🔒Read the Docs Fights Off 5.5M Rpm DDoS Attack
Read the Docs' DDoS Battle: Lessons Learned
TL;DR
Read the Docs faced a 5.5 million requests per minute DDoS attack in June 2026, testing its defenses and highlighting the need for advanced rate limiting and caching strategies.
Read the Docs recently endured a massive DDoS attack hitting 5.5 million requests per minute, 10x larger than any previous incident. This attack lasted nearly ten days, showcasing the importance of robust edge defenses and rate limiting. The attackers used sophisticated techniques like header and TLS randomization to evade detection, underscoring the need for multi-layered security. Key to surviving this attack was leveraging Cloudflare for caching and rate limiting, combined with targeted rules to challenge suspicious traffic without disrupting legitimate users.

Key Points
Read the Docs experienced a DDoS attack in June 2026, peaking at 5.5 million requests per minute.
The attack lasted nearly ten days, testing the company's infrastructure and incident response.
Attackers used header and TLS randomization to evade signature-based filters, making detection harder.
Cloudflare's caching and rate limiting were crucial in mitigating the attack's impact.
Read the Docs implemented targeted rate limiting rules to challenge suspicious traffic without disrupting legitimate users.
Why It Matters
If you're running a public documentation site, this is a wake-up call. Read the Docs' experience shows how quickly DDoS attacks can evolve, requiring constant adaptation of security measures. For teams relying on Cloudflare or similar services, understanding how to fine-tune rate limiting and caching is now critical. The yo-yo pattern of attack and retreat highlights the need for dynamic defense strategies.
Frequently Asked Questions
Why does this matter?
If you're running a public documentation site, this is a wake-up call. Read the Docs' experience shows how quickly DDoS attacks can evolve, requiring constant adaptation of security measures. For teams relying on Cloudflare or similar services, understanding how to fine-tune rate limiting and caching is now critical. The yo-yo pattern of attack and retreat highlights the need for dynamic defense strategies.
What happened?
Read the Docs faced a 5.5 million requests per minute DDoS attack in June 2026, testing its defenses and highlighting the need for advanced rate limiting and caching strategies.
Comments
Be the first to comment
Enjoyed this article?
Get it daily. 7am. Free. Reads in 5 minutes.
Join 3,472 builders reading daily.