Cloudflare sits in front of your site, filtering traffic before it reaches our servers. The free plan is worthwhile for most sites.
WHAT IT GIVES YOU
Absorption of volumetric attacks A web application firewall with basic rule sets Bot filtering A global CDN, which also improves speed Rate limiting and custom firewall rules "Under Attack" mode for incidents
SETTING IT UP
- Create an account and add your domain.
- Check the imported DNS records carefully, especially the mail records.
- Change your nameservers at the registrar to the pair Cloudflare provides.
- Wait for activation.
CRITICAL SETTINGS
Mail records must be grey-clouded, DNS only. Proxying them breaks email. SSL/TLS mode must be Full (strict), with AutoSSL already issued on our side. Flexible causes redirect loops. Bypass cache for admin and login paths. Install the Cloudflare plugin if your platform has one, so your logs show real visitor IPs rather than Cloudflare's.
BEAR IN MIND
DNS is then managed at Cloudflare, not in cPanel. Future record changes must be made there. And Cloudflare protects the path through it; if attackers learn your server's direct address, that route must still be secured.