Add Cloudflare
Cloudflare can manage a domain’s DNS and proxy website traffic through its network. Proxied web records can use Cloudflare caching and security features, while email and most verification records remain DNS-only.
Before changing nameservers
- Create or sign in to the Cloudflare account that will own the domain.
- Export the current DNS zone or save a clear copy of every record.
- Identify records used by the main website, subdomains, email and third-party services.
- Confirm that the origin website already has a valid SSL certificate if you plan to use Full (strict) encryption.
Connect the domain
- Add the domain to Cloudflare and choose the appropriate plan.
- Compare the imported DNS records with the saved zone and add anything missing.
- Replace the domain’s nameservers at the registrar with the pair Cloudflare supplies.
- Wait for Cloudflare to confirm activation, then test the website, email and important subdomains.
- Use Full (strict) SSL/TLS mode when the origin server has a valid matching certificate.
Choose which records are proxied
A, AAAA and CNAME records used for public web traffic can usually be proxied. MX, TXT and other email or verification records should remain DNS-only. Review IP Addresses and Networking for the difference between a proxy address and the origin address.
Check WordPress after activation
Open the public site and WordPress admin, submit a test form and check any login, checkout or account areas. Avoid caching private or personalised pages. If HTTPS fails, check both the origin certificate and Cloudflare encryption mode rather than switching to an unencrypted origin connection.
Common questions
Frequently Asked Questions
Does adding Cloudflare move my website hosting?
No. The website remains at its existing host. Cloudflare manages DNS and can proxy traffic to that origin server.
Which Cloudflare records should be proxied?
Public web traffic on suitable A, AAAA and CNAME records can usually be proxied. Email and verification records should remain DNS-only unless the service provider explicitly instructs otherwise.
Which SSL mode should I use?
Use Full (strict) when the origin server presents a valid, unexpired certificate for the hostname. It encrypts both parts of the connection and verifies the origin certificate.
Why did email stop after changing to Cloudflare nameservers?
An MX, TXT or mail-host record may be missing or incorrect in the Cloudflare DNS zone. Compare it with the saved records and your email provider's required settings.