All hosting help

Use Cloudflare with your hosting

How to put Cloudflare's proxy in front of your hosting account without breaking SSL, mail, or FTP.

Updated September 2026

This guide covers DNS records, HTTPS and caching when using Cloudflare with an Omega Digital hosting account.

Step 1: Add the site to Cloudflare

  1. Sign up at cloudflare.com and click Add a Site.
  2. Enter your domain and pick the Free plan.
  3. Cloudflare will scan your existing DNS. Review the imported records carefully. Anything missing needs to be added manually before you continue.
  4. Cloudflare assigns you two nameservers (e.g. evan.ns.cloudflare.com).
  5. At your registrar, replace the old nameservers with the two Cloudflare gave you.

Step 2: Configure records for Omega Digital

In the Cloudflare DNS tab, you need at minimum:

Type    Name    Content              Proxy status
A       @       198.51.100.42        Proxied (orange cloud)
A       www     198.51.100.42        Proxied (orange cloud)
A       mail    198.51.100.42        DNS only (grey cloud)  ← critical
A       ftp     198.51.100.42        DNS only (grey cloud)
A       cpanel  198.51.100.42        DNS only (grey cloud)
MX      @       mail.yourdomain.com  Priority 0

Step 3: Set SSL mode to Full (strict)

In Cloudflare → SSL/TLS → Overview, set the encryption mode to Full (strict). This means:

  • Cloudflare to browser: HTTPS with a Cloudflare certificate (automatic).
  • Cloudflare to your server: HTTPS using your Let's Encrypt certificate from Omega Digital.
  • Cloudflare validates the certificate presented by your server.

If you haven't issued a Let's Encrypt certificate yet, do that first in cPanel. Flexible mode exists, but we don't recommend it. It leaves the hop from Cloudflare to your origin unencrypted.

Step 4: Keep AutoSSL working

AutoSSL in cPanel validates by HTTP. When Cloudflare proxies @ and www, it rewrites the response, which can confuse Let's Encrypt's validator. Two fixes:

  1. Temporarily grey-cloud the proxied records when running AutoSSL for the first time, then turn the proxy back on.
  2. Better: use Cloudflare's Origin CA certificate instead. Issue one under SSL/TLS → Origin Server, install it via cPanel → SSL/TLS → Manage SSL Sites. These certificates are valid only between Cloudflare and your origin, last 15 years, and avoid the validation loop entirely.

Caching rules worth setting

Review caching rules for public assets and exclude administrative pages. The examples below illustrate those paths; use the controls available in your Cloudflare account.

# Cache all static assets aggressively
URL:    yourdomain.com/wp-content/*
Rule:   Cache Level: Cache Everything
        Edge Cache TTL: 1 month

# Never cache WordPress admin
URL:    yourdomain.com/wp-admin/*
Rule:   Cache Level: Bypass

# Never cache logged-in sessions
URL:    yourdomain.com/wp-login.php
Rule:   Cache Level: Bypass

Getting the real visitor IP in your logs

With Cloudflare proxying, server logs will show Cloudflare IPs instead of real visitors. Install mod_cloudflare, or (on current cPanel stacks) enable the Cloudflare IP restoration setting in WHM. For WordPress, the Cloudflare plugin handles this automatically and exposes real IPs to security plugins.

Common issues

  • Proxying mail subdomains. Mail will stop working within minutes. Grey cloud everything mail-related.
  • Flexible SSL leaves the connection to your origin unencrypted. Use Full (strict) with a valid origin certificate.
  • Forgetting the root A record. Cloudflare does not automatically flatten CNAMEs at the apex unless you create the record. Add an A record or use Cloudflare's CNAME flattening.
  • Caching wp-admin can expose private content. Bypass the cache for administrative pages.

Contact support

Email [email protected] with the affected domain and your Cloudflare SSL mode.

Related reading