Cloudflare is one of those services that makes your website better without costing you anything. A faster load time through caching, protection against DDoS attacks, and a free SSL certificate. Millions of websites use it, from small blogs to large online stores.

What is Cloudflare?

Cloudflare is a Content Delivery Network (CDN) with extra security features. Your website is served through Cloudflare servers that are spread around the world. This means:

  • Visitors load your site from a server close to them
  • Your origin server is put under less load
  • Malicious traffic is filtered out

Benefits of Cloudflare

A faster website

Static content (images, CSS, JavaScript) is cached on Cloudflare servers. Visitors in Tokyo do not have to wait for a server in Amsterdam.

DDoS protection

Cloudflare filters malicious traffic before it reaches your server. Millions of attacks per day are blocked.

Free SSL

Cloudflare offers a free SSL certificate. Your site is automatically reachable over HTTPS.

Better uptime

If your server is briefly offline, Cloudflare can keep showing a cached version.

Setting up Cloudflare: step by step

1. Create an account

Go to cloudflare.com and create a free account.

2. Add your website

Enter your domain name. Cloudflare automatically scans your current DNS records.

3. Check the DNS records

Cloudflare shows your current records. Check that everything is correct. Records with the orange cloud go through Cloudflare, gray clouds go direct.

4. Change your nameservers

You get two Cloudflare nameservers. Change these at your domain registrar (where you bought the domain). This can take up to 24 hours.

5. Set up SSL

Go to SSL/TLS and choose Full or Full (strict) if you already have an SSL certificate on your server.

6. Configure caching

The default settings are fine for most sites. If needed, adjust caching rules for dynamic content.

Important settings

A few recommended settings:

  • SSL Mode: Full (Strict) for the best security
  • Always Use HTTPS: On
  • Auto Minify: On for smaller files
  • Brotli: On for better compression

Cloudflare with WordPress

For WordPress there is an official Cloudflare plugin. It handles automatic cache purge on updates and optimal settings for WordPress.

Are there any downsides?

A few things to keep in mind:

  • Extra layer: Sometimes debugging can be trickier
  • Nameserver change: Your DNS is managed by Cloudflare
  • Cache issues: With updates you sometimes have to clear the cache manually

Frequently asked questions

Is Cloudflare really free?

Yes, the free plan is enough for most websites. Paid plans offer extra features.

Won't Cloudflare slow down my site?

On the contrary. The caching makes your site faster. It can only slow things down with a misconfiguration.

Get started

Setting up Cloudflare step by step

Step 1: create an account

Go to cloudflare.com and create a free account. The free plan already offers a lot of functionality.

Step 2: add your domain

Add your domain name. Cloudflare automatically scans your existing DNS records and imports them.

Step 3: check the DNS records

Check that all records have been imported correctly. Pay attention in particular to:

  • A records for your website
  • MX records for email
  • TXT records for SPF and verifications

Step 4: change nameservers

Cloudflare gives you two nameservers. At your registrar, change the nameservers to Cloudflare's. This can take up to 24 hours.

Step 5: configure the settings

After activation you can set up Cloudflare features:

  • SSL/TLS mode (Full or Full Strict recommended)
  • Caching settings
  • Security level
  • Page Rules for specific configurations

Important Cloudflare features

CDN (Content Delivery Network)

Cloudflare caches your static content on servers worldwide. Visitors get files from the nearest server, which improves speed.

DDoS protection

Cloudflare filters malicious traffic before it reaches your server. Even the free plan offers basic DDoS protection.

SSL/TLS

Cloudflare offers free SSL. You can choose between:

  • Flexible: SSL between the visitor and Cloudflare (not recommended)
  • Full: SSL to your server as well
  • Full (Strict): with certificate validation (recommended)

Firewall rules

Block specific countries, IP addresses or suspicious behavior. You can also set challenges for suspicious traffic.

Cloudflare with WordPress

Cloudflare works well with WordPress. Points of attention:

  • Install the Cloudflare plugin for optimal integration
  • Set up Page Rules to exclude wp-admin from caching
  • If there are problems: turn on "Development Mode" to temporarily disable caching

Common problems

Redirect loop after enabling SSL

This often happens with "Flexible" SSL while your site also has its own SSL. Choose "Full" or "Full (Strict)" instead of Flexible.

Changes not visible

Cloudflare caches aggressively. Purge the cache in your Cloudflare dashboard or temporarily turn on Development Mode.

IP addresses in logs

Your server sees Cloudflare's IP addresses instead of visitors'. Install a module or plugin to restore the real IP through the CF-Connecting-IP header.

Free vs Pro

The free plan is enough for most sites. Pro ($20/month) adds:

  • Web Application Firewall (WAF)
  • Image optimization
  • Mobile optimization
  • Faster support

For business sites Pro can be worth it, but start with free to test.

