Do these 3 things before closing this tab:
1Clear out junk files and repair common Windows errors2Scan for outdated or missing drivers - takes under a minute3Repair Windows errors before they cause bigger problemsTo put an existing website behind Cloudflare, add the domain to Cloudflare, review every imported DNS record, choose proxy status per hostname, change the domain’s authoritative nameservers at your registrar, and then configure SSL/TLS. Cloudflare normally remains separate from your web host: your hosting provider still serves the site while Cloudflare provides authoritative DNS and, for proxied hostnames, a reverse-proxy layer.
What a Cloudflare setup changes
Four services are often confused during setup:
- Domain registration: your registrar holds the domain registration and is where you change nameservers.
- Web hosting: your host stores and serves the website files or application.
- Authoritative DNS: the provider whose nameservers publish the records for your domain.
- Proxying and TLS: Cloudflare can sit between visitors and selected origin hostnames, while handling edge certificates and other network services.
Cloudflare does not host most websites, although it can host JAMstack sites with Cloudflare Pages. You generally keep your existing host and point DNS records to it.
Choose the setup model
| Model | What changes | When it fits | Limit to check |
|---|---|---|---|
| Full (primary DNS) setup | Cloudflare becomes authoritative after you replace the registrar’s nameservers with the two Cloudflare assigns to your zone. | You control the registrar and can edit nameservers. | You must audit records before switching; a missed record can make a hostname unreachable. |
| Partial/CNAME setup | Your current DNS provider remains authoritative while Cloudflare is used as a reverse proxy for eligible hostnames. | You cannot or do not want to move authoritative DNS, and your Cloudflare account supports the configuration. | Availability, eligible plans, and exact steps depend on the account and current Cloudflare requirements. |
The rest of this guide describes the common full setup. If you use partial setup, follow the eligibility and onboarding instructions shown in your Cloudflare account rather than assuming every feature is available.
Before you start: prerequisites and a rollback plan
- An existing registered domain and access to its registrar account.
- Access to your web host’s domain-connection instructions and current DNS targets.
- Access to your mail provider and any services that verify ownership with DNS.
- A list of active hostnames such as the apex domain,
www, blog, shop, API, staging, and application subdomains. - A record of the current nameservers and DNS records, so you can diagnose or roll back a mistake.
Do not schedule the nameserver change until you know which records must continue serving web traffic, email, and verification services. Nameserver propagation is controlled by DNS caching, so keep the old zone intact while the change takes effect.
Outdated Drivers Are Slowing You Down
One free scan finds every outdated or missing driver and matches the right update for your exact hardware.Free scan · exact hardware matchWindows Errors? Fix Them Before They Spread
Repair common Windows errors and clear accumulated junk for a smoother, more stable PC - no reinstall needed.Free scan · no reinstall#1 Best Overall
- DUAL-BAND WIFI 6 ROUTER: Wi-Fi 6(802.11ax) technology achieves faster speeds, greater capacity and reduced network congestion compared to the previous gen. All WiFi routers require a separate modem. Dual-Band WiFi routers do not support the 6 GHz band.
- AX1800: Enjoy smoother and more stable streaming, gaming, downloading with 1.8 Gbps total bandwidth (up to 1200 Mbps on 5 GHz and up to 574 Mbps on 2.4 GHz). Performance varies by conditions, distance to devices, and obstacles such as walls.
- CONNECT MORE DEVICES: Wi-Fi 6 technology communicates more data to more devices simultaneously using revolutionary OFDMA technology
- EXTENSIVE COVERAGE: Achieve the strong, reliable WiFi coverage with Archer AX1800 as it focuses signal strength to your devices far away using Beamforming technology, 4 high-gain antennas and an advanced front-end module (FEM) chipset
- OUR CYBERSECURITY COMMITMENT: TP-Link is a signatory of the U.S. Cybersecurity and Infrastructure Security Agency’s (CISA) Secure-by-Design pledge. This device is designed, built, and maintained, with advanced security as a core requirement.
