Cloudflare Rate-Limit Rule Templates for Common Attack Patterns

June 5, 2026 | 12 min read | Configuration Reference

These are production-tested Cloudflare Ruleset Engine expressions for the attack patterns DDactic most commonly finds unprotected. Each template includes the expression, the recommended threshold, the counting dimension, and the mitigation timeout. Adjust path expressions to match your application's actual endpoint structure.

Cloudflare plan requirements

Rate limiting rules via the Ruleset Engine require at minimum the Pro plan. Basic rate limiting is available on Free; advanced expressions (AND/OR, custom counting dimensions) require Business or Enterprise.

Template 1: Login Endpoint (Credential Stuffing)

# Expression scoped to POST on login paths
# Threshold: 5 requests per 60 seconds per IP
# Mitigation timeout: 10 minutes

Expression:
  (http.request.uri.path contains "/login"
    OR http.request.uri.path contains "/auth/token"
    OR http.request.uri.path contains "/oauth/token")
  AND (http.request.method eq "POST")

Action: Block
Threshold: 5
Period: 60
Mitigation timeout: 600
Counting expression: ip.src

Template 2: General API Rate Limit

# All requests under /api/ prefix
# Threshold: 200 requests per 60 seconds per IP
# Allows normal API usage while blocking sustained floods

Expression:
  http.request.uri.path matches "^/api/"

Action: Block
Threshold: 200
Period: 60
Mitigation timeout: 300
Counting expression: ip.src

Template 3: Search Endpoint (Expensive Query Protection)

# Stricter limit on expensive search/query endpoints
# Threshold: 20 requests per 60 seconds per IP

Expression:
  (http.request.uri.path contains "/search"
    OR http.request.uri.path contains "/query"
    OR http.request.uri.path contains "/find")

Action: Block
Threshold: 20
Period: 60
Mitigation timeout: 300
Counting expression: ip.src

Template 4: GraphQL Endpoint

# GraphQL endpoints need stricter limits due to query amplification
# Threshold: 30 requests per 60 seconds per IP

Expression:
  (http.request.uri.path eq "/graphql"
    OR http.request.uri.path eq "/api/graphql"
    OR http.request.uri.path contains "graphql")
  AND (http.request.method eq "POST")

Action: Block
Threshold: 30
Period: 60
Mitigation timeout: 300
Counting expression: ip.src

Template 5: Export and Report Endpoints

# Very expensive operations should have very low limits
# Threshold: 2 requests per 3600 seconds per IP

Expression:
  (http.request.uri.path contains "/export"
    OR http.request.uri.path contains "/report"
    OR http.request.uri.path contains "/download")

Action: Block
Threshold: 2
Period: 3600
Mitigation timeout: 3600
Counting expression: ip.src

Template 6: Password Reset

# Password reset endpoints are targets for enumeration + DDoS
# Also triggers SMS/email costs at scale

Expression:
  (http.request.uri.path contains "/password/reset"
    OR http.request.uri.path contains "/forgot-password"
    OR http.request.uri.path contains "/reset-password")

Action: Block
Threshold: 3
Period: 3600
Mitigation timeout: 3600
Counting expression: ip.src

Template 7: Bot Score Gating (Business/Enterprise)

# Challenge requests below bot score threshold on API paths
# This runs BEFORE rate limits to reduce legitimate traffic
# blocked by rate limits

Expression:
  (http.request.uri.path matches "^/api/")
  AND (cf.bot_management.score lt 10)
  AND (not cf.bot_management.verified_bot)

Action: Managed Challenge

Rule Priority Ordering

Apply rules in this priority order (lower number = higher priority, evaluated first): 1) Bot score challenge on all API paths. 2) Login endpoint block (strictest). 3) Export/report block (very strict). 4) Search endpoint block (strict). 5) GraphQL block (strict). 6) General API block (permissive floor). Rules higher in the list fire before lower rules, so an IP blocked by rule 2 does not get re-evaluated against rule 6.

Verify Your Rules Are Working

DDactic tests your Cloudflare rate limit rules with calibrated request sequences to confirm they fire at the right thresholds.

Run a Free Scan
CloudflareRate LimitingWAF RulesTemplatesDDoS Protection