Cloudflare refers to a well-known CDN and security platform that improves your website’s speed, availability, and protection. Routing your website traffic through Cloudflare’s global network helps reduce page load times, protect against DDoS attacks, and preserve your origin server’s IP address.
Once your domain is integrated with Cloudflare, you can decide whether specific DNS records should pass through Cloudflare’s proxy or connect directly to your server. This is controlled through the Proxy Status option.
In this post, you will learn how to set up Cloudflare for your domain and how to enable and disable the Cloudflare proxy for individual DNS records.
Here are the Prerequisites:
A registered domain name
An active Cloudflare account
Access to your domain registrar
Your web hosting or server details
Sign in to your Cloudflare account
Click Add a Domain
Enter your domain name
Now press Continue
Select the plan that best suits your requirements
Pro
Business
Enterprise
If you're setting up Cloudflare for the first time, the Free plan offers CDN, SSL Certificate, DNS management, and basic DDoS protection for most websites.
Then, click Continue
Cloudflare automatically scans your existing DNS records.
Review all crucial records before proceeding. Confirm that crucial records such as the following are available:
A Records
CNAME Records
MX Records
TXT Records
AAAA Records (if used)
If any required record is missing, add it manually before moving to the next step, as incorrect DNS records may interrupt your website or email services.
Cloudflare will represent two assigned nameservers. Log in to your domain registrar and replace your existing nameservers with the ones delivered by Cloudflare. Save the changes and wait for DNS propagation. In most cases, activation completes within a few hours, although it may take up to 24 hours, depending on your DNS cache.
After the nameserver changes have propagated successfully, Cloudflare will verify your domain automatically. Once verification is finished, your domain status will change to Active, indicating that Cloudflare is now handling your DNS.
Each DNS record in Cloudflare includes a Proxy Status option, represented by a cloud icon.
When the cloud icon is orange, requests to your website pass through Cloudflare before reaching your origin server.
With Proxy enabled, you can take advantage of:
Content Delivery Network (CDN)
DDoS protection
Website caching
Website caching
Performance optimization
SSL/TLS features
Additional security services (depending on your Cloudflare plan)
When the cloud icon is grey, Cloudflare functions only as your DNS provider.
Traffic is routed directly to your web server, and Cloudflare's performance and security features are not applied to that DNS record. This mode is commonly used for services such as mail servers, FTP, SSH, and other protocols that should not be proxied.
To enable proxy protection for a DNS record:
Log in to your Cloudflare Dashboard.
Select the domain you want to manage
Navigate to DNS.
Locate the required DNS record.
Once the icon turns orange, the proxy is enabled.
If you need traffic to bypass Cloudflare, follow these steps:
Log in to your Cloudflare account.
Select your website.
Open the DNS section.
Find the DNS record you want to modify.
Click the orange cloud icon under Proxy Status.
The icon will change to grey, indicating that the proxy has been disabled.
Enable Cloudflare Proxy for services such as:
Business websites
WordPress websites
Blog
Landing pages
E-commerce stores
Public web applications
It is recommended to keep the proxy disabled for services that require direct server communication, including:
Mail servers (MX)
SMTP
IMAP
POP3
FTP
SSH
Remote Desktop Services
Thus, setting up Cloudflare is a simple way to boost your website’s security, performance, and availability. After connecting your domain by updating its nameservers, you can handle each DNS record individually using the Proxy status option. Keeping the proxy allowed for your website enables you to utilize Cloudflare’s CDN and security features, while disabling it for services like email and FTP ensures they continue to function without interruption.