Moz Q&A is closed.
After more than 13 years, and tens of thousands of questions, Moz Q&A closed on 12th December 2024. Whilst we’re not completely removing the content - many posts will still be possible to view - we have locked both new posts and new replies. More details here.
Is CloudFlare bad for SEO?
- 
					
					
					
					
 I have been hit by DDoS attacks lately...not on a huge scale, but probably done by some "script kiddies" or competitors of mine. Still, I need to take some action in order to protect my server and my site against all of this spam traffic that is being sent to it. In the process of researching the tools available for defending a website from a DDoS attack, I came across the service offered by CloudFlare.com. According to the CloudFlare website, they protect your site against a DDoS attack by showing users/visitors they find suspicious an interstitial that asks them if they are a real user or a bot...this interstitial contains a Captcha that suspicious users are asked to enter in order to visit the site. I'm just wondering what kind of an effect such an interstitial could have on my Google rankings...I can imagine that such a thing could add to increased click-backs to the SERPs and, if Google detects this, to lower rankings. Has anyone had experience with the DDoS protection services offered by CloudFlare, who can say a word or two regarding any effects this may have on SEO? Thanks 
- 
					
					
					
					
 i know this is a old thread and i see where people says cloudflare dont have a bad effect but i need someone to tell me more about it because am scare loosing all my hardwork on my Music niche 
- 
					
					
					
					
 Wanna know if cloudflare depends on some country and unavailable in some countries? thinking of using this as well on my subscene page 
- 
					
					
					
					
 it should not negatively impact your ranking in any way shape or form. If you are seeing the speed increase from it it will most likely be a positive effect on your rankings. Google no longer uses IP's so it's fine. to have a reverse proxy in front like CloudFlare. you like it and you think it's fine to help move site, by all means, try it out. It will only have a negative impact on your rankings if you do something that's almost impossible in block Google Bot with your firewall which is not going to happen unless you really start getting technical with the WAF, in other words, don't worry about it sincerely, Tom 
- 
					
					
					
					
 Seriously I wanted to go for cloudflare too on my music blog because they make site super fast but I'm scared to loose my ranking Should I or not 
- 
					
					
					
					
 I agree that they are much better than they where I’m still using Incapsula & Fastly. I use CloudFlare Enterprise for China. Glad to hear you’re doing well! Tom 
- 
					
					
					
					
 We have hundreds of sites managed through Cloudflare. So far the good far outweighs the bad, although I am beginning to suspect bad neighbors could certainly negatively influence ranking. We have a few comparisons ongoing. We will know for sure in the coming months. I only wish Cloudflare would take a higher stance about which sites it is willing to get in bed with. Here https://sarkariresultsite.com/ is the our new website which is managed by Cloudflare. 
- 
					
					
					
					
 With CloudFlare the challenge page you refer to is dependent on your security questions. My knowledge of DDos mitigation is not great, but what I do is have the CloudFlare security settings on Low. If I was to come under attack, I would react and put the security settings on high for the duration. If the DDos is bad, than you may need the expensive plan that has specialist DDos protection. today i transfer my site https://sarkariresultsite.in on cloud flare with cloudflare flexible SSL 
- 
					
					
					
					
 Generally speaking, CAPTCHA based DDoS protection is not advised as it will drive away clients and DDoS bots alike. 
 Same goes for delay pages.Also, DDoS attacks are swift and can bring site/server down in minutes so the manual approach is risky and probably less effective than it sounds on paper. Even if you are always near your PC, like many of us here are, you`ll still be exposed on weekends, nighttime, launch breaks, etc... Hackers know that and will exploit it. (favorite attack time - VERY EARLY Sunday mornings... ) You should also consider that DDoS can serve as a means to an end. It's often used to "soften" the protective layer to hack the database, inject the site with backdoors, deface or delete it and so on and so forth. What you really need is a combination of auto-triggering and transparent mitigation, which shies away from intrusive mitigation methods in favor of more subtle progressive challenges (i.e. JS challenge combined with reputation and behavior monitoring). 
 This may sound fancy but it really this is the emerging industry standard and growing competition between vendors actually drives costs down.
- 
					
