Cloudflare Setup Guide: 8 FAQs [Solved]
Fix DNS errors, choose the right SSL mode, and configure caching rules. Direct answers to the 8 most common Cloudflare setup questions.

On this page
- How do I add my domain to Cloudflare?
- Where do I update my nameservers?
- What does the orange cloud vs. gray cloud mean?
- Which SSL/TLS encryption mode should I use?
- How do I install a Cloudflare origin certificate?
- Do I need to change cache rules?
- Why is my site slow or showing stale content after enabling Cloudflare?
- How do I secure my origin server so only Cloudflare can connect?
- Quick reference: Cloudflare setup checklist by record type
TL;DR — Key takeaways
- Set DNS records to proxied (orange cloud) for CDN benefits; leave mail and FTP records DNS-only to avoid connectivity issues.
- Use Full (strict) SSL mode only after installing an origin certificate; Flexible mode works for sites without SSL but sends unencrypted traffic to your origin.
- Default cache rules suit most static sites, but dynamic apps need page rules to bypass caching on login, checkout, and API endpoints.
- The 1001 or 1000 DNS resolution errors happen when nameservers aren't fully updated at your registrar—wait 24-48 hours or verify NS records.
- Always test changes in a staging subdomain first; Cloudflare's real-time logs show exactly what traffic hits your origin versus the cache.
Cloudflare sits between your visitors and your origin server, caching content and filtering threats. Setup is straightforward but DNS changes and SSL mode selection trip up a lot of people.
This FAQ answers the eight questions I see most often in hosting support tickets. Each answer includes the exact steps and settings you need, plus what to check when things go wrong.
How do I add my domain to Cloudflare?
Sign up at cloudflare.com and click Add Site. Enter your domain name without www or http. Cloudflare will scan your existing DNS records and import them automatically.
Review the imported records carefully. A records point to IPv4 addresses, AAAA to IPv6, CNAME to other domains, and MX to mail servers. If a record is missing, add it manually using the DNS management page.
Cloudflare will then display two nameserver addresses (they look like name1.cloudflare.com and name2.cloudflare.com). Copy both. You will need them for the next step.
Where do I update my nameservers?
Update nameservers at your domain registrar, not your hosting control panel. The registrar is the company where you purchased the domain—GoDaddy, Namecheap, Porkbun, or whoever charged your card for the domain registration.
Log into your registrar account, locate the DNS or nameserver settings for your domain, and replace the existing nameservers with the two Cloudflare provided. Remove any old nameservers completely. Some registrars label this section as 'Custom DNS' or 'Change Nameservers.'
Propagation begins immediately but takes up to 48 hours to complete worldwide. Cloudflare's dashboard will show a pending status until it detects the change. You can force a recheck by clicking the button in the overview tab.
What does the orange cloud vs. gray cloud mean?
The orange cloud means Cloudflare will proxy traffic through its network—your visitors connect to Cloudflare's servers, which then fetch content from your origin. This enables caching, DDoS protection, and the firewall.
Gray cloud means DNS-only mode. Cloudflare resolves the domain but traffic goes directly to your origin IP without passing through the CDN. Use gray cloud for records that must connect directly to your server: mail (MX), FTP, SSH, and direct-access subdomains.
For web traffic (A, AAAA, and CNAME records serving HTTP/HTTPS), keep the orange cloud enabled. For mail and file transfer protocols, always use gray cloud or you will break connectivity.
Which SSL/TLS encryption mode should I use?
Full (strict) is the correct choice for production sites. It requires a valid SSL certificate on your origin server—either a Cloudflare origin certificate (free, generated in the SSL/TLS tab) or a certificate from Let's Encrypt or another CA. Traffic is encrypted from visitor to Cloudflare and from Cloudflare to your origin.
Flexible mode encrypts traffic between the visitor and Cloudflare but sends unencrypted HTTP requests to your origin. Use this only if your server does not support HTTPS at all. It is better than nothing but not secure for login forms, payment pages, or personal data.
Full (not strict) encrypts both legs but does not validate your origin certificate. Self-signed certificates work here. I recommend Full (strict) because it prevents man-in-the-middle attacks on the origin leg. Install the Cloudflare origin certificate to your server (valid for 15 years) and switch to strict.
How do I install a Cloudflare origin certificate?
Go to SSL/TLS > Origin Server in your Cloudflare dashboard and click Create Certificate. Choose the default 15-year validity and list your domain and www subdomain (or use *.yourdomain.com for a wildcard).
Cloudflare will generate two text blocks: the certificate and the private key. Copy both. On your server, save the certificate to a file like /etc/ssl/certs/cloudflare-origin.pem and the private key to /etc/ssl/private/cloudflare-origin.key. Set permissions so only root can read the private key (chmod 600).
Update your web server configuration to use these files. For Nginx, modify the ssl_certificate and ssl_certificate_key directives. For Apache, update SSLCertificateFile and SSLCertificateKeyFile in your VirtualHost block. Reload the web server and test. Your site should now accept HTTPS connections from Cloudflare.
Do I need to change cache rules?
Cloudflare's default cache rules handle static assets (images, CSS, JavaScript) well. HTML is not cached by default, which works fine for most sites.
If you run a dynamic application—WordPress with a login, an e-commerce checkout, or an API—you may need page rules or cache rules to exclude certain paths. Create a rule to bypass cache for /wp-admin/*, /cart/*, /checkout/*, and /api/* so users always get fresh, personalized content.
Page rules are the older interface but still work. Cache Rules (under Caching in the dashboard) are more flexible and faster. Set match conditions by path, query string, or cookie, then choose an action like Bypass Cache or set a custom TTL.
Why is my site slow or showing stale content after enabling Cloudflare?
