Cloudflare does not protect your site if an attacker visits your IP address directly
A lot of people setup Cloudflare and think their setup is magically totally safe from DDoS, bots, or random scanners. But there is a super common mistake here. Cloudflare only works at the DNS and proxy level.
If an attacker finds out your server actual IP number, they can just bypass Cloudflare completely and hit your port 80 or 443 directly. When that happens, every single WAF rule, DDoS protection, and firewall rule you built on Cloudflare goes straight to the trash.
So how do these guys actually find your real IP?
First off, DNS history. If your domain pointed straight to your server IP in the past before you turned on Cloudflare, that stuff is saved in public records forever.
Second, exposed subdomains. If something like mail or ftp on your domain is not running through the Cloudflare proxy, your real IP is sitting right there in the open.
Third, outbound emails. Emails sent directly by your server like welcome emails or password resets usually spill your origin IP inside the email headers.
TL;DR Cloudflare only proxies traffic sent through your domain. If an attacker discovers your server actual IP address through old DNS logs, unproxied subdomains, or system emails, they can bypass Cloudflare entirely and attack your server directly.
Source: r/StopBadBots · by /u/siterightaway