					
					
					
 With CloudFlare the challenge page you refer to is dependent on your security questions. My knowledge of DDos mitigation is not great, but what I do is have the CloudFlare security settings on Low. If I was to come under attack, I would react and put the security settings on high for the duration. If the DDos is bad, then you may need the expensive plan that has specialist DDos protection. 
- 
					
					
					
					
 Hi 
 SEO wise, there are many things to consider before on-boarding a CDN service and bot filtering is one of them.
 I've covered the topic in 2 blogs posts about a year ago:1. CDN's SEO related advantages 2. CDN's SEO related myths (and possible issues to consider) PS: I work for CDN-based security and acceleration service provider - Incapsula. 
- 
					
					
					
					
 Hi http://www.neustar.biz/enterprise/ddos-protection https://www.verisigninc.com/en_US/forms/ddosattackservice.xhtml http://www.incapsula.com/ddos/anti-ddos-protection What can happen If you want a true built for enterprise host that actually has a perfect record and will care more than any other that I know of about security, up time and would you benefit yes you would fire host is the best they offer built-in DoS/DDoS mitigation 2 answer your question about cloud flair I do not feel adding them will give you the same advantages as a enterprise level hosting company. For instance I believe fire host to be the best let's say you think liquid Web managed dedicated with layer 7 DDoS protection is better. Well that's up to you and me to make our decisions. Based on past history and our own opinions of the companies. If you where to add CloudFlare you would receive CloudFlare layer 7 DDoS protection only once you started paying $200 a month of free cloud for a service is not a system that will protect you against an attack http://www.cloudflare.com/features-security There content delivery network as they call it is simply a reverse proxy it's not what other people would call a true CDN once again the issues would be a large with the base plan http://www.cloudflare.com/features-cdn Your so-called anti-cast DNS CloudFlare says is standard changes your IP address by definition any cast and DNS does not change your IP. There are some methods two get around this but it's not simple. A $200 a month "CloudFlare Railgun  origin network optimizer" origin network optimizer"http://www.cloudflare.com/railgun Will do the same thing as any high end content delivery network as far as fixing the front end code edge cast will do that as will NetDNA, Akamai, numerous others so may I can't list them all. Information on Akamai stopping attacks The unique thing is edge cast is very fast so is Akamai you can purchase a Akamai CDN from liquid Web for $120 a month with a terabyte of bandwidth that's a lot. It will do more than the CloudFlare Railgun including help stop DDoS attacks it will do it faster and if were to spend the money on a liquid Web VPS with DDoS you would be at about $175 a month or you could start off on the base package with fire host and that would cost you $200 a month however for a month $250 you can you can add edge casts outstanding content delivery network I have accounts with liquid Web and fire host I use fire host primarily and really do not do much with liquid Web however both of them are better than CloudFlare in terms of protection and in terms of speed. http://www.thewhir.com/web-hosting-news/cn-domain-service-restored-following-massive-ddos-attack I of course have tried to use CloudFlare and found it worthless to me. My main point is for $200 a month you can get a much faster and safer setup. The other thing to remember when CloudFlare said it blocked a 300 GB attack that is considered fictitious and debatable by many in the industry myself included. I don't think switches that At 10 Gb can do that when there's only two pointing at it Here is a link from cloud flair talking about how good of a job they did saving the Internet and stopping the biggest attack ever. They did not succeed in keeping Spamhaus online so they did not stop the attack in my opinion. http://blog.cloudflare.com/the-ddos-that-almost-broke-the-internet "On Monday, March 18, 2013 Spamhaus contacted CloudFlare regarding an attack they were seeing against their website spamhaus.org. They signed up for CloudFlare and we quickly mitigated the attack." & said there was "more then than 300Gbps of attack traffic" The other big difference between CF and everyone else is they utilize there any cast network to accept the attack this slows down any one on that network instantly as it did when "the attack that almost broke the Internet happened" Instead of moving the traffic to a private cloud and dealing with it so it would not affect others using their service they basically did not have any regard for their users at that time. "The attackers were quiet for a day. Then, on March 22 at 18:00 UTC, the attack resumed, peaking at 120Gbps of traffic hitting our network. As we discussed in the previous blog post, CloudFlare uses Anycast technology which spreads the load of a distributed attack across all our data centers. This allowed us to mitigate the attack without it affecting Spamhaus or any of our other customers. The attackers ceased their attack against the Spamhaus website four hours after it started." CloudFlare actually spread the attack on to their own customers this is something that harmed everyone using their service that day for I believe five days total. http://www.theregister.co.uk/Print/2013/03/28/spamhaus_mega_ddos_little_collateral_damage/ http://www.webhostingtalk.com/showthread.php?t=1065748 Nearly half of DDoS attacks in the first half of 2013 are now larger than 1Gbps, up from 13.5 percent in 2012, http://www.thewhir.com/web-hosting-news/prolexic-stops-massive-dns-reflection-attack largest DNS reflection attack ever recorded,” which peaked at 167Gbps. If this is now the largest what was the 300gbps? It is not bad for SEO in itself however using a CAPTCHA page if it thinks your visitors is a attack or bot is very bad & happens allot I know changing your IP address can cause some issues. What I'm getting at is if you want the type of protection you were talking about there are much better methods of going about getting it. Try them out see what you think you can really only learn more about it. I hope this helps you, Thomas 
Browse Questions
Explore more categories
- 
		
