BlogsCloudflareEmail Infrastructure & Protocols

Email Infrastructure & Protocols

Email Infrastructure & Protocols

46
posts
2017–2026

Cloudflare's engagement with email infrastructure has evolved from promoting foundational security protocols like SPF, DKIM, and DMARC to offering a comprehensive Email Routing service and advanced threat protection through its Area 1 product. This evolution now includes the launch of Email Sending, a new capability for developers to send transactional emails directly from Cloudflare Workers, integrated with Email Routing to form a unified Cloudflare Email Service. The DMARC Management tool has been enhanced to provide insights into email security trends, including the analysis of Top-Level Domains (TLDs) associated with spam and malicious emails, identifying emerging threats from new gTLDs and established domains.

2026

Cloudflare DMARC Management is now generally available

6/16/2026

This post announces the general availability of Cloudflare DMARC Management with a redesigned experience. Key technical contributions include: a unified dashboard for email authentication posture, deeper report visibility with source investigation (including IP address, sending service name, DMARC/SPF/DKIM alignment, and integration with Cloudflare's Investigate tab for threat intelligence), automated status checks for DMARC, DKIM, SPF, and BIMI records with actionable recommendations, and an SPF lookup audit to trace DNS lookups and identify potential issues against the 10-lookup limit.

Email for agents - Cloudflare Email Service now in public beta

4/16/2026

Introduces Email Sending to public beta, enabling transactional email delivery from Cloudflare Workers and via a REST API. This includes automatic SPF, DKIM, and DMARC configuration for domain integration. Enhances agent capabilities by allowing asynchronous replies and outbound communication via the Agents SDK, backed by Durable Objects for state persistence and secure reply routing. Also introduces tooling for agents, including an MCP server, Wrangler CLI email commands, a Cloudflare Email Service skill, and the open-source Agentic Inbox reference application.

2025

Announcing Cloudflare Email Service’s private beta

9/25/2025

Introduces Email Sending, a new capability for sending transactional emails directly from Cloudflare Workers. This integrates with existing Email Routing to form the Cloudflare Email Service. Highlights include simplified sending via Worker bindings, automatic DNS configuration for SPF, DKIM, and DMARC, global delivery, and observability features. Also details integration with React Email for rich HTML emails and the use of Workers AI for processing inbound emails via Email Routing.

Cloudflare named a Strong Performer in Email Security by Forrester

5/30/2025

This post announces Cloudflare's recognition as a Strong Performer in Email Security by Forrester. It details the technical strengths of Cloudflare's Email Security solution, including its antimalware and sandboxing engine, malicious URL detection and web security capabilities (analyzing URLs at delivery and click-time using OCR and ML), threat intelligence derived from global network signals, advanced content analysis using LLMs and NLP for BEC and social engineering detection, unified Zero Trust dashboard for SOC teams, user quarantine workflow, enforcement of SPF, DKIM, and DMARC, and product security standards. It also highlights integrations with partner ecosystems. The post outlines Cloudflare's future vision for email security, emphasizing AI-driven automation, deeper ecosystem integrations, real-time user coaching, and enhanced detection capabilities, positioning email security as part of a broader SASE and Zero Trust strategy.

Enhance data protection in Microsoft Outlook with Cloudflare One’s new DLP Assist

3/21/2025

This post introduces DLP Assist, a new capability integrated with Cloudflare Email Security for Microsoft Outlook. It enables real-time scanning of outgoing emails for sensitive data (like PII and credit card numbers) using OCR and other detection mechanisms. It provides immediate user feedback, allows for customizable alerts, and integrates with Microsoft Purview for actions like blocking or encryption. It also supports logging via Logpush and will incorporate AI for fine-tuning confidence levels.

Email Security now available for free for political parties and campaigns through Cloudflare for Campaigns

3/17/2025

This post announces the extension of Cloudflare for Campaigns to include Email Security, making it available for free to political parties and campaigns. It details the threat landscape of phishing and spoofing attacks targeting political entities, highlights past successes in protecting campaigns during election cycles, and outlines the features of the free Email Security offering: AI-powered phishing protection, DMARC/DKIM/SPF support, real-time monitoring, seamless integration, and insightful reporting. It also references the acquisition of Area 1 Security and the partnership with Defending Digital Campaigns.

