The following limitations apply to Spectrum applications.
By default, an account is limited to 10 unique Spectrum hostnames using Cloudflare-managed IPv4 addresses, across all zones on the account. Each hostname is backed by a dedicated IPv4 address, and this quota is applied at the account level — not per zone.
IPv6-only Spectrum applications do not count against this quota.
If you need more than 10 IPv4-backed Spectrum hostnames, you can:
- Use BYOIP — bring your own IP space so Spectrum applications are not constrained by the default shared-IPv4 allocation.
- Use IPv6-only Spectrum applications — IPv6 addresses are not subject to the same scarcity as IPv4.
- CNAME multiple subdomains to a single Spectrum application — point several DNS-only (gray-clouded)
CNAMErecords at one Spectrum application hostname. This works only when those hostnames share the same origin (one origin per application). - Use Cloudflare for SaaS — configure the Spectrum application as the target (fallback origin) for Custom Hostnames.
Contact your account team if you expect to exceed the quota.
At the moment, HTTPS applications do not support HTTP/3.
Cloudflare does not support packet fragmentation for UDP packets. If packets are fragmented, they will be dropped at Cloudflare’s edge.
Spectrum UDP applications are supported with BYOIP, including CDN and Spectrum service bindings. They are not currently supported with Magic Transit service bindings.
Minecraft Java Edition is supported but Minecraft Bedrock Edition is not supported.
Universal SSL is not compatible with Cloudflare Spectrum. Use either an advanced certificate or a custom certificate instead.
When using Spectrum as an on-ramp into Private Network Load Balancing, the proxy protocol setting in Spectrum is not supported. This applies regardless of the off-ramp used to reach your private origin, including Cloudflare WAN and Cloudflare Tunnel.
Integrating Spectrum with Cloudflare Tunnel is only supported for HTTP/HTTPS applications. This is because Spectrum must upstream the request through the Layer 7 CDN products to reach the Tunnel service.
To correctly route traffic from Spectrum through a Cloudflare Tunnel, you must:
- Configure your Spectrum application with the type set to HTTP or HTTPS.
- Point the Spectrum application's origin to a hostname that is already routing traffic through your Cloudflare Tunnel (for example, via a DNS record or Cloudflare Load Balancer).
Using a Spectrum application of any other type (for example, TCP) with a Cloudflare Tunnel origin directly is not supported. Pointing a Spectrum application's origin directly to your Tunnel's subdomain (<UUID>.cfargotunnel.com) is also not a valid configuration and will not work.
By default, Spectrum is configured to listen on all ports, which can raise concerns for security auditors. However, it is important to note that Spectrum will only proxy connections from edge ports that are specifically configured within Cloudflare.
When a TCP handshake is initiated to any port for a Spectrum IP, the handshake will always be completed. If there is a Spectrum application configured for the port, the connection will be proxied to origin. If no application is configured, the connection is immediately terminated and no origin connection will be opened.
Spectrum will only ever proxy traffic to an origin if there is a Spectrum application configured for that port.
Currently, custom rules do not work with Spectrum applications. Use IP Access rules to allowlist, block, and challenge traffic for Spectrum applications based on the request's IP address, Autonomous System Number (ASN), or country.
Refer to Configuration options for more information.