Step 1: Add the domain in Cloudflare
- Sign in to Cloudflare and choose Add a site (the exact label can vary slightly in the current dashboard).
- Enter the apex domain, such as
example.com, rather than onlywww.example.com. - Choose the plan shown for your account and let Cloudflare perform its DNS-record scan.
- Continue to the DNS records review screen; do not treat the scan as a complete migration.
The scan is a starting point. Cloudflare warns that automatic discovery can miss records. Compare the imported zone with your host, mail provider, analytics, identity, payment, and other service documentation.
Step 2: Audit and correct DNS records
Check the website records
Confirm the apex record and every public hostname. Your host may require an A record, an AAAA record, or a CNAME. Check that the value, record name, and any required TTL match the host’s instructions. Verify www separately; it is common for the apex to be correct while www points somewhere else.
Preserve mail records
Copy the exact MX records supplied by your mail provider. Also preserve applicable TXT records for SPF, DKIM, and DMARC. Removing or changing these can stop delivery or cause messages to fail authentication. Mail records should remain DNS-only; they are not web traffic.
Keep verification and service records
Certificate authorities, search tools, email platforms, and SaaS providers often use a specific CNAME or TXT value. Keep the exact name and value. If the service requires DNS-only verification, leave proxying disabled for that hostname.
Quick wins for a faster PC:
Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →Clear out junk files and repair common Windows errorsFree Scan →Choose proxy status deliberately
For supported A, AAAA, and CNAME records, Cloudflare offers two states:
- Proxied: visitors connect through Cloudflare, which can provide caching and security services before forwarding web requests to your origin.
- DNS only: DNS returns the destination value directly; traffic does not pass through Cloudflare’s reverse proxy.
Proxy only hostnames that serve compatible web traffic and whose origin is prepared for Cloudflare. Leave mail, many verification records, and services that require direct DNS resolution as DNS-only. A record can be correct yet still fail if proxying is enabled for a service that does not support it.
Rank #2
- Dual-band Wi-Fi with 5 GHz speeds up to 867 Mbps and 2.4 GHz speeds up to 300 Mbps, delivering 1200 Mbps of total bandwidth¹. Dual-band routers do not support 6 GHz. Performance varies by conditions, distance to devices, and obstacles such as walls.
- Covers up to 1,000 sq. ft. with four external antennas for stable wireless connections and optimal coverage.
- Supports IGMP Proxy/Snooping, Bridge and Tag VLAN to optimize IPTV streaming
- Access Point Mode - Supports AP Mode to transform your wired connection into wireless network, an ideal wireless router for home
- Advanced Security with WPA3 - The latest Wi-Fi security protocol, WPA3, brings new capabilities to improve cybersecurity in personal networks
Step 3: Change nameservers at your registrar
- In Cloudflare’s domain overview, copy the two authoritative nameservers assigned to this zone.
- Open your registrar’s domain-management page and find the nameserver or DNS delegation settings.
- Replace the registrar’s existing nameservers with the two Cloudflare values, exactly as displayed. Do not use nameserver examples from another domain.
- Save the change and return to Cloudflare to monitor activation.
This registrar-side delegation is what makes Cloudflare authoritative for a full setup. The registrar remains your domain registrar; Cloudflare becomes the authoritative DNS provider. If DNSSEC is enabled at the registrar or old DNS provider, follow the current Cloudflare and registrar procedure for changing nameservers. An old or mismatched DS record can make the domain fail validation even when the nameservers look correct.
Step 4: Configure SSL/TLS and HTTPS
After Cloudflare recognizes the nameserver change, open the SSL/TLS settings and make three decisions:
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
Choose an edge certificate
Cloudflare documents Universal certificates as free, publicly trusted certificates that it issues and renews for domains added to and activated on Cloudflare. Check that the certificate covers the hostnames visitors use, including the apex and www where applicable.
