
How to Set Up Cloudflare DNS for Your Website?
Cloudflare is one of the most popular places to host a domain's authoritative DNS, and for good reason: the free plan includes a fast anycast DNS network, a clean record editor, an API, and optional reverse-proxy features such as caching and DDoS protection. Moving a domain there is straightforward, but there are a few steps where small mistakes cause outages — a missed record during import, a proxied mail hostname, or DNSSEC left enabled at the old provider. If you're new to the idea of separating where you register a domain from where its DNS lives, start with the difference between a domain registrar and a DNS host.
This guide covers the full setup: adding your domain to Cloudflare, checking the imported records, choosing proxy status per record, switching nameservers at your registrar, enabling DNSSEC, and managing records through the API once everything is live. Note that this is about Cloudflare as the authoritative DNS host for your website — not the 1.1.1.1 public resolver, which is a separate service.
How Cloudflare DNS Works
When you add a domain in the standard way (Cloudflare calls it a full setup), Cloudflare becomes the authoritative DNS provider for the whole zone. You change the domain's nameservers at the registrar to two Cloudflare nameservers, and from then on every DNS query for your domain is answered by Cloudflare's network.
Each record in Cloudflare has a proxy status:
- Proxied (orange cloud). Cloudflare answers queries for the hostname with its own anycast IP addresses. Visitors connect to Cloudflare, which then fetches content from your origin server. This enables caching, the web application firewall, and DDoS protection, and hides your origin IP.
- DNS only (grey cloud). Cloudflare simply returns the record's real value, like any other DNS host. Traffic goes straight to your server.
Only HTTP and HTTPS traffic (on a defined set of ports) benefits from proxying. Anything else — mail, SSH, FTP, game servers, database connections — must use DNS-only records, or it will fail.
There's also a partial (CNAME) setup on Business and Enterprise plans, where you keep your existing DNS host and only point specific hostnames at Cloudflare. Most sites use the full setup, which is what this guide covers.
Step 1: Prepare Before You Switch
A clean migration starts at your current DNS provider, before you touch Cloudflare.
- Export or screenshot every record. Many DNS hosts offer a zone file export. If yours does, you can import it straight into Cloudflare. If not, list every record by hand, including TXT verification records, DKIM keys, SRV records, and subdomains.
- Lower TTLs on important records (for example to 300 seconds) a day or two ahead, so any mistakes after the switch are corrected quickly. What a TTL in DNS is explains why this matters.
- Check DNSSEC at the registrar. If DNSSEC is enabled for the domain, disable it (remove the DS record) at the registrar and wait for the DS record's TTL to expire before changing nameservers. Leaving an old DS record in place while switching to Cloudflare's unsigned zone makes validating resolvers return SERVFAIL for your entire domain.
You can dump the current zone's key records with dig to compare later:
for type in A AAAA CNAME MX TXT NS CAA SRV; do
echo "== $type =="
dig example.com "$type" +short
done
dig www.example.com +short
dig _dmarc.example.com TXT +short
This loop prints the main record types at the apex, plus a couple of common hostnames. dig can't list every name in a zone, so it supplements — rather than replaces — an export from your provider. If you're planning a large migration with no downtime tolerance, follow the checklist in how to plan a zero-downtime DNS migration.
Step 2: Add Your Domain to Cloudflare
- Sign in to the Cloudflare dashboard and choose Add a domain (also shown as Add site in some views).
- Enter your apex domain, such as
example.com— notwww.example.com. - Choose how to bring in records. You can let Cloudflare quick scan for common records, or upload a zone file exported from your old provider. Uploading a zone file is far more complete.
- Select a plan. The Free plan includes full authoritative DNS.
Cloudflare then shows the records it found or imported. Treat this list as a draft, not a finished copy.
Step 3: Review the Imported Records
The quick scan only finds records it can guess, so compare the list against your export line by line. Pay particular attention to:
- TXT records for SPF, DMARC, and service verification (Google, Microsoft, and others).
- DKIM records under names like
selector1._domainkeyorgoogle._domainkey, which a scan can't discover. - Subdomains like
api,staging,mail, orautodiscover. - SRV and CAA records, which scans frequently miss.
