Cloudflare settings
What every button in the Cloudflare settings does
My domains → domain → Cloudflare settings. Every domain has its own Cloudflare account: the email, password, and 2FA are on the domain card while it uses Cloudflare NS.
Do not share the Cloudflare account details: they give access to DNS and the website.
SSL mode
- Full (strict) – the server has a valid certificate. The best option for a live website.
- Full – the server has a self-signed certificate. Set after purchase.
- Flexible – the server has no HTTPS. Temporary only: an HTTPS redirect on the server causes an endless loop.
- Off – HTTPS is off.
More: Cloudflare docs.
DDoS protection
- Off – almost no checks.
- Low and Medium – normal operation. Medium is set after purchase.
- High – stricter checks, some visitors see a challenge.
- Under Attack – only during an attack: every visitor goes through a check.
Security rules
Up to 5 rules per domain. Create rule → name → expression → action.
- Expression – the condition for matching requests, like the "When incoming requests match" field in Cloudflare. For example:
(ip.src.country ne "US"). - Block – the request is rejected.
- Managed Challenge – Cloudflare picks the check itself.
- JS Challenge – a browser check for a few seconds.
- Interactive Challenge – the visitor passes the check manually.
- Skip – other rules do not apply to these requests.
A rule can be edited, disabled, or deleted.
Redirects
Add → send a domain or a link.
- Domain (
target.com) – the path is kept:example.com/pageopenstarget.com/page. - Link with a path (
https://target.com/landing) – every page leads to it. - Code and scope – 301, works for the domain and all subdomains. Without a scheme the bot adds
https://. - Remove – delete the redirect.
Purge cache
Clears the whole Cloudflare cache at once, with no confirmation. Use it when the server has a new version of the website but visitors still see the old one. DNS cache is not affected.
Hosting
A static website without your own server: send a .zip archive up to 20 MB with index.html at the root. The bot deploys it to Cloudflare Pages, connects it to the domain, and notifies you in a few minutes.
Third-party NS
With someone else's NS, the Cloudflare settings in the bot do not apply. Open any section and tap Link: the bot moves the NS back to Cloudflare.
Errors 521, 522, 525, 526: Domain does not work.