Configuring Cloudflare as an External DNS Provider
Cloudflare can manage the DNS records of your domain instead of your current DNS provider. In addition to DNS hosting, it can proxy the traffic of your website, provide an SSL certificate for it and filter malicious requests. This guide shows how to move the DNS management of a domain to Cloudflare while keeping your website and mail working.
What changes
Moving DNS management to Cloudflare does not transfer the domain registration and does not move your website. The domain stays with your current registrar, the website files stay on your server, and moving DNS management does not change the IP address of your server. Only the nameservers of the domain change: after the switch, Cloudflare answers DNS queries, and you manage all DNS records in the Cloudflare dashboard. Mail keeps working if its DNS records are transferred correctly.
Preparation
Before you start, you need:
- a domain and access to the management panel of its registrar;
- a Cloudflare account, the Free plan is enough;
- the IP address or hostname used by your website, for example, of an INTROSERV VPS or dedicated server.
Open the DNS settings of the domain at your current DNS provider and save a copy of all records: A, AAAA, CNAME, MX, TXT, SRV, CAA and others. You will compare them with the records that Cloudflare imports.
If DNSSEC is enabled for the domain, disable it and remove the existing DS records at your registrar before you change the nameservers. Otherwise, DNS queries for the domain may fail after the switch. When the domain is active in Cloudflare, you can enable DNSSEC there and add the new DS record at your registrar.
Add the domain to Cloudflare
Log in to the Cloudflare dashboard. On the Account home page, enter the domain name without www in the Add a domain field, for example example.com, and click Connect. On the Connect your domain page, keep Automatic in the Import DNS records field and click Continue.

Choose a plan. The Free plan includes authoritative DNS, the Cloudflare proxy and Universal SSL. Unless you need features that are available only on a paid plan, click Select plan under Free.

Check the DNS records
Cloudflare runs a quick scan of DNS records and shows the records it finds. The scan checks common record types and names, so it may miss custom or rare records. Compare the list with the copy you saved and add the missing records with Add record.

Check the most important records carefully:
- the A and AAAA records of the website must point to the correct server, and its CNAME records to the correct hostname;
- the MX records and the DNS records used by your mail server must match the old configuration, otherwise mail delivery stops;
- TXT records for SPF, DKIM, DMARC, domain verification and other services must be transferred unchanged.
Choose between proxy and DNS only
Set the DNS records and their Proxy status before you change the nameservers. Cloudflare lets you set the Proxy status for A, AAAA and CNAME records:
- Proxied: visitors connect to Cloudflare, and Cloudflare forwards the requests to your server. The real IP address of the server is hidden, and the Cloudflare SSL certificate and protection features work;
- DNS only: Cloudflare only answers DNS queries with the real IP address of your server, and visitors connect to the server directly.
Use Proxied for the website records, for example example.com and www. Cloudflare enables the proxy for all imported A and CNAME records by default, including records such as mail and ftp, so switch these records to DNS only. The standard Cloudflare proxy is intended for HTTP and HTTPS traffic and does not pass services such as SSH, SMTP or FTP. Use DNS only for the hostnames of mail servers, SSH, FTP, game servers and other services that are not websites.
The Cloudflare edge SSL certificate is used when HTTPS traffic passes through the Cloudflare proxy. With DNS only, visitors connect directly to your server, so the server must have its own SSL certificate for HTTPS.
If you use the proxy for your website, check the encryption mode after the domain becomes active. Open SSL/TLS, then Overview, and click Configure. By default, Cloudflare uses the Automatic SSL/TLS mode and chooses the most secure mode that your server supports. To set the mode manually when your server has a valid SSL certificate, for example from Let's Encrypt, select Full (Strict) and click Save: the connection between Cloudflare and the server is then encrypted and the certificate is verified. Avoid the Flexible mode if your website redirects HTTP to HTTPS, because this combination causes a redirect loop.

Change the nameservers
When the records are ready, click Continue to activation. Cloudflare shows two nameservers assigned to your domain, for example ada.ns.cloudflare.com and bob.ns.cloudflare.com. The names differ for each account. Below them, Cloudflare lists the current nameservers of the domain that you need to remove.

Open the control panel of your domain registrar, find the nameserver (NS) settings of the domain and replace the current nameservers with the two Cloudflare nameservers. Remove all other nameservers and save the changes.
Cloudflare checks the nameservers automatically. You can also start the check manually on the Overview page of the domain. The change usually takes effect within a few hours, but it can take up to 24 hours. When it is complete, the domain gets the Active status in the dashboard, and Cloudflare sends you an email.
Check the result
To check the DNS of the domain, run on Linux or macOS:
dig NS example.com +short dig A example.com +short dig MX example.com +short
On Windows:
nslookup -type=ns example.com nslookup -type=a example.com nslookup -type=mx example.com
The NS query must return the two Cloudflare nameservers. The MX query must return the mail servers you use for the domain: if you did not change your mail provider, they match the MX records of the old configuration. For a proxied website, the A query returns Cloudflare addresses instead of the IP address of your server. This is expected. Then open the website in a browser and send a test email to an address on the domain.
After the transfer, manage all DNS records of the domain in Cloudflare. Changes at the old DNS provider no longer have any effect.
If something does not work
If the domain stays in the Pending status for more than 24 hours, check that the nameservers at the registrar exactly match the two nameservers assigned by Cloudflare and that no other nameservers remain. If DNSSEC was enabled, make sure that the old DS record has been removed.
If the website does not open, check the A, AAAA or CNAME records of the website and the SSL/TLS encryption mode. A redirect loop usually means that the Flexible mode is used together with a redirect to HTTPS on the server.
If mail stopped working, compare the MX, TXT and mail server records in Cloudflare with the copy you saved. The DNS record of the mail server, for example the A or AAAA record of mail.example.com, must be set to DNS only, because the standard Cloudflare proxy does not pass SMTP traffic.
If a subdomain does not work, check that its record exists in Cloudflare. The quick scan often misses subdomains, so add their records manually.