Helping civil society monitor cyber attacks with the CyberPeaceTracer and Cloudflare Email Security

2/17/2025

This post details a partnership with the CyberPeace Institute to extend Cloudflare Email Security to smaller NGOs. The CyberPeace Institute acts as a central hub, onboarding its network of NGOs with Cloudflare Email Security to aggregate real-time email threat data. This data powers a live dashboard, providing visibility into phishing campaigns and enabling proactive detection and blocking of malicious emails. The CyberPeace Tracer leverages this data to share vulnerabilities and threats faced by the NGO community, providing insights into phishing campaigns, malware infections, and publicly disclosed vulnerabilities.

2024

The role of email security in reducing user risk amid rising threats

12/19/2024

This post details Cloudflare's evolution in email security, moving beyond traditional SEG capabilities to a platform approach that integrates email security with Zero Trust services. It introduces a unified dashboard for assessing holistic user risk, focusing on identifying targeted users, impersonation attempts, and risky user behaviors. Key contributions include AI-driven threat detection, automated browser isolation, automated blocking of risky websites with custom block pages, and enhanced visibility into user actions via CASB and DLP, feeding into a Unified Risk Score. It also highlights the integration with domain registration for reporting lookalike domains and the use of DMARC management for spoofing prevention.

How Cloudflare Cloud Email Security protects against the evolving threat of QR phishing

4/17/2024

This post details Cloudflare's ongoing efforts to combat QR phishing (quishing) using its cloud email security solution (formerly Area 1). It explains how quishing bypasses traditional email detection by embedding malicious links within QR codes, requiring computer vision capabilities for detection. Cloudflare's strategy involves a two-part approach: identifying and scanning QR codes using computer vision and then analyzing the decoded content with existing phishing detection engines. The post highlights the challenges of obfuscated QR codes and the use of impersonation tactics by attackers, showcasing Cloudflare's proactive ML-driven hunting and analysis to neutralize these threats.

From .com to .beauty: The evolving threat landscape of unwanted email

3/26/2024

This post analyzes email security trends, focusing on the correlation between Top-Level Domains (TLDs) and the prevalence of spam and malicious emails. It details Cloudflare's findings from 2023, highlighting that recently introduced generic TLDs (gTLDs) and those associated with specific industries like beauty are disproportionately used for malicious purposes. The analysis quantifies the percentage of spam and malicious emails for various TLDs and categorizes them by TLD type (ccTLDs, .com/.net, new gTLDs). It also tracks changes in TLD patterns from the first half to the second half of 2023, noting the rise of certain gTLDs in problematic rankings. The post discusses the historical context of email and domain names, the scale of unwanted emails processed by Cloudflare Email Security, and the evolving tactics of cybercriminals leveraging TLDs for phishing and spam.

Launching email security insights on Cloudflare Radar

3/8/2024

This post introduces a new Email Security section on Cloudflare Radar, leveraging data from Cloudflare's Email Routing and Area 1 Security services. It details new metrics for tracking malicious email volume, categorizing threats (Attachment, Link, Impersonation, Other), and identifying dangerous Top-Level Domains (TLDs). The post provides specific data points and trends observed in February 2024, including spikes in malicious email volume correlating with events like the Super Bowl and Valentine's Day. It also highlights the API endpoints for accessing this new data.

2023

Email Routing subdomain support, new APIs and security protocols

10/26/2023

This post introduces support for two new email security protocols: Authenticated Received Chain (ARC) and MTA Strict Transport Security (MTA-STS) for Cloudflare Email Routing. ARC preserves email authentication results (SPF, DKIM) through intermediate servers. MTA-STS enhances SMTP security by enforcing TLS connections. It also announces new Email Workers APIs that allow sending emails programmatically from Workers and further enhance incoming email processing capabilities.

See what threats are lurking in your Office 365 with Cloudflare Email Retro Scan

9/29/2023

Introduced a 'Retro Scan' feature for Cloudflare Area 1 Email Security, enabling customers to scan historical Office 365 emails for threats missed by existing security tools. This involves obtaining authorization for message scanning and Active Directory access, configuring scan parameters (domains, other security vendors), and presenting scan results categorized by threat type (Malicious, Suspicious, Spoof, Spam, Bulk) and targeted employees. The feature is currently in closed beta.

