Features Pricing GDPR cookie banner Google Consent Mode v2 WordPress plugin Cookiebot alternative For Agencies GDPR ePrivacy About Contact
RO | EN
Start Free →
Necessary

The __cfduid Cookie (Cloudflare): What It Is and Does

__cfduid is an HTTP cookie set by Cloudflare, historically used to distinguish individual visitors sharing the same IP address and apply security rules. It is classified as strictly necessary. Since 2021 Cloudflare has been phasing it out in favor of __cf_bm and cf_clearance, though it can still appear on sites with older integrations.

Name
__cfduid
Provider
Cloudflare
Category
Necessary
Type
HTTP cookie
Lifetime
30 days
Consent
No, but it must be listed in the cookie policy
Prevalence
found on 3 Romanian sites scanned by CookieFix

What is the __cfduid cookie?

__cfduid is an HTTP cookie historically used by Cloudflare, a content delivery network (CDN) and web security provider used by a large number of websites for attack protection and traffic optimization. The cookie appeared automatically on any site running through Cloudflare's infrastructure, set by Cloudflare's servers rather than by the site itself, from the first visit.

Cloudflare announced the gradual retirement of __cfduid starting in 2021, replacing it with more specific cookies such as __cf_bm (Bot Management) and cf_clearance. Because of this, __cfduid may still show up on sites with older configurations or outdated Cloudflare modules, which is how the CookieFix scanner identified it on a few Romanian sites in the sample.

What data it stores

The __cfduid value is a unique identifier generated by Cloudflare, used to distinguish individual clients behind the same shared IP address (for example, users on the same corporate or mobile network). The exact value format is not documented in detail publicly and may vary; we avoid guessing its internal structure.

The data is sent to Cloudflare's infrastructure rather than directly to the visited site, and is used to apply security rules at the individual client level.

What it is used for

The main purpose of __cfduid is traffic security: it lets Cloudflare tell apart requests coming from different users behind the same IP address and selectively apply measures such as rate limiting or blocking suspicious traffic, without affecting other users on the same network.

For the site owner, the benefit is indirect: the site stays functional even during automated attacks or abusive traffic, without manual intervention.

Does it require consent?

CookieFix classifies __cfduid as strictly necessary, since its stated purpose is security and the site's technical operation, not behavioral tracking or marketing. Strictly necessary cookies do not require prior visitor consent under the ePrivacy Directive (transposed in Romania through Law 506/2004), but they still must be listed in the site's cookie policy, with a clear purpose and duration.

  • Site owners should include __cfduid in their cookie policy even though it does not require consent.
  • If the site uses an older Cloudflare module, it is worth checking whether this cookie has already been replaced by __cf_bm or cf_clearance.

How to block or delete __cfduid

Visitors can delete or block __cfduid from their browser settings: Chrome, Firefox, Edge, and Safari all allow deleting cookies per domain or blocking third-party cookies from the privacy menu. Blocking it may reduce the effectiveness of some anti-bot mechanisms on the site, but it usually does not prevent basic browsing.

For site owners using a consent management platform such as CookieFix, strictly necessary cookies like __cfduid are typically allowed by default, without blocking, since they do not require consent; however, a properly configured CMP automatically blocks scripts in categories that do require visitor consent (statistics, marketing) until that consent is given, providing centralized control over all cookies on the site.

Frequently asked questions

Not in the marketing or behavioral-analysis sense; its stated purpose is traffic security, though its historical classification as "strictly necessary" has been publicly debated.

Because some sites use older versions of the Cloudflare integration or configurations that haven't been updated to the newer cookies, such as __cf_bm and cf_clearance.

No, since it is classified as strictly necessary it does not require prior consent, but it still must be listed in the site's cookie policy.

The typical duration observed is 30 days, after which the cookie expires automatically in the browser.

Updated 7 September 2026 · Information comes from the provider’s public documentation and CookieFix scans; it is not legal advice.