Executive Overview
In a closely watched legal battle setting the boundaries of digital enforcement across the European Union, a panel of three judges at the Paris Judicial Court has firmly rejected a bid by French pay-TV giant Canal+ to impose crushing daily financial penalties on internet infrastructure titan Cloudflare.
Canal+ had petitioned the court to penalize Cloudflare to the tune of €50,000 ($54,000+) per day for allegedly failing to fully comply with court-ordered blockades against illegal streams of Formula 1 and MotoGP racing. The broadcaster argued that Cloudflare was dragging its feet, selectively dodging the spirit of the law by implementing geo-blocking measures solely through its Content Delivery Network (CDN) while leaving its ubiquitous public DNS resolver, 1.1.1.1, completely untouched.
However, the Paris court sided with Cloudflare on September 17, ruling that the infrastructure provider had acted in good faith, that its actions met the threshold of "reasonable measures" under European jurisprudence, and that it could not be held responsible when pirate operators fluidly migrated to alternative CDNs or deployed mirror domains.
The decision represents a major victory for infrastructure providers, public resolvers, and digital rights advocates who argue that trying to force foundational layers of the internet—such as global DNS resolvers—to act as frontline internet censors is both technically unfeasible and disproportionate. Yet, the legal war is far from over, as other entities like Quad9 face similar existential threats in French courts, keeping the broader debate over digital piracy enforcement at a fever pitch.
Detailed Chronology of the Legal Clash
The Genesis: Expanding Net of Intermediary Liability
Over the past two years, the French legal landscape has grown increasingly hostile toward digital piracy, particularly concerning live sports broadcasting. Armed with aggressive judicial authorizations, major broadcasters like Canal+ have systematically pushed beyond traditional Internet Service Providers (ISPs), dragging a wide array of auxiliary internet intermediaries into the enforcement theater.

Under the expanding scope of French court orders, entities that facilitate internet connectivity or content delivery—including virtual private networks (VPNs), search engines, public DNS resolvers, and CDN providers—have found themselves legally compelled to prevent users from accessing designated pirate domains.
In April, Canal+ secured judicial victories targeting Cloudflare. The Paris Judicial Court ordered the infrastructure firm to block access to 21 domains linked to unauthorized Formula 1 streams and 16 domains broadcasting illegal MotoGP content. The injunctions mandated that Cloudflare had to prevent French users from reaching these domains "by any effective means," covering both its DNS resolver services and its CDN. Crucially, however, the orders prescribed no explicit technical recipe for how this must be achieved, leaving the method of compliance up to Cloudflare’s discretion.
The Escalation: Canal+ Seeks €50,000 Daily Fines
Believing that Cloudflare’s compliance efforts were an intentional sleight of hand, Canal+ returned to the Paris court in May. The broadcaster alleged that Cloudflare had deliberately circumvented the spirit of the April injunctions by selectively applying blocks only via its CDN service. According to Canal+’s filings, this narrow interpretation meant that only a minuscule fraction of the targeted domains—just three out of 21 for Formula 1, and three out of 16 for MotoGP—were actually rendered inaccessible.
To compound matters, Canal+ noted that within a single week, two of those few successfully blocked sites had already popped back online, either by shifting their infrastructure to a competing CDN or by spinning up fresh mirror sites.
Citing this perceived recalcitrance, Canal+ asked the Paris court to attach punitive daily fines of €50,000 for every day a targeted site remained reachable, alongside the same crippling daily rate for any future pirate domains flagged to Cloudflare by France’s media regulator, Arcom. Additionally, the broadcaster sought €20,000 to cover legal costs.

The September Ruling: Judges Vindicate Cloudflare
On September 17, the panel of three judges delivered their verdicts on the dual penalty requests (tracked under case numbers RG 26/08243 for Formula 1 and RG 26/08228 for MotoGP).
The court acknowledged that it was undisputed that Cloudflare implemented the blocking measures exclusively via its CDN service for domains utilizing that specific infrastructure. However, the judges accepted Cloudflare’s technical defense: that the internal architecture of its public DNS resolver (1.1.1.1) makes selective, dynamic domain blocking structurally impossible without degrading the service entirely, and that forcing such measures would be entirely unreasonable.
Addressing Canal+’s statistics—which claimed Cloudflare had only blocked 72.6% of the requested domains (a figure the court’s text paradoxically utilized while noting the lower numbers cited by the broadcaster)—the judges interpreted this implementation rate not as willful non-compliance, but as evidence of a genuine, good-faith effort to thwart infringements.
Furthermore, the court absolved Cloudflare of responsibility for the transient nature of pirate networks. In a vital nuance for the tech industry, the judges ruled that Cloudflare cannot be held accountable when cunning site operators switch to rival CDNs or deploy redirects to mirror sites. The court made it clear that pursuing those moving targets is the ongoing burden of the rightsholder, who must serve notices to the new intermediaries or report mirrors to Arcom.
Ultimately, the court dismissed the penalty requests entirely, judging them to be neither necessary nor proportionate under European law, and denied Canal+’s bid for legal costs.