Select an encryption mode
The mode controls encryption between visitors and Cloudflare and, depending on the mode, between Cloudflare and your origin. Choose it based on the certificate and HTTPS configuration installed on your web host. An edge certificate alone does not prove that the connection from Cloudflare to the origin is encrypted. If your origin’s certificate is missing, expired, or otherwise incompatible, selecting a stricter mode can expose that configuration problem rather than fix it.
Decide whether to enforce HTTPS
Enable HTTPS redirection only after the intended HTTPS URL works at the origin and through Cloudflare. Also check application settings for hard-coded HTTP links, redirect loops, and cookies that require the secure flag. Cloudflare’s setup guidance treats certificate selection, encryption mode, and HTTPS enforcement as separate choices.
Step 5: Verify the migration
- Open the apex domain over HTTPS.
- Open
wwwand each production hostname listed in your inventory. - Test a representative page, login flow, form, static asset, and any API endpoint that should be reachable.
- Send and receive a test email if the domain uses mail.
- Check ownership-verification and third-party integrations that depend on DNS.
- In Cloudflare, confirm that the zone is active and that the expected records and proxy states remain present.
If the site does not resolve, first compare the active nameservers and DNS records. If it resolves but returns an origin error, inspect the origin host, firewall, certificate, and application logs. Avoid changing unrelated Cloudflare settings until you know whether the failure is DNS, proxying, TLS, or the origin server.
Rank #3
- NIGHTHAWK WIFI 6 ROUTER FOR YOUR WHOLE HOME: Delivers fast, reliable WiFi across every room of your apartment or small home for streaming, gaming, video calls, and smart home devices, all running at the same time without slowing each other down.
- WORKS WITH YOUR EXISTING INTERNET SERVICE: Pairs with your existing modem or gateway via ethernet. Compatible with most cable, fiber, DSL, and satellite providers. Some gateways and modem router combos may require bridge mode. No coax needed.
- SET UP AND MANAGE YOUR NETWORK WITH THE NIGHTHAWK APP: Download the free Nighthawk app on iOS or Android for guided setup. Manage WiFi, run speed tests, pause devices, and set up guest networks from anywhere. Active internet required.
- READY FOR THE DEVICES YOU ALREADY OWN: Your phones, laptops, and TVs work right out of the box. WiFi 6 delivers speeds up to 1.8 Gbps across 2.4 GHz and 5 GHz bands. Backward compatible with WiFi 5 and earlier.
- COVERAGE IN EVERY ROOM: Covers up to 1,500 sq. ft. for up to 20 connected devices. Walls, floors, and interference can reduce range. Larger or multi-story homes may benefit from a NETGEAR Orbi mesh WiFi system.
Common failures and fixes
The domain is still pending
Cause: the registrar still delegates to the old nameservers, or the change has not propagated.
Fix: compare the registrar’s nameserver entries character-for-character with Cloudflare’s assigned values. Remove extra nameservers if the registrar permits only the assigned pair, then allow DNS caches to expire.
The homepage is unreachable after activation
Cause: a missing or incorrect apex, www, A, AAAA, or CNAME record.
Fix: compare each record with the host’s documented target. Check both IPv4 and IPv6 records; an incorrect AAAA record can send some visitors to a broken server even when the A record is correct.
Free tools Windows power users keep installed
One-click scans. No signup required.
Email stopped working
Cause: MX or authentication TXT records were omitted, altered, or accidentally proxied.
Fix: restore the mail provider’s exact MX, SPF, DKIM, and DMARC values and keep mail hostnames DNS-only. Recheck any provider-specific subdomain records.
Rank #4
- 𝐅𝐮𝐭𝐮𝐫𝐞-𝐏𝐫𝐨𝐨𝐟 𝐘𝐨𝐮𝐫 𝐇𝐨𝐦𝐞 𝐖𝐢𝐭𝐡 𝐖𝐢-𝐅𝐢 𝟕: Powered by Wi-Fi 7 technology, enjoy faster speeds with Multi-Link Operation, increased reliability with Multi-RUs, and more data capacity with 4K-QAM, delivering enhanced performance for all your devices.
