Skip to content
Back to Blog
DNS & Networking11 min read

Setup Cloudflare: The Complete 2026 Checklist

A step-by-step checklist for setting up Cloudflare correctly—from DNS migration and SSL configuration to security settings and performance optimization.

Written by Abdul AbrorTechnical Hosting Support Engineer
Setup Cloudflare: The Complete 2026 Checklist
On this page

Setting up Cloudflare correctly is the difference between a protected, fast site and one that leaks your origin IP or serves stale content. This checklist walks you through the entire setup process—DNS migration, SSL/TLS configuration, security hardening, caching rules, and final verification—so you can confidently deploy Cloudflare for any production site.

Pre-Setup: Preparation

Before you touch Cloudflare's dashboard, gather the information you'll need and document your current state.

☐ Document existing DNS records

Export or screenshot your current DNS zone. Most cPanel users can find this under Zone Editor or by running:

dig +noall +answer yourdomain.com ANY

Capture A, AAAA, MX, TXT (SPF, DKIM, DMARC), CNAME, and SRV records. You'll need these to rebuild the zone in Cloudflare.

☐ Identify critical subdomains and services

List every subdomain that must stay online: mail servers, FTP, API endpoints, staging environments, and any third-party integrations. Note which ones need direct-to-origin access (unproxied) versus which can be proxied through Cloudflare.

☐ Note your origin server IP and hosting provider

Record your server's public IP address. If you're behind a load balancer or CDN, note the actual origin IP, not an intermediate proxy. Check your hosting control panel or run:

curl -4 ifconfig.me

from your server.

☐ Create a Cloudflare account

Sign up at Cloudflare and verify your email. Choose the Free plan to start; you can upgrade later if you need advanced features like WAF rules or image optimization.

DNS Migration

Cloudflare becomes your authoritative nameserver, so DNS must be migrated cleanly.

☐ Add your site to Cloudflare

Click Add a Site, enter your domain, and select a plan. Cloudflare will scan your existing DNS records. Review the imported records carefully—automated scans miss SRV records and some TXT records.

☐ Verify and correct DNS records

Compare the scanned records against your documentation. Common issues:

  • Missing MX records (breaks email)
  • Missing SPF/DKIM/DMARC TXT records (email deliverability)
  • Missing subdomain CNAMEs (breaks staging, APIs)
  • Incorrect TTL values (Cloudflare proxies ignore TTL, but unproxied records use it)

Add any missing records manually.

☐ Set correct proxy status for each record

Cloudflare's orange cloud icon means traffic is proxied (passes through Cloudflare's network). Gray cloud means DNS-only (direct to origin). Set proxy status based on service type:

Proxy (orange cloud): - Web traffic: @, www, blog, shop - Any subdomain serving HTTP/HTTPS that benefits from caching and protection

DNS-only (gray cloud): - Mail servers: MX records, mail.yourdomain.com - FTP: ftp.yourdomain.com - SSH/custom ports - Third-party verification subdomains - Any service on non-HTTP ports

Proxying non-HTTP services will break them.

☐ Update nameservers at your registrar

Cloudflare will display two nameservers (e.g., alice.ns.cloudflare.com and bob.ns.cloudflare.com). Log into your domain registrar (GoDaddy, Namecheap, etc.) and replace the existing nameservers with Cloudflare's. Remove any third or fourth nameservers.

Nameserver changes propagate in 2-24 hours. Cloudflare will email you when the change is confirmed.

☐ Verify DNS propagation

After nameservers update, confirm DNS resolves correctly:

dig @1.1.1.1 yourdomain.com
dig @1.1.1.1 www.yourdomain.com
dig @1.1.1.1 yourdomain.com MX

Check that A records point to your origin IP and MX records point to your mail server.

SSL/TLS Configuration

Cloudflare offers free SSL certificates, but incorrect SSL mode breaks your site or leaves it insecure.

☐ Choose the correct SSL/TLS mode

Navigate to SSL/TLS > Overview and select an encryption mode:

  • Off: No encryption (never use in production)
  • Flexible: Cloudflare ↔ Visitor encrypted, Cloudflare ↔ Origin unencrypted. Use only if your origin lacks SSL and you cannot install one. Vulnerable to origin snooping.
  • Full: Cloudflare ↔ Visitor encrypted, Cloudflare ↔ Origin encrypted with any certificate (even self-signed). Acceptable for most hosting.
  • Full (Strict): Like Full, but requires a valid, trusted certificate on the origin. Recommended for production if your host provides AutoSSL or Let's Encrypt.

