How do I monitor a website that's behind Cloudflare?
Quick answer
How do I monitor a website that's behind Cloudflare?
Allowlist your monitoring service's IP range or a shared secret header in a Cloudflare firewall rule, then point the monitor at your public hostname — not the origin IP — so you also validate that Cloudflare itself is serving traffic.
- Monitoring the origin IP bypasses Cloudflare and misses ~15% of real outages (WAF, cache, DNS).
- Set a custom request header like X-Monitor-Token: <secret> and allowlist it in a WAF rule.
- For "I'm Under Attack" mode, JS challenges block synthetic monitors — allowlist by ASN or IP.
- Watch for 522 (origin unreachable) and 524 (origin timeout) as your true origin health signals.
Step-by-step
- 1Create a WAF allowlist rule
In Cloudflare Security → WAF, create a rule that skips challenges for a shared secret header.
- 2Add the header to the monitor
Configure the monitor to send X-Monitor-Token: <secret> on every request.
- 3Point at the public hostname
Use your public hostname (not origin IP) so cache, WAF and edge routing are all validated.
- 4Alert on 522 / 524
Treat 522 and 524 as origin outages — they mean Cloudflare is up but your origin is not.