Getting the cloud icons right.
PROXY THESE
The root domain A record The www record Any subdomain serving web pages
DO NOT PROXY THESE
mail, and whatever hostname your MX records point to The MX records themselves, which cannot be proxied ftp cpanel, webmail, webdisk and similar service hostnames Any subdomain used for a non-web service Any record used for domain validation by another service
WHY MAIL BREAKS
Cloudflare's proxy handles web traffic. Mail connections to a proxied hostname do not reach us.
Sending and receiving both fail, and the cause is not obvious.
THE CHECK AFTER SETUP
Go through every record and look at the cloud. Anything that is not a web page should be grey.
TXT RECORDS
Not proxied; the option does not apply. Confirm SPF, DKIM and DMARC records imported correctly.
A missing SPF record after a Cloudflare move means your mail starts failing authentication.
WHAT TO TEST AFTERWARDS
Load the website Send a message from a mailbox Receive a message to a mailbox Connect to cPanel