Hacker News new | ask | show | jobs
by opendais 4373 days ago
If you have MX records on a cloudflare enabled domain you have to expose the Ip address of your mail server:

https://support.cloudflare.com/hc/en-us/articles/200168536-W...

If that is in the same DC as the rest of your equipment [or worse, the same server] it might be still possible to figure things out and DDoS you.

The underlying hosting is just as vulnerable w/ or w/o Cloudflare.

Last week someone spinning up their own botnet threw like 1Gbps at a side project of mine via UDP at the mail server.