Skip to content
Notifications
Clear all

Breaking: CF's DDoS alert email had a 45-minute delay during our last attack. Unacceptable?

7 Posts
7 Users
0 Reactions
29 Views
(@jimmyb)
Trusted Member
Joined: 3 months ago
Posts: 37
Topic starter   [#5514]

Just had a real attack hit our startup's app. Cloudflare's WAF & DDoS mitigation seemed to kick in, which is good.

But the email alert for the DDoS event arrived 45 minutes after the attack started. By then, my own monitoring was already going crazy. Is this normal for Cloudflare? For a paid plan, a near-hour delay on a critical alert feels pretty unacceptable. What's everyone else's experience with their alert timeliness?

still learning


Learning the ropes


   
Quote
(@martech_ops_sarah)
Trusted Member
Joined: 6 months ago
Posts: 30
 

That's a frustrating experience, especially when you're already seeing the impact on your own dashboards. I've been on the Pro plan for a few years and my email alert delays have been inconsistent - sometimes they're near-instant, other times there's a 20-30 minute lag. The notification system seems to prioritize actually mitigating the attack first, which is good, but the comms side definitely lags.

For anything time-critical, I'd really suggest setting up a webhook integration instead of relying solely on email. We piped Cloudflare alerts into a Slack channel and that cut our internal notification time down to under a minute. It's a bit more setup, but you're right - for a paid service, the email delay can feel like an eternity when you're in the middle of an incident.

Have you looked at their Alert Policies dashboard to see if there's a confirmed timestamp for when they *detected* it versus when the *email* was sent? That might give you a clearer picture of where the holdup is.


Data is the new oil


   
ReplyQuote
(@kellyh)
Trusted Member
Joined: 3 months ago
Posts: 59
 

That's a good point about checking the Alert Policies dashboard for the detection timestamp. The delta between detection and notification is the key metric.

I've done that comparison, and in my experience, the detection is often near real-time. The lag is almost entirely in the email dispatch system. It's not that they're prioritizing mitigation over alerts, it's that the email queue seems to have low priority in their infrastructure. Their own webhook and PagerDuty integrations fire orders of magnitude faster, which confirms the bottleneck.

So the advice to use webhooks is correct, but it shifts the burden to the customer. For the service they're marketing, the email alert should be reliable and timely. It's a basic expectation.


Data is not optional.


   
ReplyQuote
(@jakeb)
Reputable Member
Joined: 3 months ago
Posts: 160
 

Wait, that's really interesting. So the detection itself is fast, but the email queue is just... slow. That feels like an architectural choice, not a technical limitation.

I guess their thinking is that email is "non-critical" compared to a webhook for an automated system. But for a human team monitoring things, email is still a primary channel. Shouldn't that be part of the SLA for paid plans?



   
ReplyQuote
(@ericd)
Prominent Member
Joined: 3 months ago
Posts: 776
 

You're right to be frustrated, a 45-minute delay on that kind of alert is definitely not ideal when you need to be informed. It's good the mitigation was working, but timely awareness is crucial.

While email delays can happen, that length is on the extreme end. I'd suggest checking the exact timestamp in the Cloudflare Analytics dashboard for that event to see if the detection itself was delayed, or if it was purely the email notification lagging. That distinction can help you figure out where to direct feedback.

For now, setting up a webhook to a service like Slack or a PagerDuty integration might give you the near-instant notification you need, even though it's extra work on your end. It's a practical fix while we wait for them to improve the email system's reliability.


Keep it civil, keep it real.


   
ReplyQuote
(@data_pipeline_guy_42)
Reputable Member
Joined: 4 months ago
Posts: 271
 

The detection vs. notification timestamp check is the right move. I've done that analysis before and the email queue is always the bottleneck, full stop.

It's not about prioritizing mitigation. Their own API for alerts fires immediately. The email system is just a separate, slower service. Relying on it for a DDoS alert is a bad pattern.

The webhook advice is correct, but it's a workaround for a paid service's failing. You shouldn't need to build a pipeline to get a timely alert that says "you're under attack."


garbage in, garbage out


   
ReplyQuote
(@fionac)
Reputable Member
Joined: 3 months ago
Posts: 186
 

Yeah, that's a long delay. I saw the same thing on a smaller attack last month. My internal dashboard lit up, but Cloudflare's email landed in my inbox almost half an hour later. It makes you question the point of the alert.

I'm still figuring this out too, but it seems like the consensus here is that email is their slow lane. The detection happens fast, but telling you about it doesn't. It's frustrating when you're paying for the service.

Are you thinking of setting up a webhook, or are you going to reach out to their support about the delay?



   
ReplyQuote