Then set the proxy status for each record:
| Record | Typical proxy status | Why |
|---|---|---|
example.com A/AAAA (website) | Proxied | Web traffic benefits from caching and protection |
www CNAME (website) | Proxied | Same as above |
mail A record used by MX | DNS only | SMTP can't pass through the HTTP proxy |
| MX, TXT, SRV, CAA | Not proxiable | These record types are always DNS only |
ssh, ftp, vpn hostnames | DNS only | Non-HTTP protocols |
api behind a third-party platform | Depends | Some platforms require DNS only to issue their own certificates |
A common security slip: if your website is proxied but mail.example.com points at the same server as DNS only, anyone can look up the mail hostname and find your origin IP. Where possible, keep mail on a different IP or a hosted mail service.
Cloudflare also lets you create a CNAME at the apex. Because a real CNAME at the zone apex isn't allowed by the DNS standards, Cloudflare resolves it behind the scenes and returns A and AAAA records instead, a technique explained in what CNAME flattening is.
Step 4: Change Nameservers at Your Registrar
When the records look right, Cloudflare displays the two nameservers assigned to your account, for example ada.ns.cloudflare.com and bob.ns.cloudflare.com. These names differ between accounts, so always copy the exact pair from your dashboard rather than from a tutorial.
At your registrar:
- Open the domain's management page and find the Nameservers setting.
- Switch from the registrar's default nameservers to custom nameservers.
- Remove all existing nameservers and enter only the two Cloudflare nameservers.
- Save.
Don't mix Cloudflare's nameservers with your old provider's — that makes resolvers receive different answers depending on which nameserver they reach. For registrar-specific steps, see how to update nameservers for a domain.
Back in Cloudflare, use Check nameservers to trigger a re-check. Activation commonly happens within an hour, but delegation changes at the TLD can take up to 24–48 hours to be seen everywhere, depending on the TLD's NS TTL. Cloudflare emails you when the zone becomes Active.
Confirm the delegation yourself:
dig NS example.com +short
dig example.com @ada.ns.cloudflare.com +short
The first command should return only the two Cloudflare nameservers. The second queries one Cloudflare nameserver directly and shows what it serves for your apex — Cloudflare anycast IPs if the record is proxied, or your origin IP if it's DNS only. You can watch the change spread with the methods in how to check if DNS changes have propagated.
Step 5: Configure SSL/TLS for Proxied Records
Proxied traffic has two legs: visitor to Cloudflare, and Cloudflare to your origin. Cloudflare issues an edge certificate automatically for the first leg. For the second, set the encryption mode under SSL/TLS in the dashboard:
- Full (strict) — Cloudflare connects to your origin over HTTPS and validates its certificate. This is the setting to use whenever your origin has a valid certificate (a public one, or a free Cloudflare Origin CA certificate).
- Full — HTTPS to the origin without certificate validation. Better than nothing, but vulnerable to interception between Cloudflare and the origin.
- Flexible — HTTP to the origin. Avoid it; it also causes redirect loops on servers that force HTTPS.
If you use CAA records to restrict which certificate authorities can issue for your domain, make sure they allow the CAs Cloudflare uses for edge certificates. Cloudflare can add the necessary CAA entries automatically when Universal SSL is active.
Step 6: Enable DNSSEC
Once the zone is active, turn DNSSEC back on — this time with Cloudflare as the signer:
- In the dashboard, go to DNS, then Settings, and enable DNSSEC.
- Cloudflare shows the DS record details: key tag, algorithm (13, ECDSA P-256 with SHA-256), digest type, and digest.
- Add the DS record at your registrar. Many registrars support adding it through a DNSSEC section; some are updated automatically by Cloudflare.
Verify the chain of trust:
dig DS example.com +short
dig example.com +dnssec +multi | grep -E "flags:|RRSIG"
The DS query should return the record you added, and the second query should show an ad flag (when using a validating resolver) and RRSIG records. If you're deciding whether DNSSEC is worth enabling, see what DNSSEC is and whether you should enable it.
Managing Cloudflare DNS Records with the API
The dashboard is fine for occasional edits, but the API makes changes repeatable. Create an API token under your profile's API Tokens page, using the Edit zone DNS template scoped to the specific zone. Avoid the legacy Global API Key, which grants access to everything in your account.
Find your zone ID (shown on the domain's overview page, or via the API):
export CLOUDFLARE_API_TOKEN="your-token-here"
curl -s "https://api.cloudflare.com/client/v4/zones?name=example.com" \
-H "Authorization: Bearer $CLOUDFLARE_API_TOKEN" | jq -r '.result[0].id'
This returns the zone ID for example.com, which every DNS record endpoint needs.