- 𝐁𝐄𝟑𝟔𝟎𝟎 𝐃𝐮𝐚𝐥-𝐁𝐚𝐧𝐝 𝐖𝐢-𝐅𝐢 𝟕 𝐑𝐨𝐮𝐭𝐞𝐫: Delivers up to 2882 Mbps (5 GHz), and 688 Mbps (2.4 GHz) speeds for 4K/8K streaming, AR/VR gaming & more. Dual-band routers do not support 6 GHz. Performance varies by conditions, distance, and obstacles like walls.
- 𝐔𝐧𝐥𝐞𝐚𝐬𝐡 𝐌𝐮𝐥𝐭𝐢-𝐆𝐢𝐠 𝐒𝐩𝐞𝐞𝐝𝐬 𝐰𝐢𝐭𝐡 𝐃𝐮𝐚𝐥 𝟐.𝟓 𝐆𝐛𝐩𝐬 𝐏𝐨𝐫𝐭𝐬 𝐚𝐧𝐝 𝟑×𝟏𝐆𝐛𝐩𝐬 𝐋𝐀𝐍 𝐏𝐨𝐫𝐭𝐬: Maximize Gigabitplus internet with one 2.5G WAN/LAN port, one 2.5 Gbps LAN port, plus three additional 1 Gbps LAN ports. Break the 1G barrier for seamless, high-speed connectivity from the internet to multiple LAN devices for enhanced performance.
- 𝐍𝐞𝐱𝐭-𝐆𝐞𝐧 𝟐.𝟎 𝐆𝐇𝐳 𝐐𝐮𝐚𝐝-𝐂𝐨𝐫𝐞 𝐏𝐫𝐨𝐜𝐞𝐬𝐬𝐨𝐫: Experience power and precision with a state-of-the-art processor that effortlessly manages high throughput. Eliminate lag and enjoy fast connections with minimal latency, even during heavy data transmissions.
- 𝐂𝐨𝐯𝐞𝐫𝐚𝐠𝐞 𝐟𝐨𝐫 𝐄𝐯𝐞𝐫𝐲 𝐂𝐨𝐫𝐧𝐞𝐫 - Covers up to 2,000 sq. ft. for up to 60 devices at a time. 4 internal antennas and beamforming technology focus Wi-Fi signals toward hard-to-reach areas. Seamlessly connect phones, TVs, and gaming consoles.
A verification service cannot find its record
Cause: the record name or value is wrong, or the service requires DNS-only status.
Fix: copy the provider’s value exactly, remove unintended quotation or whitespace changes, and disable proxying when the provider instructs you to do so.
The Tool Desk
Outbyte PC Repair FREERepair Windows errors before they cause bigger problemsFix Now →Outbyte Driver Updater FREEScan for outdated or missing drivers - takes under a minuteDriver Scan →Redirect loops or an HTTPS origin error
Cause: the selected encryption mode does not match the origin certificate or the origin redirects Cloudflare in a way that repeats.
Fix: verify that the origin serves HTTPS directly, inspect its certificate coverage and expiration, then select the Cloudflare mode appropriate to that configuration. Test before enabling a global HTTPS redirect.
DNSSEC validation fails
Cause: a stale DS record at the registrar or an incomplete DNSSEC transition.
Fix: follow the current DNSSEC instructions from both Cloudflare and your registrar. Do not delete or recreate security records blindly; a mismatched delegation can make all DNS answers appear invalid.