Cloudflare Email Security now works with CrowdStrike Falcon LogScale

9/21/2023

This post details the integration of Cloudflare Email Security with CrowdStrike Falcon LogScale. It outlines the technical steps required to set up webhook alerts from Cloudflare Email Security to ingest detection data into Falcon LogScale, including generating ingest tokens and configuring the SIEM target. It also highlights the provision of a parser and dashboard within Falcon LogScale for analyzing this data.

Cloudflare partners with KnowBe4 to equip organizations with real-time security coaching to avoid phishing attacks

3/17/2023

This post announces the integration of Cloudflare's Area 1 email security solution with KnowBe4's Security Awareness Training platform (KSMAT) and SecurityCoach. This integration enables real-time security coaching for employees when Area 1 detects malicious attachments, links, spoofed emails, or suspicious emails. The post details the technical steps for setting up this integration and highlights its importance in addressing human error as a significant factor in phishing attacks.

How we built DMARC Management using Cloudflare Workers

3/17/2023

This post details the technical implementation of Cloudflare's DMARC Management service. It explains how Cloudflare Workers and Email Routing are used to process incoming DMARC reports. Key technical components include: receiving emails via Email Routing, extracting the RUA from the 'to' attribute, using Workers KV to store domain information, reading the raw email into an ArrayBuffer, parsing MIME parts using libraries like postal-mime, storing compressed reports in R2 object storage, and publishing data to the Workers Analytics Engine using a defined schema. The architecture leverages workerd runtime and Capnproto for inter-process communication.

Stop brand impersonation with Cloudflare DMARC Management

3/17/2023

This post introduces DMARC Management, a new feature that simplifies the configuration and monitoring of DMARC policies. It provides insights into email sending sources, allows for one-click approval of legitimate senders, and helps organizations combat brand impersonation and email fraud. The implementation leverages Cloudflare Email Routing for report ingestion and Workers for data processing and analytics.

Accelerate building resiliency into systems with Cloudflare Workers

3/8/2023

Introduced a weighted traffic routing module implemented as a Cloudflare Worker to improve the resiliency of email notification systems. This worker sits between internal services and external Email Service Providers (ESPs), dynamically routing emails based on configurable weights. This approach allows for rapid failover between ESPs during outages, maintains sender reputation by ensuring continuous traffic to all configured ESPs, and leverages Workers for automatic scaling and near-instantaneous global deployment upon configuration changes.

API-based email scanning

1/12/2023

Introduced an open beta for Microsoft 365 domain onboarding via the Microsoft Graph API for Cloudflare Area 1 email security. This API-based onboarding allows for quicker deployment times and more flexibility compared to traditional MX record changes, by evaluating all messages associated with a domain directly through the Microsoft Graph API. This is particularly beneficial for organizations undergoing M&A transactions. The post details the setup wizard and authorization process, and outlines future plans for retroactive scanning, granular mailbox scanning control, and hybrid deployment options (API + MX records).

Email Link Isolation: your safety net for the latest phishing attacks

1/11/2023

This post announces the General Availability (GA) of Email Link Isolation, a new feature within Cloudflare Area 1. It details how Email Link Isolation works by rewriting suspicious links, presenting an interstitial page to users for increased vigilance, and leveraging Cloudflare Browser Isolation for protection against malware and vulnerabilities when users choose to proceed. The post highlights the feature's integration with Area 1's existing capabilities, its ease of deployment, and the positive feedback received during its beta phase, emphasizing its role as a crucial last layer of defense against sophisticated phishing attacks.

How Cloudflare Area 1 and DLP work together to protect data in email

1/11/2023

This post details the integration of Cloudflare Area 1 Email Security with Cloudflare One's Data Loss Prevention (DLP) capabilities. It explains how DLP leverages Cloudflare One's HTTP(s) filtering to inspect and control traffic to corporate email applications like Google Suite and O365, preventing the upload of sensitive data. It also describes how Area 1 enforces strong TLS standards for partner domains, prevents passive data loss by detecting account takeovers and phishing attempts, uses Email Link Isolation to protect against malicious links, and stops ransomware by analyzing attachment metadata and hash values.

