# Preventing DDoS on a Discourse instance?

**URL:** https://meta.discourse.org/t/preventing-ddos-on-a-discourse-instance/133348
**Category:** Support
**Created:** [November 13, 2019, 11:24pm UTC](https://meta.discourse.org/t/preventing-ddos-on-a-discourse-instance/133348 "2019-11-13T23:24:03Z")
**Posts on this page:** 1
**Showing post:** 9

<div class="post-metadata">

### Author: ![HAWK](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/hawk/32/86627_2.png) [@HAWK](https://meta.discourse.org/u/HAWK)
#### Post date: [March 14, 2022, 3:28am UTC](https://meta.discourse.org/t/preventing-ddos-on-a-discourse-instance/133348/9 "2022-03-14T03:28:26Z")

</div>

There are a few more recent topics that cover this.

> [@How to protect a server's IP from being exposed?](https://meta.discourse.org/t/how-to-protect-a-servers-ip-from-being-exposed/217424):
>
> My forum has CloudFlare and when inserting a URL from this service, I can get the real IP of my server, this is a big gift for DDoS attacks. I checked it on the Discourse Meta and this forum don’t have URL-filtration too. Blocked domain by IPlogger can’t help because the attacker can use a custom domain using the script for logger ip address. I think need use whitelist to filter domain who can use onebox. Example: if admin allow only url from Youtube, Twitter, Imgur, all other ur…

---

_[View the full topic](https://meta.discourse.org/t/preventing-ddos-on-a-discourse-instance/133348)._
