Rate limiting rules · Cloudflare Web Application Firewall (WAF) docs | Latest TMZ Celebrity News & Gossip | Watch TMZ Live Skip to content
Cloudflare Docs

Rate limiting rules

Rate limiting rules allow you to define rate limits for requests matching an expression, and the action to perform when those rate limits are reached.

Rule parameters

Like other rules evaluated by Cloudflare's Ruleset Engine, rate limiting rules have the following basic parameters:

  • An expression that specifies the criteria you are matching traffic on using the Rules language.
  • An action that specifies what to perform when there is a match for the rule and any additional conditions are met. In the case of rate limiting rules, the action occurs when the rate reaches the specified limit.

Besides these two parameters, rate limiting rules require the following additional parameters:

  • Characteristics: The set of parameters that define how Cloudflare tracks the rate for this rule.
  • Period: The period of time to consider (in seconds) when evaluating the rate.
  • Requests per period: The number of requests over the period of time that will trigger the rate limiting rule.
  • Duration (or mitigation timeout): Once the rate is reached, the rate limiting rule blocks further requests for the period of time defined in this field.
  • Action behavior: By default, Cloudflare will apply the rule action for the configured duration (or mitigation timeout), regardless of the request rate during this period. Some Enterprise customers can configure the rule to throttle requests over the maximum rate, allowing incoming requests when the rate is lower than the configured limit.

Refer to Rate limiting parameters for more information on mandatory and optional parameters.

Refer to How Cloudflare determines the request rate to learn how Cloudflare uses the parameters above when determining the rate of incoming requests.

Important remarks

  • Rate limiting rules are evaluated in order, and some actions like Block will stop the evaluation of other rules. For more details on actions and their behavior, refer to the actions reference.

  • Rate limiting rules are not designed to allow a precise number of requests to reach the origin server. In some situations, there may be a delay (up to a few seconds) between detecting a request and updating internal counters. Due to this delay, excess requests could still reach the origin server before Cloudflare enforces a mitigation action (such as blocking or challenging) in our global network.

  • Applying rate limiting rules to verified bots might affect Search Engine Optimization (SEO). For more information, refer to Improve SEO.


Availability

FeatureFreeProBusinessEnterprise with app securityEnterprise with Advanced Rate Limiting
Available fields
in rule expression
Path, Verified BotHost, URI, Path, Full URI, Query, Verified BotHost, URI, Path, Full URI, Query, Method, Source IP, User Agent, Verified BotGeneral request fields, request header fields, Verified Bot, Bot Management fields1General request fields, request header fields, Verified Bot, Bot Management fields1, request body fields2
Counting characteristicsIPIPIP, IP with NAT supportIP, IP with NAT supportIP, IP with NAT support, Query, Host, Headers, Cookie, ASN, Country, Path, JA3/JA4 Fingerprint1, JSON field value2, Body2, Form input value2, Custom
Available fields
in counting expression
N/AN/AAll rule expression fields, Response code, Response headersAll rule expression fields, Response code, Response headersAll rule expression fields, Response code, Response headers
Counting modelNumber of requestsNumber of requestsNumber of requestsNumber of requestsNumber of requests, complexity score
Rate limiting
action behavior
Perform action during mitigation periodPerform action during mitigation periodPerform action during mitigation periodPerform action during mitigation period, Throttle requests above rate with block actionPerform action during mitigation period, Throttle requests above rate with block action
Counting periods10 sAll supported values up to 1 min3All supported values up to 10 min3All supported values up to 65,535 s3All supported values up to 65,535 s3
Mitigation timeout periods10 sAll supported values up to 1 h3All supported values up to 1 day3All supported values up to 1 day3 4All supported values up to 1 day3 4
Number of rules1255 or more5100

Footnotes

1: Only available to Enterprise customers who have purchased Bot Management.

2: Availability depends on your WAF plan.

3: List of supported counting/mitigation period values in seconds:
10, 15, 20, 30, 40, 45, 60 (1 min), 90, 120 (2 min), 180 (3 min), 240 (4 min), 300 (5 min), 480, 600 (10 min), 900, 1200 (20 min), 1800, 2400, 3600 (1 h), 65535, 86400 (1 day).
Not all values are available on all plans.

4: Enterprise customers can specify a custom mitigation timeout period via API.

5: Enterprise customers must have application security on their contract to get access to rate limiting rules. The number of rules depends on the exact contract terms.

Footnotes

  1. Only available to Enterprise customers who have purchased Bot Management. 2 3

  2. Availability depends on your WAF plan. 2 3 4

  3. Supported period values in seconds:
    10, 15, 20, 30, 40, 45, 60 (1 min), 90, 120 (2 min), 180 (3 min), 240 (4 min), 300 (5 min), 480, 600 (10 min), 900, 1200 (20 min), 1800, 2400, 3600 (1 h), 65535, 86400 (1 day). 2 3 4 5 6 7 8

  4. Enterprise customers can specify a custom mitigation timeout period via API. 2

  5. Enterprise customers must have application security on their contract to get access to rate limiting rules. The number of rules depends on the exact contract terms.

Next steps

Refer to the following resources:

For Terraform examples, refer to Rate limiting rules configuration using Terraform.


TMZ Celebrity News – Breaking Stories, Videos & Gossip

Looking for the latest TMZ celebrity news? You've come to the right place. From shocking Hollywood scandals to exclusive videos, TMZ delivers it all in real time.

Whether it’s a red carpet slip-up, a viral paparazzi moment, or a legal drama involving your favorite stars, TMZ news is always first to break the story. Stay in the loop with daily updates, insider tips, and jaw-dropping photos.

🎥 Watch TMZ Live

TMZ Live brings you daily celebrity news and interviews straight from the TMZ newsroom. Don’t miss a beat—watch now and see what’s trending in Hollywood.