2022

Expanding Area 1 email security to the Athenian Project

12/12/2022

This post details the expansion of the Athenian Project to include Cloudflare's Area 1 email security suite for state and local governments. It highlights how Area 1 provides advanced phishing and ransomware protection, complementing existing web security services offered under the Athenian Project. The post includes a case study of Rowan County, North Carolina, demonstrating the ease of deployment and effectiveness of Area 1 in detecting and blocking malicious emails.

How Cloudflare helps secure the inboxes of democracy

12/12/2022

This post details how Cloudflare's Area 1 solution protects political campaigns by analyzing millions of emails and stopping phishing attacks. It highlights specific attack vectors such as domain proximity, suspicious links, and malicious attachments, and explains how Area 1's machine learning models identify these threats. The post emphasizes the ease of deployment for campaigns and the importance of inbound technical controls given the complexity of implementing email hygiene and authentication standards like SPF, DKIM, and DMARC in rapid campaign cycles.

Click Here! (safely): Automagical Browser Isolation for potentially unsafe links in email

9/29/2022

This post introduces 'Email Link Isolation,' a new capability integrated with Cloudflare Area 1. It addresses the risk of users clicking on potentially unsafe email links by automatically rewriting them to open in a remote, isolated browser. This protects users and organizations from credential theft, malicious downloads, and browser exploits by executing untrusted content away from the user's device and corporate network. The feature leverages Cloudflare's DNS resolver, Gateway classifiers, and Browser Isolation technology.

Cloudflare Area 1 - how the best email security keeps getting better

9/20/2022

This post details the integration of Cloudflare Area 1 Email Security into the main Cloudflare dashboard, offering trials and demos. It highlights the product's ability to proactively identify and protect against phishing campaigns by scanning the internet for attacker infrastructure and incorporating data from Cloudflare's broader threat intelligence. The post also announces the launch of Cloudforce One, a threat research and operations team that will improve products based on observed TTPs and offer subscription services. Additionally, the Email Security DNS Wizard, which guides customers through SPF, DKIM, and DMARC configuration, has been integrated into the Email Security stack.

Introducing browser isolation for email links to stop modern phishing threats

6/20/2022

This post marks a significant integration of Cloudflare's Area 1 Security acquisition into the broader Cloudflare One platform. It introduces Remote Browser Isolation (RBI) specifically for email links, a new capability that enhances email security by executing suspicious links in an isolated browser. This directly addresses the challenge of modern phishing attacks that bypass traditional security controls, especially deferred and multi-channel campaigns, by accepting human error as a factor and providing a robust, post-delivery protection layer.

Area 1 threat indicators now available in Cloudflare Zero Trust

6/20/2022

This post details the integration of Area 1's threat indicator data into Cloudflare's Zero Trust suite, specifically enhancing phishing detection capabilities within Gateway and Page Shield. It highlights how the combined threat intelligence from both Area 1 and Cloudflare's existing pipelines creates a more robust dataset for identifying and blocking phishing threats, leveraging Area 1's adversary-focused research and web crawling tools.

Send email using Workers with MailChannels

5/13/2022

This post introduces a partnership with MailChannels to enable sending emails directly from Cloudflare Workers. It provides a code example for making a POST request to the MailChannels API from a Worker and demonstrates how to use the `@cloudflare/pages-plugin-mailchannels` for forms on Cloudflare Pages, simplifying email sending for contact forms and similar use cases without requiring separate email service accounts or domain validation.

Route to Workers, automate your email processing

5/13/2022

Introduces 'Route to Workers' for Cloudflare Email Routing, allowing Cloudflare Workers to process incoming emails. This feature provides an `email` event handler in Workers, exposing sender, recipient, headers, and raw body. It enables custom logic for filtering, tagging, alerting (e.g., to Slack), and forwarding emails. The post also highlights starter templates for common use cases and the integration with the existing Email Routing dashboard for easy creation and management of email-processing Workers.

Email Routing Insights

4/25/2022

Introduced an 'Overview' page for Email Routing, providing users with detailed visibility into the service's status, configuration, and email traffic. This includes routing status, DNS record verification, counts of custom and destination addresses, and advanced metrics on received, forwarded, dropped, and rejected messages. A new Activity Log offers granular details for each message, including sender, custom address, timestamp, action taken, and SPF/DMARC/DKIM status, with filtering options for easier troubleshooting.

