Technical issues

How to connect CloudFlare?

2020-07-30

Cloudflare is a service your site's traffic passes through: it caches static files, speeds up loading for visitors in different countries and filters attacks. Below is how to connect a site hosted with us.

Before you start

The site should already work on our hosting. Issue a free SSL certificate for it in the panel (see the article "How to get a free Let's Encrypt SSL certificate?") before changing the nameservers: while the domain is on our NS, the certificate is issued with no extra steps.

How to connect the site

  1. Sign up at dash.cloudflare.com, click "Onboard a domain" in the dashboard and enter the domain without www, for example example.com.
  2. Choose a plan. The free one (Free) is enough for most sites.
  3. Check the DNS records Cloudflare found on its own:
    • the A records for the domain and www must point to your site's IP (shown in "WWW domains" -> site -> "IP addresses"), for example 217.182.203.80; keep them "Proxied" (orange cloud);
    • set mail records (mail, MX) to "DNS only" (grey cloud);
    • copy the SPF and DKIM records if you use our mail (see the article "How to keep emails out of spam?").
  4. Cloudflare will show two nameservers of its own. In your domain registrar's panel, turn off DNSSEC if it is on, and replace the current NS with these two.
  5. Wait until the domain status in Cloudflare becomes "Active". This usually takes from a few minutes to 24 hours; you will get an email when it is done.

Once the domain is on Cloudflare's nameservers, its DNS records are edited in Cloudflare, not in the "DNS zones" section of our panel.

How to set up SSL

In Cloudflare open "SSL/TLS" -> "Overview" and choose "Full (strict)": the connection to our server will be encrypted and checked against the certificate issued in the panel.

Do not use "Flexible" if "Redirect to HTTPS" is on in the site settings: the site will end up in an endless redirect loop.

With proxying on, Let's Encrypt cannot verify the domain the usual way. If the certificate on the hosting needs to be reissued, temporarily switch the domain records to "DNS only", issue the certificate and turn proxying back on.

If the site is under attack

On the domain page in Cloudflare, turn on "Under Attack Mode" in the "Quick Actions" block. Visitors will see a short automatic browser check before entering the site, and malicious traffic will be filtered out. When the attack is over, turn the mode off.