Handling additional hostnames.
ADDING A SUBDOMAIN
Create it in cPanel first, so the hosting serves it.
Then add a DNS record for it in Cloudflare, since that is where DNS now lives.
Creating a subdomain in cPanel adds a record to the cPanel zone, which is no longer consulted.
THE PROXY DECISION
A subdomain serving web pages: proxied.
A subdomain used for a service: DNS only.
WILDCARD RECORDS
Cloudflare supports wildcard DNS records. On the free plan, wildcard records cannot be proxied.
If you rely on wildcard subdomains for web traffic, they resolve directly to us rather than through Cloudflare.
STAGING SUBDOMAINS
Set them to DNS only and protect them with cPanel Directory Privacy.
A staging site behind Cloudflare with caching can serve stale content confusingly.
SSL FOR SUBDOMAINS
Each needs certificate coverage. Run AutoSSL after adding one, ticking the new subdomain.
Cloudflare's free certificate covers one level of subdomain. Deeper nesting requires a paid plan.
CHECKING
Visit each subdomain after setup and confirm it loads over https without warnings.