Best Value
- Dual band router upgrades to 1200 Mbps high speed internet (300mbps for 2.4GHz plus 900Mbps for 5GHz), reducing buffering and ideal for 4K stream
- Full Gigabit Ports - Gigabit Router with 4 Gigabit LAN ports, ideal for any internet plan and allow you to directly connect your wired devices
- Boosted Coverage - Four external antennas equipped with Beamforming technology extend and concentrate the Wi-Fi signals
- MU-MIMO technology - (5GHz band) allows high speeds for multiple devices simultaneously
- Access Point Mode - Supports AP Mode to transform your wired connection into wireless network, an ideal wireless router for home
Operational guidance after launch
- Keep an export or documented copy of the active zone and update it when adding services.
- Review new hostnames before enabling proxying; a web origin, mail endpoint, and verification record do not have the same requirements.
- When moving hosts, lower DNS TTL in advance only if your migration plan requires faster cache turnover, then restore an appropriate value afterward.
- Keep origin firewall rules and certificates maintained. Cloudflare does not remove the need to secure and operate the origin server.
- Document who controls the registrar, Cloudflare account, hosting account, and mail account so a future administrator can recover the setup.
Or skip the browser setup
If your next task is generating reliable website screenshots for documentation or monitoring, ScreenshotNeo provides a one-request API rather than requiring you to configure a browser. It accepts consent banners before capture and removes more than 60 known consent platforms, newsletter popups, and chat widgets; each step can be disabled. Only clean shots are billed: bot checks or CAPTCHAs, blank pages, timeouts, failed loads, and cache hits cost nothing, and each response reports the result in X-Page-Verdict and X-Billed headers. It also offers an MCP server for AI agents, with take_screenshot, get_page_info, and capture_pdf tools.
Here is a complete cURL request (see the ScreenshotNeo API documentation):
curl -G "https://api.screenshotneo.com/v1/shot" -d access_key=YOUR_API_KEY --data-urlencode url=https://example.com -o shot.webp
Python:
import requests
r = requests.get("https://api.screenshotneo.com/v1/shot", params={"access_key": "YOUR_API_KEY", "url": "https://example.com"}, timeout=90)
open("shot.webp", "wb").write(r.content)
Node.js:
const q = new URLSearchParams({ access_key: 'YOUR_API_KEY', url: 'https://example.com' });
const res = await fetch(`https://api.screenshotneo.com/v1/shot?${q}`);
const buffer = Buffer.from(await res.arrayBuffer());
await import('node:fs/promises').then(fs => fs.writeFile('shot.webp', buffer));
ScreenshotNeo includes full-page capture with lazy images loaded, CSS-selector element capture, dark mode, device presets and custom viewports, retina scale, PDF output, custom CSS and JavaScript, clicks, waits, request blocking, headers, cookies, user agents, authorization, timezone and geolocation, transparent backgrounds, resizing, configurable caching, signed links, asynchronous webhooks, bulk capture for up to 100 URLs per call, a usage API, and an OpenAPI specification. Its parameter names are compatible with those used by other screenshot APIs, which can simplify a migration.
The Free plan includes 1,000 screenshots per month with no card. Paid plans start at $5 for 3,000 shots; yearly billing provides two months free, and every feature is available on every plan. Create a free ScreenshotNeo account.
FAQ
Do I need to transfer my domain registration to Cloudflare?
No. A full setup changes authoritative nameservers at your existing registrar; it does not require moving the registration.
Will Cloudflare replace my web host?
Usually no. Keep the host that serves your website unless you intentionally deploy it on a service such as Cloudflare Pages.
Can I proxy every DNS record?
No. Proxying is intended for supported web traffic. Mail and many verification or non-HTTP services should remain DNS-only.
Frequently Asked Questions
Do I need to transfer my domain registration to Cloudflare?
No. A full setup changes authoritative nameservers at your existing registrar; it does not require moving the registration.
Recommended Free Tools
Will Cloudflare replace my web host?
Usually no. Keep the host that serves your website unless you intentionally deploy it on a service such as Cloudflare Pages.
Can I proxy every DNS record?
No. Proxying is intended for supported web traffic. Mail and many verification or non-HTTP services should remain DNS-only.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