		Moz ToolsChat with the community about the Moz tools. 
- 
		
		SEO TacticsDiscuss the SEO process with fellow marketers 
- 
		
		CommunityDiscuss industry events, jobs, and news! 
- 
		
		Digital MarketingChat about tactics outside of SEO 
- 
		
		Research & TrendsDive into research and trends in the search industry. 
- 
		
		SupportConnect on product support and feature requests. 
Related Questions
- 
		
		
		
		
		
		Kind of duplicate categories and custom taxonomy. Necessary, but bad for SEO?
 Hello Everyone! I'm new here! My husband and I are working on creating a website: https://sacwellness.com .The site is an online therapist directory for the the Sacramento California area. Our problem is this: In wordpress our category system is being used for blog posts. Our theme is using a custom taxonomy system to categorize different therapist specialties, therapeutic approaches, etc. We've found ourselves in a position where our custom taxonomy and categories are near duplicates. for example we have the blog categories: ADHD counseling, Anxiety therapy, and Career counseling our corresponding custom taxonomy/therapist categories are: ADHD, Anxiety, and....(oops) career counseling. My understanding is that google doesn't see a difference between identically named categories and custom taxonomies and will so choose one to rank and disregard the other, effectively leaving you competing against yourself. is this true in a case like this? Can google maybe understand the difference because of the custom taxonomy and/or URL paths? if this is a problem is it ok to have near duplicates....like ADHD vs. ADHD counseling. This has been our solution so far....but now we're questioning it....derp x_x. I thought about tagging the categories with no index, but I think the archive pages would be useful for people. Essentially we have 2 sets of archives for each keyword. One is for blog posts, and one is for therapists who work with that particular issue along with the 6 most recent blog posts in that category.....because we are putting the 6 most recent blog posts at the bottom of the therapist pages I feel like it wouldn't be as terrible of a loss if we had to noindex the category pages. ....what do you think? Thank you! Intermediate & Advanced SEO | | angelamaemae0
- 
		
		
		
		
		
		Default Wordpress 301 Redirects of JS and CSS files. Bad for SEO & How to Fix?
 Hi there: We are developers with some digital marketing expertise, but a current issue has us perplexed. An outside SEO firm has asked us to clean up a large number of 301 redirects. Most of these are 'default' Wordpress behavior that relate to calling the latest version of a JS or CSS file. For instance, a JS file is called with this: https://websitexyz.com/wp-includes/js/wp-embed.min.js?ver=4.9.1 but ultimately redirects to this: https://websitexyz.com/wp-includes/js/wp-embed.min.js. We are being asked to prevent the redirect from happening by, presumably, calling the ultimate file to begin with. The issue is that, as far as we know, there's no easy way to alter WP behavior to call the ultimate file to begin with. Does anyone have any thoughts on this? Thanks. Intermediate & Advanced SEO | | Daaveey0
- 
		