Getting the most out of Cloudflare

Setting up Page Rules

Page Rules let you create specific settings per URL pattern:

  • Cache everything for static pages
  • Bypass cache for admin sections
  • Force HTTPS on all pages
  • Set custom security levels

With the free plan you get 3 Page Rules, often enough for basic optimization.

Maximizing caching

By default Cloudflare caches static files. For better performance:

  • Set the Browser Cache TTL high for static content
  • Use Cache Everything for static pages
  • Enable Auto Minify for CSS, JavaScript and HTML

Using security features

Even the free plan offers powerful security:

  • Bot Fight Mode against malicious bots
  • Browser Integrity Check
  • Email Address Obfuscation
  • Hotlink Protection

When to disable Cloudflare

Sometimes you need to bypass Cloudflare temporarily:

  • When debugging website problems
  • When you need to find your server IP
  • With conflicts with certain applications

Use Development Mode to temporarily disable caching without deactivating Cloudflare entirely.

Cloudflare is a powerful tool that can improve any website. Start with the free features and upgrade to Pro if you need the extra capabilities.

Cloudflare has grown into an indispensable tool for website management. The free version already offers functionality you used to pay hundreds of euros a month for. From DDoS protection to caching, from analytics to SSL - the platform has it all.

For larger websites the paid plans are worth considering. They offer advanced security options, image optimization and better analytics. But for most websites the free plan is more than enough.

The initial setup takes some technical knowledge, especially changing the nameservers. But once set up, everything runs automatically. Your website becomes faster, safer and more reliable - without you having to do anything else. That is the power of Cloudflare.

Cloudflare makes your website faster and safer in a few clicks. The free version already offers more than enough for most websites. Try it out and experience the difference. You will wonder why you did not start sooner.

Cloudflare's free plan is generous enough for most websites. Try it out - the setup takes only half an hour and the benefits are immediately noticeable in faster load times and better protection.

Cloudflare deserves a spot in your toolkit. The combination of speed and security is unbeatable for the price of free.

Setting up Cloudflare takes half an hour and delivers immediate results. Combine it with good web hosting for the best performance.

Setting up Cloudflare: plans compared

Before you start setting up Cloudflare, it is good to know which plan suits you. Below is a comparison of the available plans.

FeatureFreePro ($20/mo)Business ($200/mo)
CDNYesYesYes
DDoS protectionBasicAdvancedAdvanced
WAF rulesLimitedExtensiveCustom
Image optimizationNoYes (Polish)Yes
CachingStandardExtensiveFull
SSLUniversalDedicatedDedicated + wildcard
SupportCommunityEmailChat + phone

For most websites Cloudflare's free plan is more than enough. Combined with good web hosting you get the most out of your website.

Setting up Cloudflare: optimal configuration

After setting up Cloudflare, there are a number of settings you should optimize right away:

  1. SSL/TLS mode: set it to "Full (Strict)" if your hosting has a valid SSL certificate
  2. Always Use HTTPS: enable this to redirect all HTTP traffic
  3. Browser Cache TTL: set it to "Respect Existing Headers" or at least 4 hours
  4. Auto Minify: enable it for JavaScript, CSS and HTML
  5. Brotli compression: enable it for better compression than Gzip
  6. Page Rules: set up caching rules for static content
  • Tip: use "Development Mode" temporarily when you are testing changes to your website
  • Tip: only enable "Under Attack Mode" during an active DDoS attack

Frequently asked questions about setting up Cloudflare

Will my website get slower with Cloudflare?

In exceptional cases this can happen if Cloudflare servers are farther from your visitors than your own server. For Dutch websites with a Dutch data center the effect is minimal to positive. Always test before and after setup.

Can I use Cloudflare with any hosting provider?

Yes, Cloudflare works with any hosting provider. You only have to change your nameservers to Cloudflare's. This works independently of your hosting.

What if my website has problems after setting up Cloudflare?

The most common problems are SSL related. Make sure the SSL/TLS mode matches your hosting configuration. With redirect loops the SSL mode is probably set to "Flexible" while your hosting enforces HTTPS. Set it to "Full (Strict)".

Setting up Cloudflare together with your hosting

After setting up Cloudflare, it is important to align the configuration with your hosting environment. Make sure you pass the real IP address of visitors to your server through the CF-Connecting-IP header. With Apache, install the mod_remoteip module, or configure Nginx with set_real_ip_from for the Cloudflare IP ranges. Without this setting, your server logs and security plugins only see the Cloudflare IP address instead of your visitors'. With Theory7 web hosting this is correctly configured by default.

Setting up Cloudflare: advanced features

Besides the basic configuration, Cloudflare offers various advanced features that make your website faster and safer. Learn how to get the most out of your setting up Cloudflare configuration.

Configuring Page Rules

With Page Rules you can set specific behavior for certain URL patterns. Set up redirects for old URLs, force HTTPS on all pages, disable caching for dynamic pages such as your admin panel, or set a custom cache time for static content. The free version of Cloudflare offers three Page Rules, which is enough for most websites. Prioritize rules that have the biggest impact on performance and security.