If your cPanel server has AutoSSL enabled, choose Full (Strict).

☐ Install an origin certificate (optional but recommended)

For stricter security, generate a Cloudflare Origin Certificate under SSL/TLS > Origin Server. This is a free 15-year certificate Cloudflare trusts. Install it on your origin server:

  1. Click Create Certificate
  2. Choose RSA 2048-bit, validity 15 years
  3. Download the certificate and private key
  4. In cPanel, go to SSL/TLS > Manage SSL Sites
  5. Paste the certificate and private key, then install

Set SSL/TLS mode to Full (Strict) after installation.

☐ Enable Automatic HTTPS Rewrites

Under SSL/TLS > Edge Certificates, enable Automatic HTTPS Rewrites. This converts insecure resource requests (HTTP images, scripts) to HTTPS, preventing mixed-content warnings.

☐ Enable Always Use HTTPS

Under SSL/TLS > Edge Certificates, enable Always Use HTTPS to redirect all HTTP traffic to HTTPS automatically. This is a 301 redirect at the edge, faster than origin-side redirects.

☐ Set Minimum TLS Version

Under SSL/TLS > Edge Certificates, set Minimum TLS Version to TLS 1.2 or higher. TLS 1.0 and 1.1 are deprecated and insecure.

☐ Verify SSL is working

Visit your site via HTTPS and check:

  • Browser shows a padlock icon
  • Certificate issuer is Cloudflare (or your custom cert if you uploaded one)
  • No mixed-content warnings in the browser console

Test with SSL Labs for a detailed report (note: this tests the Cloudflare edge, not your origin directly).

Security Hardening

Cloudflare's security features protect against bots, DDoS, and common attacks.

☐ Set Security Level

Under Security > Settings, choose a security level:

  • Essentially Off: No challenge unless highly suspicious
  • Low: Challenges known threats
  • Medium: Default, balanced protection
  • High: Challenges most visitors; use for attack mitigation
  • I'm Under Attack: Aggressive interstitial page; temporary use only

Start with Medium. Increase only if under active attack.

☐ Enable Bot Fight Mode (Free plan) or configure Bot Management

Under Security > Bots, enable Bot Fight Mode on the Free plan. This challenges known bad bots. Paid plans get advanced bot scoring and allow custom rules.

☐ Review and configure Firewall Rules (paid) or WAF Managed Rules

Free plans have limited firewall capabilities. Paid plans unlock:

  • WAF Managed Rulesets under Security > WAF: Enable the Cloudflare Managed Ruleset and OWASP Core Ruleset for automatic protection against common vulnerabilities.
  • Custom Firewall Rules under Security > WAF > Custom rules: Block by country, IP, user agent, or URI path.

Example custom rule (paid plans): block access to wp-login.php except from your office IP:

(http.request.uri.path eq "/wp-login.php" and ip.src ne YOUR.OFFICE.IP)

Action: Block.

☐ Enable DDoS protection

DDoS protection is automatic and always on. Under Security > DDoS, verify HTTP DDoS Attack Protection and Network-layer DDoS Attack Protection are enabled. No action needed unless you want to configure sensitivity (Enterprise only).

☐ Configure Rate Limiting (paid)

Rate Limiting (paid feature) throttles abusive traffic. Common use cases:

  • Limit login attempts: 5 requests per minute to /wp-login.php per IP
  • Limit API calls: 100 requests per minute per API key

Create rules under Security > WAF > Rate limiting rules.

☐ Restore original visitor IP at origin

When Cloudflare proxies traffic, your origin sees Cloudflare's IPs, not visitor IPs. Restore real IPs:

Apache (cPanel/WHM):

Install mod_remoteip or mod_cloudflare. In cPanel, this is often automatic. Verify by checking Apache logs for real IPs instead of Cloudflare IPs.

Nginx:

Add to your server block:

set_real_ip_from 173.245.48.0/20;
set_real_ip_from 103.21.244.0/22;
set_real_ip_from 103.22.200.0/22;
set_real_ip_from 103.31.4.0/22;
set_real_ip_from 141.101.64.0/18;
set_real_ip_from 108.162.192.0/18;
set_real_ip_from 190.93.240.0/20;
set_real_ip_from 188.114.96.0/20;
set_real_ip_from 197.234.240.0/22;
set_real_ip_from 198.41.128.0/17;
set_real_ip_from 162.158.0.0/15;
set_real_ip_from 104.16.0.0/13;
set_real_ip_from 104.24.0.0/14;
set_real_ip_from 172.64.0.0/13;
set_real_ip_from 131.0.72.0/22;
set_real_ip_from 2400:cb00::/32;
set_real_ip_from 2606:4700::/32;
set_real_ip_from 2803:f800::/32;
set_real_ip_from 2405:b500::/32;
set_real_ip_from 2405:8100::/32;
set_real_ip_from 2a06:98c0::/29;
set_real_ip_from 2c0f:f248::/32;
real_ip_header CF-Connecting-IP;

Reload Nginx. Verify logs show real visitor IPs.

