Brand Protection Now Drafts Your Cease & Desist Letters!
Hey there, it's me, Shii-chan! Today I found an update that folks who protect their brand are going to like.
Cloudflare ChangelogWhat was announced?
From Cloudflare's Changelog, the Security Center Brand Protection feature now has an automated Cease & Desist (C&D) workflow.
When you find an infringing domain hosted outside of Cloudflare's network, you can generate, review, and download a custom-branded legal notice on the spot. The post says it happens "in seconds."
The story so far
Until now, Brand Protection focused on detection — spotting suspicious domains. But after spotting one, actually sending a notice meant your Trust & Safety and Legal teams had to look up recipients and draft the text by hand.
This update is meant to bridge that gap, moving you from pure detection all the way to actionable enforcement.
What changes
The manual burden drops a lot. Recipient lookup and drafting are automated, so Legal and Trust & Safety teams no longer start from a blank page. Once you spot an infringing match in the dashboard, you can move straight into preparing the notice.
Dive Deep
Here are the concrete points from the post:
- Automatic WHOIS and recipient lookup: Behind the scenes it scrapes registrar data and WHOIS contacts (like the registrant or registrar abuse email) and highlights where your notice should go.
- Smart template pre-fill: It fills your custom-branded templates with metadata like the infringing domain, registrar name, and discovery date.
- Three enforcement tones depending on the match strength:
- Exact Match: a formal demand for identical trademark infringements
- Similar Match: a standard notice tuned for typosquatting (one-character-distance matches)
- Friendly Tone: an amicable initial outreach for potentially unintentional infringements
- Full editing control: Before creating the final PDF, a real-time review screen lets you fine-tune the wording and placeholders to match your internal legal standards.
The flow is simple. When you review a malicious domain match, your path splits by where the attacker is hosted. If the domain uses Cloudflare's network or registrar, one click triggers the existing integrated abuse reporting flow. If it's hosted elsewhere, the "Generate C&D Letter" option launches the document builder — pick a template, verify the auto-populated recipient data, and download your PDF.
You manage this from Cloudflare Dashboard > Application Security > Brand Protection by selecting your detected matches. For more, read the Brand Protection documentation.
One important note: this only helps you draft — it doesn't give legal advice. The post is clear about it:
Cloudflare does not represent you and cannot provide you with legal advice.
So whether your rights were infringed, whether a C&D is appropriate, and what it should say are all up to you.
Wrap-up
- Brand Protection adds an automated Cease & Desist workflow for infringing domains hosted outside Cloudflare's network
- It automates WHOIS recipient lookup, template metadata pre-fill, and PDF generation
- Three tones — Exact Match / Similar Match / Friendly Tone — with editable text before export
- It's drafting assistance only; the legal judgment stays with you
This one lands nicely for Trust & Safety and Legal teams dealing with brand impersonation and typosquatting!