Check if Cloudflare is actually caching your content. Visit your site and open browser developer tools (F12), then look at the response headers for a request. The cf-cache-status header will say HIT (served from cache), MISS (fetched from origin), BYPASS (cache rule excluded it), or DYNAMIC (not cacheable).
If you see too many MISS responses, your origin might be sending Cache-Control: no-cache headers or setting cookies on every request. Review your server and application configuration. WordPress plugins and session cookies often disable caching accidentally.
Stale content means cache TTL is too long or you forgot to purge cache after an update. Go to Caching > Configuration and click Purge Everything to clear the cache. For granular control, purge by URL or cache tag.
How do I secure my origin server so only Cloudflare can connect?
Attackers can bypass Cloudflare by connecting directly to your origin IP if they discover it. Restrict your firewall to allow HTTP/HTTPS traffic only from Cloudflare's IP ranges.
Cloudflare publishes its IP ranges at cloudflare.com/ips. Download the IPv4 and IPv6 lists and configure your firewall (iptables, ufw, or cloud security groups) to drop traffic from any other source on ports 80 and 443. This forces all web traffic through Cloudflare.
If you use cPanel or Plesk, install the Cloudflare plugin to automate this. On a bare server, write a script that fetches the IP list and regenerates firewall rules weekly, because Cloudflare occasionally adds new ranges.
Quick reference: Cloudflare setup checklist by record type
Here's a summary table of DNS record types and whether to proxy them through Cloudflare (orange cloud) or leave them as DNS-only (gray cloud).
- A / AAAA (web traffic): Orange cloud — enables CDN, caching, and DDoS protection.
- CNAME (www or subdomains for web): Orange cloud if serving HTTP/HTTPS; gray cloud for non-web services.
- MX (mail server): Gray cloud always — mail protocols do not work through Cloudflare's proxy.
- TXT (SPF, DKIM, verification): Gray cloud — these are informational records, not routed traffic.
- SRV (service records like Minecraft, Discord bots): Gray cloud — application-specific protocols bypass the CDN.
- A / AAAA for FTP, SSH, direct database access: Gray cloud — these protocols fail if proxied.
Quick troubleshooting checklist
- Create a Cloudflare account and add your domain
- Copy the two nameserver addresses Cloudflare provides
- Update nameservers at your domain registrar (not your host)
- Wait for DNS propagation (check status in Cloudflare dashboard)
- Set DNS records: A/AAAA for web traffic, MX for mail, CNAME for subdomains
- Enable proxy (orange cloud) on web traffic records only
- Choose SSL/TLS mode: Full (strict) if you have an origin cert, Flexible if you don't
- Install Cloudflare origin certificate on your server for Full (strict) mode
- Configure cache rules or page rules for dynamic content paths
- Test your site in an incognito window and check response headers
- Set up firewall rules if you see bot traffic or attacks
- Enable Under Attack mode temporarily if under active DDoS
FAQ
Do I change nameservers at my host or my registrar?
Change nameservers at your domain registrar, not your hosting provider. The registrar is where you purchased the domain name (GoDaddy, Namecheap, Google Domains). Your host manages files and databases but does not control DNS authority. Log into your registrar account, find the nameserver settings (sometimes labeled DNS management or domain settings), and replace the existing nameservers with the two Cloudflare provides. Propagation usually completes within a few hours but can take up to 48 hours.
What SSL mode should I choose in Cloudflare?
Use Full (strict) if your origin server has a valid SSL certificate installed—either a Cloudflare origin certificate or one from Let's Encrypt. This encrypts traffic end-to-end. Use Flexible only if your origin does not support HTTPS at all; traffic between Cloudflare and your server will be unencrypted, which is a security risk. Avoid Off unless you are troubleshooting a specific SSL loop. Full (strict) is the recommended production setting for any site handling user data or login sessions.
Why is my site showing a 1001 or 1000 error after setup?
Error 1001 or 1000 means Cloudflare cannot resolve your domain's DNS. The most common cause is nameservers at your registrar still pointing to the old provider instead of Cloudflare's nameservers. Log into your registrar and verify the nameserver records match exactly what Cloudflare provided—no typos, no trailing dots. If they are correct, wait another 12-24 hours for full propagation. You can check propagation status using a tool like whatsmydns.net or the DNS checker in your Cloudflare dashboard.
Related articles
- Hosting OperationsSelf-Hosted App Deployment Fails? Check DNS, SSL, Reverse Proxy, and Logs FirstTroubleshoot failed self-hosted app deployments by checking DNS, SSL, reverse proxy routing, container status, logs, and ports.
- Hosting OperationsSelf-Hosted PaaS on a VPS: What to Check Before Installing Coolify, Dokploy, or CapRoverA hosting support checklist for preparing a VPS before installing self-hosted PaaS tools like Coolify, Dokploy, or CapRover.
- Hosting OperationsLinux Server Security Lessons from the Arch Linux Malware Package IncidentPractical Linux server security checklist for VPS admins after package malware concerns, with safe checks, rollback steps, and support guidance.
- Hosting OperationsAWS Lightsail Hong Kong VPS Latency: Practical Hosting Guide for IndonesiaLearn how to test AWS Lightsail Hong Kong VPS latency, compare regions, migrate safely, and troubleshoot hosting performance.
- Hosting OperationsCloudflare Tomorrow Watchlist: A Practical Hosting Operations GuidePractical Cloudflare troubleshooting checklist for DNS, SSL, caching, WAF, origin health, safe testing, and rollback planning.
- Hosting OperationsNetwork Safety Checklist for AI Agent Skills in Hosting OperationsAudit AI agent skills safely with network checks, secret protection, sandbox testing, rollback steps, and hosting support troubleshooting guidance.