New 24/7 monitoring and daily cloud backups now included in every Shield Pro plan.

Help Centre

BugShield Knowledge Base

Guides, walkthroughs, and answers for getting the most out of your account.

Add Cloudflare

Cloudflare can manage a domain’s DNS and proxy website traffic through its network. Proxied web records can use Cloudflare caching and security features, while email and most verification records remain DNS-only.

Before changing nameservers

  • Create or sign in to the Cloudflare account that will own the domain.
  • Export the current DNS zone or save a clear copy of every record.
  • Identify records used by the main website, subdomains, email and third-party services.
  • Confirm that the origin website already has a valid SSL certificate if you plan to use Full (strict) encryption.

Connect the domain

  1. Add the domain to Cloudflare and choose the appropriate plan.
  2. Compare the imported DNS records with the saved zone and add anything missing.
  3. Replace the domain’s nameservers at the registrar with the pair Cloudflare supplies.
  4. Wait for Cloudflare to confirm activation, then test the website, email and important subdomains.
  5. Use Full (strict) SSL/TLS mode when the origin server has a valid matching certificate.

Choose which records are proxied

A, AAAA and CNAME records used for public web traffic can usually be proxied. MX, TXT and other email or verification records should remain DNS-only. Review IP Addresses and Networking for the difference between a proxy address and the origin address.

Check WordPress after activation

Open the public site and WordPress admin, submit a test form and check any login, checkout or account areas. Avoid caching private or personalised pages. If HTTPS fails, check both the origin certificate and Cloudflare encryption mode rather than switching to an unencrypted origin connection.

Common questions

Frequently Asked Questions

Does adding Cloudflare move my website hosting?

No. The website remains at its existing host. Cloudflare manages DNS and can proxy traffic to that origin server.

Which Cloudflare records should be proxied?

Public web traffic on suitable A, AAAA and CNAME records can usually be proxied. Email and verification records should remain DNS-only unless the service provider explicitly instructs otherwise.

Which SSL mode should I use?

Use Full (strict) when the origin server presents a valid, unexpired certificate for the hostname. It encrypts both parts of the connection and verifies the origin certificate.

Why did email stop after changing to Cloudflare nameservers?

An MX, TXT or mail-host record may be missing or incorrect in the Cloudflare DNS zone. Compare it with the saved records and your email provider's required settings.

Still need help?

Can’t find what you need? Our team is here to help.

Contact us