Cloudflare sits between your visitors and your site. It answers DNS, terminates TLS, caches static content close to users, absorbs DDoS traffic and can filter malicious requests with a web application firewall (WAF). Set up well, it makes a site faster and harder to knock over. Set up carelessly, it can cause redirect loops or serve the wrong page to the wrong person.
Setup order that avoids surprises
- Add the domain and let Cloudflare import your existing DNS records. Compare them against your current zone before changing nameservers.
- Mark mail records (MX, SPF, DKIM, DMARC) as DNS only. Proxying them breaks email.
- Set SSL/TLS to Full (strict) and install a valid certificate on the origin. A free Cloudflare Origin CA certificate works for this.
- Switch nameservers at your registrar and watch traffic for a day.
- Only then turn on Always Use HTTPS, HSTS, caching rules and the WAF managed rules.
Lock the origin down
A proxy only protects you if attackers cannot go around it. Restrict your origin so it accepts traffic only from Cloudflare, either with Authenticated Origin Pulls or firewall rules for Cloudflare's published IP ranges, and avoid exposing the origin's real address in DNS records or email headers.
Common mistakes
| Mistake | What goes wrong | Fix |
|---|---|---|
| SSL mode set to Flexible | Traffic from Cloudflare to your server is unencrypted; redirect loops are common | Use Full (strict) with a valid origin certificate |
| Caching personalised HTML | One visitor can be served another visitor's page | Cache static assets only; bypass cache for logged-in and cart pages |
| Origin IP still reachable | Attackers hit the server directly and skip your protection | Allow only Cloudflare to reach the origin |
| Mail records proxied | Email stops working | Set MX and mail-related records to DNS only |
| No rate limiting on forms and logins | Credential stuffing and spam | Add rate limiting and Turnstile to sensitive endpoints |