Area 1 Security Announces the Most Spoofed Brand of 2021: WHO is Back Again?

3/31/2022

This post, originally from Area 1 Security before their acquisition by Cloudflare, highlights the prevalence of brand phishing attacks and identifies the World Health Organization (WHO) as the most spoofed brand in 2021. It details common phishing tactics, including display name spoofing and domain impersonation, and explains how attackers leverage trusted brands to bypass traditional email defenses like SPF, DKIM, and DMARC. The post emphasizes the need for advanced detection techniques, such as those employed by Area 1, to combat these sophisticated threats.

Democratizing email security: protecting individuals and businesses of all sizes from phishing and malware attacks

3/14/2022

This post announces the integration of Area 1's email security technology into Cloudflare's paid self-serve plans, offering one-click deployment for DNS email security records (SPF, DKIM, DMARC) and enhanced integration with Zero Trust products (Gateway, RBI, DLP). It also highlights the improvement of threat intelligence by connecting Area 1's data with Cloudflare's Security Center and 1.1.1.1.

Why we are acquiring Area 1

2/23/2022

This post announces the acquisition of Area 1 Security, a company specializing in cloud-native email security. The integration of Area 1's technology with Cloudflare's global network aims to provide a complete Zero Trust security platform. The post details the rationale behind focusing on email security, highlighting its importance as a threat vector and the limitations of existing solutions. It also describes Cloudflare's internal use of Area 1's technology to protect employees from phishing attempts, demonstrating its effectiveness in reducing reported phishing emails. The acquisition is positioned as a significant step in enhancing Cloudflare's security offerings by combining email threat data with Cloudflare's network threat data.

Email Routing is now in open beta, available to everyone

2/8/2022

This post announces the open beta availability of Cloudflare Email Routing, removing the waitlist and making it accessible to all zones. It highlights the product's journey from closed beta, the adoption by hundreds of thousands of zones, and the identification of new use cases and limitations. It also directs users to migration guides and community forums for feedback.

Migrating to Cloudflare Email Routing

1/27/2022

This post announces the general availability of Cloudflare Email Routing, a service that allows users to create custom email addresses for their domains and forward incoming emails to any destination inbox. It details the setup process, including defining custom and destination addresses, email verification, and automatic DNS record configuration (MX and SPF). It also explains Gmail's address conventions (plus addressing and dot ignoring) and how to use them with Email Routing via the 'Catch-all address' feature. The post highlights the privacy-first, secure, powerful, and simple nature of the service, noting its availability to all customers for free and its scalability.

2021

Tip of the ICEberg for Cloud-Native Email Security: Area 1 Named in the Gartner™ Market Guide for Email Security

12/9/2021

This post introduces the Gartner Market Guide for Email Security and the new Integrated Cloud Email Security (ICES) category. It highlights Area 1 Security's recognition as a Representative Vendor in this category, detailing how ICES solutions offer advanced threat detection (NLU, NLP, social graph analysis, image recognition), ease of use through API integration, and improved visibility and response compared to traditional Secure Email Gateways (SEGs). The post emphasizes Area 1 Horizon's capabilities, including its preemptive threat detection, flexible deployment options (API and MX record holder), and integration with SIEM/SOAR systems.

Cloudflare and the IETF

10/13/2021

This post details Cloudflare's active participation in the IETF and its contributions to the evolution of core internet protocols. It highlights how Cloudflare works to improve performance, security, privacy, and availability through standardization efforts, providing examples of incremental innovations (DoH, ECH, ODoH, MASQUE) and architectural advancements (QUIC, HTTP/3). The post emphasizes Cloudflare's commitment to building a better internet by developing, advocating, and advancing open standards.

Exported Authenticators: The long road to RFC

10/13/2021

This post introduces Exported Authenticators (EAs), a new TLS extension that significantly enhances application-layer authentication. It explains how EAs allow for stronger authentication than traditional TLS, enabling features like multiple certificates per connection and passwordless logins. The post details the design and standardization process of EAs within the IETF, highlighting their close adherence to TLS 1.3 design principles and the importance of channel binding for security. This represents a significant advancement in securing web communications beyond basic TLS.

