Cloudflare is one of the most popular services for improving website performance and security, but if you've never used it before, the setup process can feel intimidating. This guide assumes you know nothing about Cloudflare and walks you through your first working configuration step by step.
What Is Cloudflare?
Cloudflare is a content delivery network (CDN) and security platform that sits between your website visitors and your web hosting server. When someone visits your site, their request goes through Cloudflare's network first, which can cache static content, filter malicious traffic, and optimize delivery.
Think of Cloudflare as a protective and accelerating layer in front of your hosting. Your hosting server remains the origin—the place where your actual website files live—but Cloudflare handles much of the incoming traffic.
Key benefits:
- Performance: Content is served from data centers closer to your visitors
- Security: Built-in DDoS protection and Web Application Firewall (WAF)
- SSL/TLS: Free SSL certificates for encrypted connections
- Analytics: Traffic insights and threat monitoring
- Uptime: Continues serving cached content even if your origin goes down temporarily
Cloudflare offers a generous free tier that covers most basic needs, making it accessible for personal sites, small businesses, and development projects.
Prerequisites
Before you begin, you'll need:
- A registered domain name (e.g., example.com)
- Access to your domain registrar account (where you bought the domain)
- Access to your web hosting control panel or DNS management
- About 15-30 minutes of focused time
You do not need to move your hosting or change where your website files are stored. Cloudflare only changes how traffic reaches your existing server.
Step 1: Create Your Cloudflare Account
Go to the Cloudflare website and sign up for a free account:
- Visit cloudflare.com and click Sign Up
- Enter your email address and create a strong password
- Verify your email address by clicking the link sent to your inbox
- Log in to your new Cloudflare dashboard
The free plan is selected by default and includes most features you'll need as a beginner.
Step 2: Add Your Domain to Cloudflare
Once logged in, you'll see the dashboard with an option to add a site.
- Click Add a Site or Add Site in the top navigation
- Enter your domain name (without www, just the bare domain like
example.com) - Click Add Site
- Select the Free plan and click Continue
Cloudflare will now scan your existing DNS records. This process typically takes 30-60 seconds.
Step 3: Review and Import DNS Records
Cloudflare attempts to automatically detect your current DNS records by querying public DNS servers. This is a critical step—these records tell the internet where to find your website, email servers, and other services.
Understanding DNS Record Types
You'll see several types of records:
- A record: Maps your domain to an IPv4 address (e.g., 192.0.2.1)
- AAAA record: Maps your domain to an IPv6 address
- CNAME record: Creates an alias pointing to another domain
- MX record: Directs email to your mail servers
- TXT record: Stores text data, often used for verification and email authentication
Review the Detected Records
Cloudflare displays all records it found. Carefully review this list:
- Look for your main A record (usually @ or your bare domain)
- Check for a www CNAME or A record
- Verify MX records if you use email with this domain
- Confirm any subdomains you actively use
Orange cloud vs. gray cloud:
Next to each DNS record, you'll see a cloud icon that can be orange (proxied) or gray (DNS-only).
- Orange cloud (proxied): Traffic flows through Cloudflare's network, enabling caching, security features, and performance optimization
- Gray cloud (DNS-only): Cloudflare only provides DNS resolution; traffic goes directly to your origin server
For your website (A and CNAME records for your main domain and www), keep the orange cloud enabled. For mail servers (MX records) and other services that shouldn't be proxied, the gray cloud is automatically set.
Add Missing Records
If Cloudflare missed any important records:
- Click Add Record
- Select the record type from the dropdown
- Enter the name (subdomain or @)
- Enter the content (IP address or target)
- Leave TTL on Auto
- Choose proxy status (orange or gray cloud)
- Click Save
When you're satisfied with the DNS records, click Continue.
Step 4: Change Your Nameservers
This is the most important step. To activate Cloudflare, you must update your domain's nameservers at your domain registrar.
What Are Nameservers?
Nameservers are authoritative servers that store DNS records for your domain. When someone types your domain into a browser, their computer queries nameservers to find out where your website is hosted.
By default, your domain uses your registrar's nameservers. Switching to Cloudflare's nameservers transfers DNS authority to Cloudflare.
Get Your Cloudflare Nameservers
Cloudflare will display two nameservers assigned to your account, looking something like:
amy.ns.cloudflare.com
reza.ns.cloudflare.com
The exact names vary per account. Keep this page open or write them down.
Update Nameservers at Your Registrar
Log in to your domain registrar (GoDaddy, Namecheap, Google Domains, etc.) and locate the nameserver settings. The exact location varies by registrar, but typically:
- Find your domain in the domain management dashboard
- Look for Nameservers, DNS Settings, or Domain Settings
- Select Custom Nameservers or Use Custom DNS
- Remove the existing nameservers
- Add the two Cloudflare nameservers exactly as shown
- Save the changes
Important: Some registrars require you to disable DNSSEC before changing nameservers. If you see a DNSSEC option, turn it off.
Wait for Propagation
Nameserver changes can take anywhere from a few minutes to 24 hours to propagate globally, though most complete within an hour. Cloudflare will send you an email when the change is detected.
You can check the Overview page in your Cloudflare dashboard to see the status. It will show "Pending Nameserver Update" until the change completes.
Step 5: Configure SSL/TLS Settings
Once your nameservers are active, configure SSL/TLS to ensure secure connections.
Understanding SSL/TLS Encryption Modes
Cloudflare offers several encryption modes that control how traffic is encrypted between visitors, Cloudflare, and your origin server:
- Navigate to SSL/TLS in the Cloudflare dashboard
- Click the Overview tab
- You'll see encryption mode options:
Off: Not recommended. Disables HTTPS entirely.
