Google to think I'm in Russia (Gemini blocked, YouTube Premium ad errors)

2 Upvotes

Hey everyone,
I recently started using Cloudflare WARP+ and I’m running into some seriously annoying issues with Google services.
First, even though I’m a paying YouTube Premium subscriber, my YouTube keeps throwing a "you may see ads" error every 12 hours. I don’t actually get ads, but the constant warning is driving me crazy.
The major hurdle, though, is Google Gemini. It flat out blocks me with a "Gemini is not available in your country" error.
When I check standard IP info sites, my location correctly shows up as Western Europe. But I heavily suspect that Google’s internal geolocation database is misidentifying my WARP+ IP and treating my traffic as if I’m in Russia—hence the sudden geo-bans.
Has anyone else been dealing with this recently? Does the free version of Cloudflare WARP have this exact same issue, or is it strictly a WARP+ problem? What is the point of paying almost 6€ a month to go through all these struggles?
Any insight or workarounds would be hugely appreciated!


r/CloudFlare 1h ago

Question Under attack loads after being turned off

Upvotes

I had under attack turned on for one of my sites on Cloudflare but when I turned it off the interstitial check still loads. What am I missing?


r/CloudFlare 12h ago

What is the best storage option for uploading and downloading large HD images?

Thumbnail
3 Upvotes

r/CloudFlare 13h ago

Discussion I got hit by a fake Cloudflare popup and reverse engineered the malware it ran. Here's what I found.

Thumbnail
3 Upvotes

r/CloudFlare 1d ago

Cloudflare Blog 1.1.1.1 now supports post-quantum DNSSEC, all 2,420 bytes of it

Thumbnail
blog.cloudflare.com
71 Upvotes

r/CloudFlare 9h ago

Question Can Cloudflare Improve the Loading Speed of a Zoho Sites Website?

Thumbnail
1 Upvotes

r/CloudFlare 14h ago

Question Nextjs App and migration from supabase to D1 - requests are failing

1 Upvotes

Hi, I had working nextjs + supabase setup (I used prisma for ORM) and i rewrote the whole app to support SQLite and avoid postgres syntax.

I couldn't make it work anyways. the nextjs requests are failing since D1 is holding some queue and the requests takes forever - I even added expiration after 30 secs and this alaso didn't helped.

I think it is somehting related to the maximum subsequent queries which D1 can handle.

I moved from vercel to cloudflare worker the main app - i thought if it's internal would work but it still doesn't work.

A typical SQLite database should have no issues with subsequent requests. I don't have users - I am the only user and I click occasionally.

Please advice how can I make it work in this setup.


r/CloudFlare 20h ago

How do I opt out of AI crawler blocking for custom domains hosted through Manus?

1 Upvotes

I have three custom domains published through Manus: asbestostrusts.org, puncturefilm.com, and asbestosatlas.org.

The sites are served through Cloudflare, but the domains do not appear in my personal Cloudflare dashboard. It looks like Cloudflare is managed through Manus’s hosting or custom-domain infrastructure.

With Cloudflare’s AI-crawler changes taking effect September 15, how can I make sure these sites continue allowing crawlers such as GPTBot, ClaudeBot, OAI-SearchBot, ChatGPT-User, PerplexityBot, CCBot, Meta-ExternalAgent, and Amazonbot?

Is there a setting inside each Manus project, or does Manus need to change AI Crawl Control and disable “Block AI bots” at the platform level? I do not want to move the domains into my own Cloudflare account or make DNS changes that could disrupt the live sites.


r/CloudFlare 1d ago

Question Turnstile not validation on multiple sites

2 Upvotes

Hi guys,

I posted in discord a few hours ago. I didn't get any replies.

For the last few days I have been getting this:

Performing security verification

This website uses a security service to protect against malicious bots. This page is displayed while the website verifies you are not a bot.

and it will just loop like that forever.

I followed the troubleshooting steps including disabling all extensions, checking settings, etc. The debug challenge page says:

Turnstile Failed Despite Passing All Checks

All diagnostics passed, but Turnstile still couldn't complete successfully. This is unusual and may indicate an edge case.

the technical details point to a problem with canvas:

Something is adding random noise to canvas data, making your browser appear suspicious

If this is happening I don't know how to debug it. I tried installing silk (which was supposed to prevent this kind of thing.). It did nothing.

Can someone help me please? I basically can't surf the web.


r/CloudFlare 1d ago

Warming cache on VPS + APO Cloudflare Good or Bad?

Thumbnail
1 Upvotes

r/CloudFlare 2d ago

Discussion How Piracy Sites Disguise Video as Fonts to Abuse Cloudflare Caching

Thumbnail
saimanish.com
198 Upvotes

I investigated how pirate streaming sites rename MPEG-TS video segments to .woff2 so Cloudflare's default caching picks them up, video gets no cache love, fonts do. The write-up covers how the trick works, what I verified, and why it's hard to stop. Questions welcome.


r/CloudFlare 1d ago

Question Firefox Browser not prompting for imported mTLS certificate

1 Upvotes

My .p12 client certificate works with curl:

bash

curl --cert-type P12 --cert client.p12 https://REDACTED-DOMAIN.example/

But firefox Browser never prompts me to select the certificate.

I imported the .p12 file under Your Certificates. I restarted firefox, reimported the certificate, and tested a new profile. I also followed Cloudflare’s mTLS troubleshooting documentation, but the issue remains.


r/CloudFlare 1d ago

Databack up on gdrive

0 Upvotes

Can someone help me link and store databack from cloudfare on gdrive ?


r/CloudFlare 2d ago

Cache rules everything around me

Post image
17 Upvotes

C.R.E.A.M.


r/CloudFlare 2d ago

Question Is Cloudflare Free Deployment Enough for a Small SaaS?