Easily creating and routing email addresses with Cloudflare Email Routing

9/27/2021

This post introduces Cloudflare Email Routing, a new service that allows users to create any number of email addresses on their domain and redirect them to an existing mailbox. It acts as an intelligent router at the transport layer, handling the SMTP envelope to deliver messages to their final destination while preserving original headers and the body. The service does not look into, queue, or store emails, ensuring real-time delivery and privacy. The configuration process is described as simple, involving adding a domain to Cloudflare DNS, creating the desired email address, and validating the destination email. The post also mentions upcoming features and encourages user feedback.

Tackling Email Spoofing and Phishing

9/27/2021

This post introduces the Email Security DNS Wizard, a new tool designed to simplify the configuration of SPF, DKIM, and DMARC records. It explains the concepts behind email spoofing and phishing, detailing how SPF, DKIM, and DMARC work to authenticate email senders and prevent malicious use of domains. The wizard aims to guide users through the process of creating these essential DNS records, thereby improving email deliverability and enhancing security.

Sophisticated Microsoft Spoof Targets Financial Departments

3/18/2021

This post details a sophisticated Microsoft Office 365 credential harvesting campaign that targeted financial departments and executives. It highlights the advanced techniques used by attackers, including spoofing Microsoft-themed domains, using PDF/HTM/HTML attachments, and leveraging advanced phishing kits to bypass email authentication and Microsoft's native defenses. Area 1 Security's role in blocking these campaigns is emphasized, showcasing the effectiveness of their threat detection capabilities in identifying and mitigating such advanced threats.

KEMTLS: Post-quantum TLS without signatures

1/15/2021

This post introduces KEMTLS, a novel mechanism for achieving post-quantum TLS without relying on traditional signatures. It addresses the challenge of larger post-quantum cryptographic primitives by replacing handshake signatures with key encapsulation mechanisms (KEMs), significantly reducing handshake data size and improving efficiency. Cloudflare has implemented this in Golang's TLS 1.3 suite, demonstrating a commitment to future-proofing internet security against quantum computing threats.

2020

What is an Integrated Email Security solution? And is it right for your organization?

11/10/2020

This post introduces Gartner's new category of Integrated Email Security Solutions (IESS) and positions Area 1 Security as a Representative Vendor for IESS. It details how IESS provides core SEG functionalities with advantages like quick deployment and direct integrations with Office 365 and Google G Suite. The post highlights differentiating capabilities for next-generation email security products as outlined by Gartner, including Network Sandbox, Content Disarm and Reconstruction, URL Rewriting and Time-of-Click Analysis, Display Name Spoof Detection, Domain-Based Message Authentication, Reporting and Conformance on Inbound Email, Lookalike Domain Detection, and Anomaly Detection, and maps Area 1's coverage to these capabilities.

NTS is now an RFC

10/1/2020

This post announces the official RFC standardization of Network Time Security (NTS) for NTP, a protocol Cloudflare has been instrumental in developing and promoting. It highlights the importance of NTS for overall internet security by ensuring the integrity of time synchronization, and details Cloudflare's role in its development, implementation, and ongoing support, including making their time service NTS-compatible and encouraging wider adoption.

New Area 1 security study shows that U.S. State & local election administrators remain vulnerable to phish

7/26/2020

This post details a study by Area 1 Security (prior to its acquisition by Cloudflare) that analyzed the phishing vulnerabilities of U.S. state and local election administrators. It highlights findings such as the prevalence of rudimentary email protection, the use of personal email accounts for official duties, and the continued use of vulnerable Exim email servers. The post also provides recommendations for improving email security, including ending the use of Exim, transitioning to cloud email infrastructure, and ceasing the use of personal email for election duties.

2017

Why Some Phishing Emails Are Mysteriously Disappearing

12/12/2017

This post details a new technique for combating phishing by dynamically rewriting DMARC records for known malicious domains. When a DNS query for DMARC records of a known phishing domain is made, Cloudflare rewrites the policy to 'reject' on the fly. This prevents phishing emails from being delivered by instructing receiving email clients to reject them. The post also explains the underlying email authentication protocols (SPF, DKIM, DMARC) and demonstrates the technique using a fake phishing domain.