# Putting Cloudflare in front of your website, safely

*Cloud & Edge · 6 min read · Updated 2026-10-07 · https://www.jbrichardson.com/resources/cloudflare-in-front-of-your-site*

**Short answer:** Put Cloudflare in front of your site by importing DNS, setting SSL/TLS to Full (strict) with a valid origin certificate, and only then enabling caching and the WAF. Keep mail records DNS-only, cache static assets rather than personalised pages, and restrict the origin to Cloudflare traffic so attackers cannot bypass the protection.

Cloudflare sits between your visitors and your site. It answers DNS, terminates TLS, caches static content close to users, absorbs DDoS traffic and can filter malicious requests with a web application firewall (WAF). Set up well, it makes a site faster and harder to knock over. Set up carelessly, it can cause redirect loops or serve the wrong page to the wrong person.

## Setup order that avoids surprises

1. Add the domain and let Cloudflare import your existing DNS records. Compare them against your current zone before changing nameservers.
2. Mark mail records (MX, SPF, DKIM, DMARC) as DNS only. Proxying them breaks email.
3. Set SSL/TLS to Full (strict) and install a valid certificate on the origin. A free Cloudflare Origin CA certificate works for this.
4. Switch nameservers at your registrar and watch traffic for a day.
5. Only then turn on Always Use HTTPS, HSTS, caching rules and the WAF managed rules.

## Lock the origin down

A proxy only protects you if attackers cannot go around it. Restrict your origin so it accepts traffic only from Cloudflare, either with Authenticated Origin Pulls or firewall rules for Cloudflare's published IP ranges, and avoid exposing the origin's real address in DNS records or email headers.

## Common mistakes

| Mistake | What goes wrong | Fix |
| --- | --- | --- |
| SSL mode set to Flexible | Traffic from Cloudflare to your server is unencrypted; redirect loops are common | Use Full (strict) with a valid origin certificate |
| Caching personalised HTML | One visitor can be served another visitor's page | Cache static assets only; bypass cache for logged-in and cart pages |
| Origin IP still reachable | Attackers hit the server directly and skip your protection | Allow only Cloudflare to reach the origin |
| Mail records proxied | Email stops working | Set MX and mail-related records to DNS only |
| No rate limiting on forms and logins | Credential stuffing and spam | Add rate limiting and Turnstile to sensitive endpoints |

> **Check your host first** Some hosting platforms, Vercel among them, recommend not placing another proxy in front of their network because it can interfere with their own caching and routing. If your site is on one of these, use Cloudflare for DNS and security rules the platform supports, and read its guidance before proxying.

---
Published by JBRichardson LLC, 1603 North Olden Ave, Ewing, NJ 08638. Phone (609)-564-3016. https://www.jbrichardson.com/contact