Setting up Firewall Rules

The Cloudflare Firewall offers powerful protection against common attacks. Set up rules to block specific countries if you do not expect international traffic, block known malicious user agents, and protect your login page with an extra security layer. The Web Application Firewall (WAF) offers ready-made rules that protect against common vulnerabilities such as SQL injection and Cross-Site Scripting attacks.

Cloudflare features overview

FeatureFree planPro planBusiness plan
CDN and cachingYesYesYes
SSL/TLSSharedDedicatedDedicated + wildcard
Page Rules32050
WAFBasicAdvancedAdvanced + custom
Image optimizationNoYes (Polish)Yes
RailgunNoNoYes

Setting up Cloudflare: solving common problems

When setting up Cloudflare, various problems can occur. Here are the most common issues and their solutions.

Mixed content warnings

After enabling SSL through Cloudflare you may get mixed content warnings. This means your website uses HTTPS, but some resources (images, scripts, stylesheets) are still loaded over HTTP. Cloudflare offers the Automatic HTTPS Rewrites option that automatically fixes most of these problems. For stubborn cases you have to change the URLs in your database from http to https.

Overly aggressive caching

Sometimes Cloudflare caches pages for too long, so that changes are not immediately visible to visitors. Use the Development Mode option to temporarily disable caching while you make changes. For structural solutions, set Cache-Control headers on your server to tell Cloudflare how long content may be cached. Set shorter cache times for dynamic pages and longer times for static files.

Also read our article on improving website speed for additional optimization tips alongside Cloudflare.

Setting up Cloudflare: frequently asked questions and best practices

When setting up Cloudflare and in daily use, many of the same questions come up. Below we answer the most important questions and share best practices.

Does Cloudflare affect my SEO?

Cloudflare generally has a positive effect on SEO. The faster load times through caching and CDN improve your Core Web Vitals scores, which Google uses as a ranking factor. The always-available SSL connection is also positive for rankings. Do make sure you configure caching correctly: if Cloudflare serves outdated versions of your pages, search engines may index the wrong content. Use the Purge Cache option after publishing new content.

What if my website gets slower with Cloudflare?

In rare cases Cloudflare can make your website slower. This usually happens if your server is in the Netherlands and your visitors are mostly Dutch, but Cloudflare routes the traffic through a distant data center. Check through the debug header which data center processes your requests. If performance does not improve, consider an upgrade to the Pro plan, which offers better routing, or limit proxying to static files only.

Best practices for Cloudflare

  • Use Full Strict SSL instead of Flexible to guarantee end-to-end encryption
  • Always enable Auto Minify for HTML, CSS and JavaScript to reduce page size
  • Enable Brotli compression for better compression than standard GZIP
  • Set a Security Level that suits your website; Medium is suitable for most sites
  • Configure Bot Fight Mode to block automated attacks
  • Create a redirect from HTTP to HTTPS through the Always Use HTTPS option

Setting up Cloudflare: summary and closing tips

With the right configuration, Cloudflare is a powerful tool that makes your website faster, safer and more reliable. Here we summarize the most important tips for optimally setting up Cloudflare.

Essential settings checklist

After activating Cloudflare, work through this checklist for an optimal configuration. Set the SSL level to Full Strict for maximum security. Enable Always Use HTTPS to encrypt all traffic. Enable Auto Minify for HTML, CSS and JavaScript. Enable Brotli compression for better performance. Configure Browser Cache TTL to at least one month for static files. Set the Security Level to Medium for most websites. Enable Bot Fight Mode to block automated threats.

Cloudflare maintenance and monitoring

After the initial configuration, Cloudflare requires minimal maintenance, but regular checking is important. Review the Analytics dashboard monthly for insight into your traffic, blocked threats and caching efficiency. Check whether new security features are available after Cloudflare updates. Purge the cache after major website updates to make sure visitors see the latest version. Evaluate quarterly whether your Cloudflare plan still fits your needs and consider an upgrade as your website grows.

Setting up Cloudflare: frequently asked questions

When setting up Cloudflare, the same questions come up regularly. A frequently asked question is whether Cloudflare is compatible with all hosting providers. The answer is yes: Cloudflare works as a reverse proxy and is compatible with any hosting provider, whether you use shared hosting, VPS or a dedicated server. Another frequently asked question concerns the impact on dynamic content. By default Cloudflare only caches static files such as images, CSS and JavaScript. Dynamic content such as shopping carts and login pages is not cached unless you explicitly configure this through Page Rules or Cache Rules.

Using Cloudflare Page Rules effectively

Page Rules are a powerful part of Cloudflare with which you can configure specific settings per URL pattern. Use Page Rules to adjust cache settings for specific pages, exclude certain pages from caching or set extra security measures for sensitive sections of your website. The free Cloudflare plan offers three Page Rules, which is enough for most basic configurations. Combine a rule for forcing HTTPS, one for caching static pages and one for excluding your admin panel from the cache.