Skip to content
JBRichardson.comIT Cloud Solutions

Putting Cloudflare in front of your website, safely

Cloud & Edge 6 min readUpdated October 7, 2026

What Cloudflare does for DNS, caching and attack protection, the setup order that avoids outages, and the mistakes to avoid.

All guides

Cloudflare sits between your visitors and your site. It answers DNS, terminates TLS, caches static content close to users, absorbs DDoS traffic and can filter malicious requests with a web application firewall (WAF). Set up well, it makes a site faster and harder to knock over. Set up carelessly, it can cause redirect loops or serve the wrong page to the wrong person.

Setup order that avoids surprises

  1. Add the domain and let Cloudflare import your existing DNS records. Compare them against your current zone before changing nameservers.
  2. Mark mail records (MX, SPF, DKIM, DMARC) as DNS only. Proxying them breaks email.
  3. Set SSL/TLS to Full (strict) and install a valid certificate on the origin. A free Cloudflare Origin CA certificate works for this.
  4. Switch nameservers at your registrar and watch traffic for a day.
  5. Only then turn on Always Use HTTPS, HSTS, caching rules and the WAF managed rules.

Lock the origin down

A proxy only protects you if attackers cannot go around it. Restrict your origin so it accepts traffic only from Cloudflare, either with Authenticated Origin Pulls or firewall rules for Cloudflare's published IP ranges, and avoid exposing the origin's real address in DNS records or email headers.

Common mistakes

MistakeWhat goes wrongFix
SSL mode set to FlexibleTraffic from Cloudflare to your server is unencrypted; redirect loops are commonUse Full (strict) with a valid origin certificate
Caching personalised HTMLOne visitor can be served another visitor's pageCache static assets only; bypass cache for logged-in and cart pages
Origin IP still reachableAttackers hit the server directly and skip your protectionAllow only Cloudflare to reach the origin
Mail records proxiedEmail stops workingSet MX and mail-related records to DNS only
No rate limiting on forms and loginsCredential stuffing and spamAdd rate limiting and Turnstile to sensitive endpoints