A yearly check.
DNS
Every record still needed, and nothing missing Proxy states correct, particularly mail Zone exported and stored with your documentation
SSL
Mode still Full (strict) AutoSSL valid at our end Any HSTS setting still appropriate
CACHING
Development mode off Cache rules still matching what you intend Exclusions still covering cart, checkout, account and admin
SECURITY
Security level appropriate Under Attack mode off Firewall rules still needed, and none blocking something you now depend on Rate limits still appropriate for your traffic
OPTIMISATION
Nothing enabled that you have not tested recently No double minification with your caching plugin
ACCESS
Who has access to the Cloudflare account Two-factor authentication enabled The account not registered to someone who has left
WHY ANNUALLY
Configurations drift. Rules added for a past problem remain, blocking something new.
The zone export alone justifies the time.