Caching and Performance

Cloudflare's CDN caches static assets by default. Fine-tune caching for your application.

☐ Understand default cache behavior

Cloudflare caches static files (CSS, JS, images) based on file extension. It does not cache HTML by default on the Free plan. Dynamic content (PHP, API responses) bypasses cache unless explicitly configured.

☐ Set Browser Cache TTL

Under Caching > Configuration, set Browser Cache TTL. This controls how long browsers cache resources. Common values:

  • Respect Existing Headers: Use origin's Cache-Control headers (recommended if you set them)
  • 4 hours to 1 month: Safe defaults for static assets

Avoid very low values (e.g., 30 minutes) for static assets; it wastes bandwidth.

☐ Configure Caching Level

Under Caching > Configuration, set Caching Level:

  • No Query String: Treats file.css?v=1 and file.css?v=2 as the same file (caches ignore query strings)
  • Ignore Query String: Like No Query String, delivers from cache regardless of query string
  • Standard: Default; respects query strings for versioning

Use Standard unless you have a specific reason to ignore query strings.

☐ Create Cache Rules or Page Rules for HTML caching (optional)

To cache HTML (e.g., static landing pages, blogs), create a Cache Rule (new interface) or Page Rule:

Page Rule example (legacy):

URL pattern: yourdomain.com/blog/*
Settings: Cache Level: Cache Everything, Edge Cache TTL: 2 hours

Cache Rule example (new):

Under Caching > Cache Rules, create a rule:
If: Hostname equals yourdomain.com and URI Path starts with /blog/
Then: Eligible for cache, Edge TTL: 2 hours

Be cautious caching HTML for logged-in users or dynamic content.

☐ Enable Auto Minify

Under Speed > Optimization, enable Auto Minify for JavaScript, CSS, and HTML. This strips whitespace and comments, reducing file size. Test after enabling; rarely, it breaks poorly written code.

☐ Enable Brotli compression

Under Speed > Optimization, enable Brotli. This provides better compression than gzip for modern browsers. No downside; browsers that don't support Brotli fall back to gzip.

☐ Configure Rocket Loader (use with caution)

Rocket Loader under Speed > Optimization defers JavaScript loading to speed up rendering. It can break JavaScript-heavy sites or poorly coded scripts. Enable in staging first, test thoroughly, then enable in production if safe.

☐ Purge cache after major changes

When you deploy code or content changes, purge Cloudflare's cache:

  • Purge Everything: Under Caching > Configuration, click Purge Everything. Use sparingly; clears all cached assets.
  • Purge by URL: Purge specific files by entering their full URLs.
  • Purge by Tag/Host (paid): More granular cache clearing.

Automate cache purging via Cloudflare's API in your deployment pipeline.

Firewall and Access Rules

Control who can access your site.

☐ Whitelist your office/admin IPs (optional)

If you want to allow admin access only from known IPs, create an IP Access Rule under Security > WAF > Tools:

Action: Allow
IP/Range: YOUR.OFFICE.IP
Zone: This website

Then block everyone else from /wp-admin/ or /admin/ with a custom firewall rule.

☐ Block abusive countries or IPs

If you see attack traffic from specific countries, create a firewall rule (paid) or use IP Access Rules (free):

Under Security > WAF > Tools, add:
Action: Block
IP/Range or Country: e.g., 192.0.2.0/24 or select country
Zone: This website

Use this sparingly; blocking entire countries can block legitimate users.

☐ Enable Email Address Obfuscation

Under Scrape Shield, enable Email Address Obfuscation to hide email addresses in HTML from bots. Helps reduce spam.

Domain and DNS Finalization

Lock down your domain security settings.

☐ Enable DNSSEC (optional)

DNSSEC protects against DNS spoofing. Enable under DNS > Settings > DNSSEC. Cloudflare generates DS records; add them to your registrar. Check your registrar's documentation for the process.

☐ Disable Cloudflare's email obfuscation if it breaks your contact forms

If contact forms or JavaScript-based email links break, disable Email Address Obfuscation under Scrape Shield.