Supporting Context & Metrics: The Technical Reality of Internet Infrastructure
The heart of the dispute touches on a foundational architectural debate in modern networking: the role of content delivery networks versus recursive DNS resolvers.
CDN Blocking vs. DNS Resolvers
Cloudflare operates one of the world’s largest content delivery networks, caching website assets close to end users to accelerate web traffic and absorb volumetric Distributed Denial of Service (DDoS) attacks. When a pirate streaming site uses Cloudflare’s CDN, the company possesses the direct server-side visibility and control required to implement geo-blocking or pull the plug on specific routes.
Conversely, public DNS resolvers like Cloudflare’s 1.1.1.1 or Quad9 operate as the global telephone switchboard of the internet. They translate human-readable web addresses (like example.com) into numerical IP addresses. Forcing a recursive DNS resolver to block domains requires hardcoding blacklists that inspect and alter query responses on a global or regional scale. Cloudflare has consistently argued that its 1.1.1.1 resolver is architecturally unsuited for censorship duties, maintaining a strict policy of neutrality for its public DNS.
Transparency Data and Volume of Blocks
Cloudflare’s official transparency reports underscore this operational distinction. According to the company’s recent disclosures:
- Public DNS (1.1.1.1): To date, Cloudflare has not blocked a single piece of content or domain through its 1.1.1.1 public DNS resolver, despite facing persistent court orders in France and Italy.
- CDN Geoblocking: In stark contrast, Cloudflare actively utilizes its CDN framework to enforce court-mandated blocks where it has direct technical control. In the first half of the year, it geoblocked 662 domains in France across seven distinct court orders. That number surged in the second half of 2025, with Cloudflare geoblocking 1,238 domains in France under a single sweeping court order.
Real-Time Stream Mitigation vs. Blunt Instruments
Rather than relying on blunt, downstream instruments like DNS manipulation—which can easily be bypassed by savvy users switching to alternative resolvers (such as Google’s 8.8.8.8 or Cloudflare’s own 1.1.1.1)—Cloudflare advocates for dynamic, protocol-aware solutions.

In submissions to the European Commission regarding the EU Counterfeit and Piracy Watch List consultation, Cloudflare highlighted its real-time pirate stream mitigation program. This initiative allows vetted rightsholders to directly flag unauthorized live streams running through its network. According to the company, these streams are disrupted "within seconds" without requiring blunt DNS or IP address blockades.
"For live content, where speed is crucial, Cloudflare has built real-time mitigation mechanisms that allow vetted rightsholder partners to flag infringing streams," Cloudflare stated in its European Commission filing. "When those streams are running through our network, we act on them in seconds."
Official Statements and Industry Fallout
The legal victory provides a temporary sigh of relief for Cloudflare, but the broader industry implications are profound.
Broadcasters and sports rights owners argue that multi-million-euro investments in live content rights are being severely undermined by fast-moving pirate networks. From the perspective of Canal+, intermediaries that profit from the digital ecosystem—whether through transit, caching, or name resolution—must share the burden of protecting intellectual property, regardless of technical friction.
On the other side of the ledger, technology advocates and infrastructure operators view aggressive financial penalties as an existential threat to an open and neutral internet. Holding foundational network layers liable for the agile, cat-and-mouse tactics of pirate syndicates—such as instant domain switching and mirror redirection—creates an untenable legal hazard. If infrastructure providers can be fined €50,000 a day for failing to police every corner of the web, smaller non-profit providers face immediate financial ruin.

This fear is far from theoretical. Non-profit public DNS resolver Quad9 is currently staring down a nearly identical legal onslaught in France, where Qatari sports broadcaster beIN Sports is seeking catastrophic daily penalties reaching up to €580,000 for Quad9’s refusal to implement DNS-level piracy blocks. The forthcoming rulings in the Quad9 case are expected to signal whether the French judiciary will maintain its nuanced stance on technical proportionality or lean further into strict intermediary liability.
Future Outlook
The September 17 ruling by the Paris Judicial Court establishes an important judicial boundary: while major infrastructure players like Cloudflare must cooperate in good faith when equipped with appropriate tools (such as CDN geoblocking capabilities), courts are not yet willing to weaponize disproportionate fines against foundational internet layers for failing to achieve total, frictionless censorship.
However, the legal war over sports piracy in Europe is far from settled. Canal+ retains the right to appeal the Paris court’s decision, meaning this high-stakes confrontation could easily ascend to higher appellate courts. Furthermore, as regulatory bodies like the European Commission continue to review counter-piracy frameworks, the tension between safeguarding live broadcasting revenues and preserving the neutral, open architecture of the internet will remain a defining legal battleground of the digital age.
For now, Cloudflare’s 1.1.1.1 public DNS resolver remains block-free, and the company’s pragmatic, CDN-centric approach to anti-piracy enforcement has survived its most severe legal challenge to date. All eyes now turn to the looming verdict in the Quad9 case to see if this judicial leniency will extend to non-profit public resolvers, or if the squeeze on internet infrastructure is only just beginning.