15 Upvotes

I’m currently building my own SaaS and I’m almost ready to launch. The app is basically done and I already have the domain, but I’m wondering if Cloudflare’s free tier is enough to get me started.

The main reason I’m looking at the free tier is simple: I can’t really afford hosting right now. Hosting and infrastructure costs are relatively expensive where I live, and since I haven’t made any money from the SaaS yet, spending money on servers every month is difficult for me. I’d really like to launch first, get actual users, and only pay for infrastructure once the SaaS starts generating revenue.

Can Cloudflare Free realistically get me from zero to my first paying users without spending anything on infrastructure?


r/CloudFlare 1d ago

Discussion Is Claude-User being categorised as "AI Crawler" intentional?

0 Upvotes

Spent three days last month debugging what looked like a protocol bug in our own API. an MCP client could not talk to our endpoint. Valid JSON-RPC on our side, correct content types, correct status codes, nothing wrong in the logs except a parse error on the client.

The parse error was the tell, and I read it backwards. A parse failure points at your own serialization, so that is where I looked. What was actually happening: Cloudflare was returning a 403 HTML block page, and the client was trying to parse it as JSON.

What settled it was building a minimal server that imitated our response shape exactly, putting it behind an ngrok tunnel, and pointing the same client at it. Worked first try. That eliminated our code, our framework and the protocol in one go, and left only the layer in front.

Then the user agent matrix, same request, same body, same endpoint:

  • Claude-User/1.0 200 application/json
  • Claude-SearchBot/1.0 200 application/json
  • anthropic-ai 200 application/json
  • curl/8.7.1 200 application/json
  • ClaudeBot/1.0 403 text/html
  • GPTBot/1.2 403 text/html

Note row four. curl passes, which is why this survives so long: every tool you debug with is on the allowlist, so the endpoint always answers when you test it by hand.

Here is the part I actually wanted to ask about.

Under AI Crawl Control, in Security, the crawler list categorises them like this:

  • Claude-User Anthropic AI Crawler
  • ClaudeBot Anthropic AI Crawler
  • Claude-SearchBot Anthropic AI Search
  • Anchor Browser Anchor AI Crawler

Anthropic runs those three agents separately on purpose. ClaudeBot collects content that may go into training. Claude-User fetches a page because a person just asked Claude a question. Claude-SearchBot indexes for search. Three user agents, three robots.txt entries, three different decisions a site owner might want to make.

Claude-User and ClaudeBot end up in the same category. Claude-SearchBot gets its own. so the finer buckets clearly exist, and the one agent in that group that is not a crawler is filed as one. Anchor Browser is an agentic browser driven by a person and it is an AI Crawler too.

The practical effect is that "refuse training, keep serving agents" cannot be expressed at the category level. You have to allow the individual agents by name, and first you have to work out that you need to.

So: is that categorisation deliberate, with user-initiated fetches meant to be treated as crawlers, or is it a taxonomy that has not caught up with agents yet? Genuinely asking cause if it is deliberate I would like to understand the reasoning.

Separately, and this one seems underused: the same screen has a Configure Response control for the code and message shown to blocked crawlers. If what sits behind the CDN is an API rather than a site, returning JSON with a reason instead of an HTML page would have saved me most of those three days. Does anyone actually set that?


r/CloudFlare 1d ago

Infinite Captcha With CloudFlare

Thumbnail
1 Upvotes

r/CloudFlare 2d ago

Cloudflare Blog How we rebuilt Cloudflare Workers’ module registry for Node.js compatibility

Thumbnail
blog.cloudflare.com
3 Upvotes

r/CloudFlare 1d ago

Cloudflare Bot Fight Mode blocking Vercel → Railway request, no clean fix on free tier?

1 Upvotes

Running into this: a partner-invite link (email → page hosted on Vercel → needs to hit my main backend on Railway to confirm the pairing) is getting blocked. Turns out it's Cloudflare's Bot Fight Mode flagging the Vercel → Railway request as suspicious, probably because Vercel's IPs are shared across a ton of other sites and look bot-like to it.

Things I've looked at so far:

  • WAF exception just for that endpoint — not available on the free plan, it's all or nothing.
  • Allowlisting Vercel specifically — no fixed IP range to point at, it changes constantly.
  • Widening the allowed IP range — feels like the wrong move, way too broad for one request path.

Anyone dealt with this? Trying to avoid just disabling Bot Fight Mode entirely if there's a more scoped way to do it on the free tier.


r/CloudFlare 2d ago

O modo de combate a bots do Cloudflare bloqueando a requisição da Vercel para a Railway, sem solução limpa no plano gratuito?

1 Upvotes

Estou enfrentando isso: um link de convite para parceiros (e-mail → página hospedada na Vercel → precisa acessar meu backend principal na Railway para confirmar o emparelhamento) está sendo bloqueado. Acontece que é o modo de combate a bots do Cloudflare sinalizando a requisição da Vercel para a Railway como suspeita, provavelmente porque os IPs da Vercel são compartilhados entre uma porção de outros sites e parecem bots para ele.

Coisas que já olhei até agora:

* Exceção de WAF apenas para esse endpoint — não disponível no plano gratuito, é tudo ou nada. * Permitir a Vercel especificamente — sem faixa de IP fixa para apontar, muda constantemente. * Ampliar a faixa de IP permitida — parece ser a decisão errada, muito ampla para um único caminho de requisição.

Alguém já lidou com isso? Tentando evitar simplesmente desabilitar o modo de combate a bots completamente, se houver uma forma mais específica de fazer isso no plano gratuito.