		
		
		
		
		Yoast seo title question
 I was referred to this plugin and have found it to be the most irritating and poorly designed plugin in the world. I want to be able to set my titles without it changing my page headers as well. For instance - If I set my title to be "This is my article name | site name" it will make my H1 tag read the same. I do not want or desire this nonsense. Why would they think this is something wise? Why would I want my site name on every single H1 tag on my site? How can I fix this? I only want my title to be my title. I want my H1 tag to remain the post/page name that I define in wordpress. Intermediate & Advanced SEO | | Atomicx0
- 
		
		
		
		
		
		Meta Keywords Good or Bad
 Hi All, I've been reading more about the meta keyword tag and why it may not be a good idea to include them on pages and am looking for thoughts/feedback on this idea. If you have employed this tactic, can you give me some insight into any results you saw. If you decided to not employ this tactic, why did you choose not to? I wan to understand all sides of this before employing any changes to my company's websites. Thank you for your help! Intermediate & Advanced SEO | | airnwater0
- 
		
		
		
		
		
		If you have an unlimited SEO budget, what would you do?
 Here's a bit of background information: I've achieved the targets and is now being offered what is essentially an unlimited budget. I have a nice list of ideas but thought I would the brilliant people here at the SEOMOZ community what they would do. So as to promote as much response as possible, I'm going to keep my list to myself for now. And by "SEO", I mean I can do things like content strategy, blogging, infographics, etc. Shoot away! Intermediate & Advanced SEO | | andrep0
- 
		
		
		
		
		
		Are dropdown menus bad for SEO
 I have an ecommerce shop here: http://m00.biz/UHuGGC I've added a submenu for each major category and subcategory of items for sale. There are over 60 categories on that submenu. I've heard that loading this (and the number of links) before the content is very bad for SEO. Some will place the menu below the content and use absolute positioning to put the menu where it currently is now. It's a bit ridiculous in doing things backwards and wondering if search engines really don't understand. So the question is twofold: (1) Are the links better in a bottom loading sidemenu where they are now? (2) Given the number of links (about 80 in total with all categories and subcategories), is it bad to have the sidemenu show the subcategories which, in this instance, are somewhat important? Should I just go for the drilldown, e.g. show only categories and then show subcategories after? Truth is that users probably would prefer the dropdown with all the categories and second level subcategories, despite the link number and placement. Intermediate & Advanced SEO | | attorney1
- 
		
		
		
		
		
		Is DOCTYPE important for SEO?
 Hello fellow Mozzers. I am just having a brief look at a potential clients website before speaking to them tomorrow and whilst looking at the source I noticed that they don't appear to have a clear definition for their Doctype. All the have at the top of each page is I have to admit that Doctypes aren't my strong point but I know that they are normally slightly more descriptive than this. Can this have any effect on rankings? or is this just an issue for W3C validation? Thanks 🙂 Intermediate & Advanced SEO | | AdeLewis0
- 
		
		
		
		
		
		Does capitalization matter for SEO?
 Two places capitalization comes into play: (1) on-page use (title, h1, body text, img alt text, etc) (2) external anchor text I didn't think it mattered from Google's point of view for on-page usage (is this correct?) but I notice that OpenSiteExplorer' s 'anchor text distribution' tab shows different counts for the same keyword if it's capitalized in different ways (eg seomoz.org is listed separate from SEOmoz.org). Is that just OSE or does Google treat the keyword/phrase different based on its capitalization, too? And if so, then should I be creating external links to my site with the 'regular' and 'Capitalized' versions of my key phrases? Intermediate & Advanced SEO | | scanlin1
 
			
		 
			
		 
			
		 
			
		 
			
		 
			
		 
			
		 
			
		 
			
		 
					
				 
					
				 
					
				 
					
				 
					
				