Create a proxied A record for the apex:
export ZONE_ID="023e105f4ecef8ad9ca31a8372d0c353"
curl -s "https://api.cloudflare.com/client/v4/zones/$ZONE_ID/dns_records" \
-H "Authorization: Bearer $CLOUDFLARE_API_TOKEN" \
-H "Content-Type: application/json" \
--data '{"type":"A","name":"example.com","content":"203.0.113.10","ttl":1,"proxied":true}'
A ttl of 1 means "automatic" in Cloudflare's API; proxied records always use automatic TTL. The response includes the new record's id.
List existing records of a given type and update one:
curl -s "https://api.cloudflare.com/client/v4/zones/$ZONE_ID/dns_records?type=TXT" \
-H "Authorization: Bearer $CLOUDFLARE_API_TOKEN" | jq '.result[] | {id, name, content}'
curl -s -X PATCH "https://api.cloudflare.com/client/v4/zones/$ZONE_ID/dns_records/RECORD_ID" \
-H "Authorization: Bearer $CLOUDFLARE_API_TOKEN" \
-H "Content-Type: application/json" \
--data '{"content":"v=spf1 include:_spf.google.com ~all"}'
The first call lists TXT records with their IDs; the second patches the content of one record, leaving its other fields unchanged. Replace RECORD_ID with an ID from the list. For larger setups, Cloudflare's official Terraform provider lets you keep the whole zone in version control.
Common Mistakes When Setting Up Cloudflare DNS
- Missing records after import. The quick scan misses DKIM, SRV, and unusual subdomains. Email breaks first, often days later when a DKIM-signed message fails checks.
- Proxying non-web hostnames. A proxied
mailorftprecord returns Cloudflare IPs that don't accept those protocols. - Leaving DNSSEC on at the old provider. The old DS record no longer matches, and the domain stops resolving for validating resolvers.
- Using Flexible SSL with a server that redirects HTTP to HTTPS, causing an endless redirect loop.
- Exposing the origin IP through DNS-only records, old subdomains, or historical DNS data. If origin secrecy matters, change the origin IP after moving behind the proxy.
- Leaving stale records that point at deleted cloud resources. These are an invitation to subdomain takeover — audit them during the move, as described in what a dangling DNS record is.
Cloudflare DNS Setup FAQ
Yes. The Free plan includes authoritative DNS hosting for your domain, the record editor, the API, DNSSEC, and the basic proxy features. Paid plans add things like more advanced security features and partial (CNAME) setup.
No. You only change the nameservers at your current registrar. Transferring registration to Cloudflare Registrar is optional and separate from using Cloudflare DNS.
Often within an hour of changing nameservers, but it can take up to 24 to 48 hours depending on the TLD and registrar. Cloudflare emails you when the zone becomes active.
No. Proxy only HTTP and HTTPS hostnames that you want Cloudflare to cache or protect. Mail servers, SSH, FTP, and other non-web services must be set to DNS only.
Not if you copy every MX, SPF, DKIM, and DMARC record exactly and keep mail-related hostnames DNS only. Email problems after a move almost always come from a record that was missed during import.
Yes. Cloudflare accepts a CNAME at the apex and flattens it, returning the resolved A and AAAA records to visitors, so the zone stays standards-compliant.
Proxied records always use automatic TTL. For DNS-only records, Auto is fine for most cases; set a lower value temporarily before planned changes and a higher one for records that rarely change.
Because the record is proxied. Visitors connect to Cloudflare, which forwards requests to your origin. Switch the record to DNS only if you need the real IP returned.
Conclusion
Setting up Cloudflare DNS comes down to a handful of steps: add the domain, verify every imported record against your old zone, decide which hostnames to proxy, switch the nameservers at your registrar, and then re-enable DNSSEC with Cloudflare's DS record. The provider does most of the heavy lifting, but the import review is where you should spend your time — a missing DKIM key or a proxied mail record is the usual cause of post-migration problems.
Once the zone is active, set SSL/TLS to Full (strict), use a scoped API token for automation, and audit for stale records. With that done, you have fast, resilient authoritative DNS and the option to put Cloudflare's proxy in front of your site whenever you need it.
Here are some useful references for Cloudflare DNS:
- Cloudflare DNS Docs: Cloudflare DNS documentation — official documentation covering zone setup, record management, and DNS settings.
- Cloudflare DNS Docs: Proxy status — explains proxied versus DNS-only records and which traffic can be proxied.
- Cloudflare API: Cloudflare API documentation — reference for the DNS records endpoints used above.
- Cloudflare SSL/TLS Docs: SSL/TLS documentation — details on encryption modes, edge certificates, and Origin CA.
- RFC 4033: DNS Security Introduction and Requirements — the core DNSSEC specification behind the DS record step.


