The certificate Cloudflare presents to visitors.
WHAT IT IS
A certificate Cloudflare issues automatically for domains on its network, covering the domain and its first-level subdomains, presented to visitors on proxied records.
WHAT IT DOES NOT DO
Secure the connection between Cloudflare and your server. That requires a certificate on our server and the correct SSL mode.
WHAT THIS MEANS
Visitors see a valid padlock from Cloudflare's certificate. Whether the second leg is encrypted depends entirely on your SSL mode setting.
With Flexible, visitors see a padlock while half the journey is unencrypted.
DEEPER SUBDOMAINS
Universal SSL covers one level. test.shop.yourdomain.com is not covered without an upgrade.
DNS-ONLY RECORDS
Records not proxied do not use Cloudflare's certificate at all. Those connections go directly to our server and use our certificate, which is why mail still works with DNS-only records.
THE CORRECT SETUP
AutoSSL on our server, Cloudflare SSL/TLS set to Full (strict), mail records DNS-only.