Flexible: Encrypts traffic between visitors and Cloudflare, but uses unencrypted HTTP between Cloudflare and your origin server. Use this only if your hosting doesn't support SSL.
Full: Encrypts the entire connection, but Cloudflare doesn't validate your origin server's SSL certificate. The certificate can be self-signed or expired.
Full (Strict): Encrypts the entire connection and requires a valid SSL certificate on your origin server. This is the most secure option.
Recommended Settings
If your hosting already has a valid SSL certificate (most cPanel hosts and managed hosting providers do): - Select Full (Strict)
If your hosting doesn't have SSL or you're unsure: - Select Full for now - Contact your hosting provider about installing a proper SSL certificate - Switch to Full (Strict) once your origin has valid SSL
If your hosting absolutely cannot support SSL: - Select Flexible as a temporary measure - Plan to add origin SSL as soon as possible
Enable Always Use HTTPS
- Go to SSL/TLS > Edge Certificates
- Find Always Use HTTPS
- Toggle it On
This automatically redirects all HTTP requests to HTTPS, ensuring visitors always use encrypted connections.
Enable Automatic HTTPS Rewrites
While still on the Edge Certificates page:
- Find Automatic HTTPS Rewrites
- Toggle it On
This fixes mixed content issues by automatically rewriting insecure resource URLs to use HTTPS.
Step 6: Configure Basic Security Settings
Cloudflare includes security features that protect your site from common threats.
Set Security Level
- Go to Security > Settings
- Locate Security Level
- Select your preferred level:
- Essentially Off: Minimal challenge, best for sites with no abuse
- Low: Challenges only the most threatening visitors
- Medium: Recommended default, balances security and user experience
- High: Challenges more visitors, may impact legitimate traffic
- I'm Under Attack: Activates aggressive protection, shows interstitial page to all visitors
Start with Medium and adjust based on your needs.
Enable Bot Fight Mode (Free Plan)
If you're on the free plan:
- Stay in Security > Bots
- Toggle Bot Fight Mode to On
This provides basic bot protection using challenge pages for detected bots.
Step 7: Optimize Performance Settings
Cloudflare's caching and optimization features speed up your site.
Enable Auto Minify
- Go to Speed > Optimization
- Find Auto Minify
- Check the boxes for: - JavaScript - CSS - HTML
This removes unnecessary characters from your code, reducing file sizes.
Set Caching Level
- Go to Caching > Configuration
- Locate Caching Level
- Select Standard (recommended for most sites)
Standard caches static content like images, CSS, and JavaScript while always fetching dynamic content from your origin.
Configure Browser Cache TTL
Still in Caching > Configuration:
- Find Browser Cache TTL
- Set it to 4 hours or 1 day for a good starting point
This tells visitors' browsers how long to cache content locally.
Step 8: Verify Your Setup
After completing the configuration, verify everything works correctly.
Check Your Website Loads
- Open an incognito/private browser window
- Visit your website using your domain name
- Confirm the site loads correctly
- Check that you're redirected to HTTPS
Verify SSL Certificate
Click the padlock icon in your browser's address bar and verify:
- The connection is secure
- The certificate is issued by Cloudflare
- There are no certificate warnings
Test Subdomains and Email
If you use subdomains or email:
- Visit any subdomains you configured
- Send a test email to your domain
- Verify everything functions normally
Review Analytics
After a few hours, check Analytics & Logs in your Cloudflare dashboard to see traffic patterns and security events.
Common Issues and Solutions
Website shows "Error 521" or "Error 522": Your origin server may be blocking Cloudflare's IP addresses or is offline. Check your hosting firewall settings and server status.
Website stuck in redirect loop: Your SSL/TLS mode may be incompatible with your origin. If your origin forces HTTPS, use Full or Full (Strict) mode, not Flexible.
Email stopped working: Verify your MX records are present in Cloudflare DNS and set to gray cloud (DNS-only).
Changes not appearing: DNS and cache changes take time to propagate. Try purging Cloudflare's cache under Caching > Configuration > Purge Everything.
Understanding Cloudflare's Dashboard
Familiarize yourself with key dashboard sections:
- Overview: Quick stats and status
- Analytics: Traffic insights and security events
- DNS: Manage DNS records
- SSL/TLS: Configure encryption settings
- Security: Firewall rules, rate limiting, bot protection
- Caching: Cache configuration and purging
- Speed: Optimization features
- Page Rules: Advanced traffic routing and caching rules (limited on free plan)
Next Steps After Setup
Once your basic setup is complete, consider:
- Setting up Page Rules to customize caching for specific URLs
- Configuring Firewall Rules to block or challenge specific traffic patterns
- Enabling Email Routing (free) to create email forwards without a mail server
- Exploring Workers for serverless edge computing
- Reviewing Analytics regularly to understand your traffic patterns
Conclusion
Setting up Cloudflare adds a powerful layer of security, performance, and reliability to your website without changing your hosting. By following this guide, you've configured DNS, enabled SSL/TLS encryption, activated basic security protections, and optimized content delivery.
The most important thing to remember is that Cloudflare sits in front of your hosting—it doesn't replace it. Your nameserver change routes traffic through Cloudflare's network, where requests are filtered, cached, and optimized before reaching your origin server.
Start with these baseline settings and explore additional features as you become more comfortable with the platform. Monitor your analytics to see the impact on traffic and security, and adjust settings based on your specific needs.
