Let UNPWNED Scan Your Cloudflare Site
See a yellow "Partial Scan" result on your report? If Cloudflare was detected at the perimeter, it may have challenged some scanner requests. Authentication, rate limiting, upstream availability, and network errors can create the same gaps, so the report keeps completed evidence separate from unanswered checks. Verify ownership and re-run first. UNPWNED then retries missing checks through its available scan paths without treating unanswered checks as secure.
The short version
First: verify ownership in Domains with a TXT, HTML file, or meta tag. Then connect Cloudflare if you want requested SPF or DMARC fixes or eligible scanner-access management. Read the account-wide warning before accepting scanner access, then re-run the scan.
Easiest: connect Cloudflare in one click
First prove ownership in Domains with the provided TXT, HTML file, or meta tag. Connect Cloudflare separately from Settings if you want requested DNS fixes or eligible scanner-access management, then return to re-run the scan.
One connection can enable
- Discovers authorized zones for requested DNS and scanner-access actions.
- Can auto-fix common email DNS issues (SPF and DMARC) when you ask it to.
- For an eligible paid account, lets you separately create or remove an account-level scanner access rulefor UNPWNED's dedicated IP.
We request the permissions shown on Cloudflare's consent screen, and you can revoke access from your Cloudflare profile. Connecting does not create a firewall rule by itself. Scanner access requires a second, explicit confirmation after the exact requested hostname is verified within an active parent Cloudflare zone visible to the connected token and UNPWNED confirms that its dedicated egress proxy is active. The Cloudflare token remains encrypted and server-side.
Connect Cloudflare →Prefer to do it manually?
You never have to connect anything. Verify by DNS below, re-run, and change Cloudflare protection only if the new report confirms that a challenge still prevents a one-time scan.
Verify your domain (do this first)
When you prove the site is yours, we mark the scan as owner-approved. Eligible owner-authorized requests use the signed scanner identity and additional scan paths. Cloudflare recognition of that identity is pending approval, so verification improves the available scan path but does not guarantee that Cloudflare will allow every request. DNS verification takes about two minutes and only needs one record.
Open UNPWNED, go to Domains, and add your domain. We give you a unique TXT record that looks like this:
In your Cloudflare dashboard, open DNS → Records, click Add record, choose type TXT, paste the value, and save.
Back in UNPWNED, click Verify. That is it. Re-run your scan and check whether coverage improved.
Re-run the owner-authorized scan
Verification unlocks the owner-only scan path. UNPWNED uses browser-compatible requests that retain the UNPWNED identity token, signed scanner identity, bounded retries, and a dedicated scanner egress route only after an eligible network failure. Re-run before changing Cloudflare settings, because a timeout or upstream failure can look similar to a perimeter block.
Monitoring is different
Never keep Bot Fight Mode disabled for monitoring. UNPWNED preserves your last reliable score when a scheduled scan returns partial coverage. Eligible owner-authorized requests already include Web Bot Auth compatible signatures. Cloudflare recognition is pending approval, so those signatures do not yet guarantee verified-bot treatment.
Dedicated scanner access only
UNPWNED never offers scanner access for a shared cloud address. The action remains unavailable unless the request is from a paid account, the exact requested hostname is currently verified within an active parent Cloudflare zone visible to the connected token, and the published scanner IP is routed through UNPWNED's dedicated egress proxy. If any of those checks fails, no Cloudflare rule is created.
For shared cloud egress that is neither dedicated nor published as a stable scanner range, do not create a Cloudflare IP Access Allow rule. Automatic Cloudflare IP Allow creation is disabled for every shared address.
Read before enabling scanner access
Cloudflare creates its IP Access Allow rule at the account level. It applies to every zone in the selected Cloudflare account, not only the exact requested hostname or its parent zone. For traffic from UNPWNED's dedicated scanner IP, the rule may bypass or take precedence over Bot Fight Mode, managed WAF rules, custom rules, and rate limits. Enable it only if you are authorized to make that account-wide change.
Before requesting creation, UNPWNED stores a durable intent and puts its opaque ID in the Cloudflare note only so an interrupted or uncertain response can be reconciled safely. Once the outcome is known, UNPWNED records the exact returned or recovered Cloudflare rule ID in its durable registry. A note, description, matching IP, or intent alone never authorizes deletion. If UNPWNED cannot establish the exact relationship, it deletes nothing. The UNPWNED removal action is account-wide: it removes every UNPWNED-managed scanner access rule and revokes scanner access for every hostname bound to that Cloudflare account. Your own Cloudflare rules remain unchanged.
The active registry record remains while scanner access is active. After removal, the removed record is deleted within 24 months of removal. A resolved creation intent is deleted within 24 months of resolution, while an unresolved intent remains until reconciliation. Each related scanner-access audit event is deleted within 24 months of its own timestamp. While an active record or unresolved intent remains, UNPWNED blocks Cloudflare disconnection and both self-service and administrator account deletion with an HTTP 409 Conflict response. If you already removed the rule in Cloudflare, run Remove in UNPWNED so it can verify the exact outcome and reconcile the records. The blocked action can continue only after removal and reconciliation.
If your paid plan ended or was downgraded, you can reconnect Cloudflare only to complete this cleanup. A replacement token must have access to every affected Cloudflare account and each known exact rule ID. Once no active record or unresolved intent remains, account deletion can continue and remaining registry and intent records linked to the account may be deleted by database cascade.
First: identify the exact Cloudflare event
Run the verified scan, note its time, then open your site in Cloudflare and go to Security → Events. Filter to the scan window and exact hostname. Open a matching event and check the source, action, and rule ID before changing anything.
- Bot Fight Mode: use the short one-time pause below, then restore it immediately.
- Managed Rules: keep the ruleset enabled. Send the exact rule ID and report link to support. If a temporary exception is necessary, limit it to that rule, the exact hostname, and one manual scan window, then remove it.
- Custom Rules: change only the rule that matched. Do not add an unmanaged global IP Allow rule, and restore the rule immediately after the manual scan.
- Rate limiting: wait for the limit to reset and re-run. Do not disable rate limiting for a scan.
Only when the event source is Bot Fight Mode
Use this only for a manually started scan when a matching Cloudflare Security Event identifies Bot Fight Mode as the source. Pausing Bot Fight Mode reduces bot protection for all traffic during the scan. Keep the window short, restore it immediately afterward, and do not use this path for monitoring.
- 1.Open your Cloudflare dashboard and pick your site.
- 2.Go to Security → Bots.
- 3.Toggle Bot Fight Mode to Off.
- 4.Come back to UNPWNED and re-run your scan. Wait for it to finish.
- 5.Toggle Bot Fight Mode back to On. Your protection is restored.
Why this is a last resort: this changes protection for every visitor during the scan. UNPWNED does not recommend replacing it with an IP Access Allow rule for shared cloud egress addresses. Keep protection enabled unless you are present to restore it as soon as the one-time scan finishes.
That's it
Re-run your scan. If every required check returns authoritative evidence, UNPWNED will publish an official score and grade. If coverage is still partial, keep your protection enabled and send the report link to [email protected] and we will help.
Run my scan again →Need the complete verification, Deep Scan, access review, and re-scan flow? Open the scan completion guide. For technical scanner identity and rules for other firewalls, see our Scanning Policy.