☐ Set up CAA records (optional but recommended)

Certificate Authority Authorization (CAA) DNS records tell CAs which organizations can issue certificates for your domain. Add CAA records under DNS:

0 issue "letsencrypt.org"
0 issue "pki.goog"
0 issuewild "letsencrypt.org"

Adjust based on your CA. This prevents rogue certificate issuance.

Monitoring and Verification

Verify everything works and set up monitoring.

☐ Test site functionality

Browse your site as a visitor:

  • Test all critical pages and forms
  • Verify images, CSS, and JavaScript load
  • Test login and logout
  • Check email delivery (contact forms, transactional emails)
  • Test any third-party integrations (payment gateways, APIs)

Use multiple browsers and an incognito window to avoid cached results.

☐ Check for mixed content warnings

Open the browser console (F12) on HTTPS pages. Look for warnings about insecure resources. Fix by updating URLs to HTTPS or enabling Automatic HTTPS Rewrites.

☐ Verify origin IP is hidden

Your origin IP should not be publicly discoverable. Check:

dig yourdomain.com

The A record should resolve to a Cloudflare IP (in the 104.x, 172.x, or 173.x ranges), not your origin IP. If your origin IP leaks, Cloudflare's DDoS protection is bypassed.

Common leak sources: DNS records left in gray-cloud (DNS-only) mode, old DNS history in public records, mail server DNS records, subdomains not on Cloudflare.

☐ Set up email alerts

Under Notifications, configure alerts for:

  • DDoS attacks
  • High error rates (502, 503, 504)
  • SSL/TLS certificate expiration (if using a custom cert)
  • Health checks failing (if configured)

☐ Enable Analytics and review traffic

Under Analytics & Logs, review traffic patterns, cache hit ratio, and threat mitigation. Aim for a cache hit ratio above 80% for static sites. Lower ratios indicate misconfigured caching or mostly dynamic content.

☐ Document your configuration

Export or screenshot your Cloudflare settings: DNS records, SSL mode, security level, page rules, and firewall rules. Store this documentation with your site's runbook for future reference or troubleshooting.

Common Issues and Quick Fixes

Site shows "Error 521: Web server is down"
Cloudflare cannot reach your origin. Check origin server status, firewall rules, and that the origin IP in Cloudflare DNS is correct.

Site shows "Error 525: SSL Handshake Failed"
SSL/TLS mode mismatch. If origin has no SSL certificate, use Full. If origin has a valid cert, use Full (Strict).

Email stops working after Cloudflare setup
Mail DNS records (MX, mail.yourdomain.com) must be gray-cloud (DNS-only), not orange-cloud (proxied). Verify MX records point to the correct mail server IP.

Origin IP is exposed
Check DNS history on third-party sites, ensure all web-facing subdomains are proxied (orange cloud), and avoid leaking the origin IP in mail headers or old DNS records.

Cache not working
Cloudflare only caches static assets by default. Use Page Rules or Cache Rules to cache HTML. Verify Cache-Control headers from your origin allow caching.

Conclusion

Setting up Cloudflare correctly takes time but pays dividends in performance, security, and uptime. Work through this checklist methodically: migrate DNS cleanly, configure SSL/TLS for your origin's capabilities, harden security settings, optimize caching, and verify everything works before calling the job done. The result is a site that's faster for users, protected from common attacks, and easier to scale as traffic grows. Keep your configuration documented, monitor alerts, and revisit cache and security rules as your site evolves.

FAQ

Do I need to update my origin firewall after enabling Cloudflare?

Yes. Configure your origin firewall (CSF, iptables, cloud firewall) to allow only Cloudflare IP ranges. This prevents attackers from bypassing Cloudflare and attacking your origin directly. Cloudflare publishes its IP ranges; import them into your firewall rules.

Can I use Cloudflare with a subdomain only?

Yes, but you must add the root domain to Cloudflare and use DNS records to proxy specific subdomains. Cloudflare requires authoritative control of the entire domain.

Does Cloudflare replace my hosting provider's SSL certificate?

Cloudflare provides a certificate for visitor-to-Cloudflare connections. Your origin still needs a certificate for Cloudflare-to-origin connections if using Full or Full (Strict) mode.

How often should I purge the cache?

Only after deploying changes. Frequent cache purging defeats the purpose of caching and increases origin load. Automate purges in your deployment pipeline instead of doing them manually.

Will Cloudflare slow down my site for some visitors?

Cloudflare has data centers worldwide, so most visitors experience faster load times. Rarely, if your origin and most visitors are in the same geographic location and your host's network is excellent, Cloudflare might add minimal latency. Test with real-world users.