Cloudflare and DNS

DNS and Cloudflare, set up so the origin is not left open.

Nameservers, records, SSL, redirects and a WAF in front of a VPS or dedicated server you already own. The Cloudflare account stays yours. We do not resell the proxy.

Your server. Your provider. Our Linux expertise.

The usual break

The proxy is on. The certificate or the mail record is not.

Moving nameservers to Cloudflare is easy. What fails afterwards is mail, because the MX was proxied, or the origin, because SSL is set to Full and the server has no certificate. We fix the records and the web server together, not one side only.

nameserversA and AAAAMXSPF / DKIM / DMARCSSL moderedirects
What we do

Put Cloudflare in front, then close the side door

DNS move

Export the current zone, recreate it, leave MX and mail records unproxied, lower TTL before a server move, then switch nameservers at the registrar.

SSL and the origin

A real certificate on the VPS, Full (strict) in Cloudflare, and the origin firewall limited to Cloudflare ranges so the old IP is not a bypass.

WAF and cache

A small rule set for wp-login and xmlrpc, cache on static files, bypass on cart and admin. Not a 40-rule paste from a blog.

What Cloudflare does not do

PTR, the mail server, and a dead disk stay on the VPS

Still the provider’s job

Reverse DNS lives on the IP, at Hetzner or OVHcloud, not in Cloudflare. Mail delivery problems are the MTA and the PTR, even when the website is orange-clouded.

Still a server problem

A 502 from the origin, a full disk, or PHP-FPM down is not a DNS incident. We trace it to the VPS instead of adding another page rule.

Mail server support →

Price

Hourly, unless the zone is large enough to quote

A single site onto Cloudflare, with SSL and the origin locked, is normal technical work at €55/hour, minimum 1 hour. A registrar move with many domains, or a WAF in front of several applications, is quoted after the zone export. No Cloudflare plan is sold through us.

Pricing → · Server security →

Independent since 2004

The Cloudflare login stays yours. We ask for a temporary member on the account, not the owner password, and you remove it when the records are confirmed.

Your server. Your provider. Our Linux expertise.

DNS wrong, or Cloudflare half-finished?

Tell us the domain and whether mail is on the same server. We reply with the records to change before any cut.

Request Support → Contact Us