DNS, Security & Integrations
Cloudflare DNS & SSL Setup
Move your domain onto Cloudflare properly, with DNS records recreated and SSL working correctly.
The Problem
Moving to Cloudflare without carefully recreating every DNS record first is one of the most common ways sites and email both go down at once — and getting the SSL mode wrong causes redirect loops straight after.
About this problem
Cloudflare becomes authoritative for a domain only after the nameservers change, and from that moment it answers every query from its own zone. Any record that was not recreated there, such as an MX, a TXT for SPF or DKIM, or a subdomain, simply stops resolving. Its automatic import also misses records at times, so a manual comparison against the old zone is needed.
People usually come looking for this when they want the CDN, caching or firewall features, or when a host or registrar has pushed them towards Cloudflare. The SSL/TLS mode matters just as much: if Cloudflare connects to the origin over HTTP while the origin redirects to HTTPS, the result is an endless redirect loop straight after the switch.
What's Included
- Full export of existing DNS records before any change
- Recreating every record correctly in Cloudflare
- Setting the correct SSL/TLS mode to avoid redirect loops
- Verifying site and email both work after the switch
What's NOT Included
- Domain registrar transfer (Cloudflare DNS doesn't require this)
- Cloudflare paid plan costs, if you choose to upgrade
- Ongoing Cloudflare configuration changes beyond initial setup
How It Works
- I export the complete current DNS zone from the existing provider, including MX, TXT, SRV, CAA and subdomain records, and keep it as a reference.
- I add the domain to Cloudflare, compare the imported records line by line against that export, and recreate anything missing or wrong.
- I decide per record whether it should be proxied (orange cloud) or DNS-only, keeping mail-related hostnames such as mail and smtp unproxied.
- I check what the origin server does on port 443 and port 80, then set the SSL/TLS mode (Full or Full strict where the certificate allows) to avoid redirect loops.
- I change the nameservers at your registrar, or guide you through doing so if I have no access, and then wait for Cloudflare to confirm the zone is active.
- I test the website over HTTPS and send and receive test email, and I query the records from public resolvers to confirm everything matches the original zone.
In practice: you buy the service, send over whatever access or details the job needs, I investigate and do the work, and you confirm it's resolved before we call it done.
Frequently Asked Questions
- Will my website and email go down when I move to Cloudflare?
- Not if every record is recreated correctly before the nameservers change, which is the main point of this service. Caching at resolvers can cause brief inconsistencies while the change spreads, but the records themselves will be identical.
- Do I have to transfer my domain to Cloudflare?
- No. Only the nameservers need to point to Cloudflare; the domain can stay registered where it is. A registrar transfer is not part of this service.
- Why do I get ERR_TOO_MANY_REDIRECTS after enabling Cloudflare?
- It is almost always the SSL/TLS mode: Flexible mode talks to your server over HTTP, and if the server redirects to HTTPS the two keep bouncing. Setting the correct mode for your origin certificate resolves it.
- Should I proxy all my DNS records through Cloudflare?
- No. Web hostnames usually benefit from the proxy, but mail, FTP and other non-HTTP records must stay DNS-only. I set this per record.
- What is the difference between Full and Full (strict) SSL?
- Full encrypts traffic to your origin but accepts any certificate, while Full (strict) requires a valid, trusted certificate. Strict is safer, and I use it where your origin certificate supports it.
- Does this include paid Cloudflare plan features?
- No. I work with whatever plan you have, and any plan upgrade costs are yours to decide. Ongoing changes to Cloudflare settings after the initial setup are also not included.
- How long does the nameserver change take to work?
- It depends on the registrar and resolver caching, and can range from minutes to a day or so. I cannot force it, but I verify the result once it has taken effect.