Cloudflare Proxied vs DNS Only: The Orange Cloud Explained
In Cloudflare's DNS settings, the orange cloud sends traffic through Cloudflare and the grey cloud doesn't. What changes with each, which records must be grey, the SSL modes that avoid redirect loops, and how proxying interacts with your host's automatic SSL.
Every DNS record in Cloudflare has a little cloud icon next to it. It's one of the most consequential switches in the dashboard:
- ๐ Proxied (orange cloud): visitors connect to Cloudflare, which connects to your server.
- โช DNS only (grey cloud): Cloudflare just answers "this domain is at this IP," and visitors connect directly to your server.
(New to Cloudflare? What is Cloudflare?)
What changes when you proxy
| Proxied ๐ | DNS only โช | |
|---|---|---|
What dig yourapp.com shows |
Cloudflare's IPs | Your server's real IP |
| Caching / CDN | Yes | No |
| DDoS protection, firewall rules | Yes | No |
| Your server's IP hidden | Yes (mostly) | No |
| SSL certificate visitors see | Cloudflare's | Your server's |
| Works for any port/protocol | HTTP/HTTPS (and some ports) | Everything |
| Upload size and timeout limits | Cloudflare's plan limits | Your server's |
Records that must be grey
Proxying only works for web traffic. These should be DNS only:
- Mail records โ MX records can't be proxied, and the hostnames they point to (like
mail.yourapp.com) need grey A records. - SSH, database, game servers โ anything that isn't HTTP(S) on standard ports.
- TXT records (verification, SPF, DKIM) โ not proxyable anyway.
- Hostnames your host needs to reach directly for verification, if it says so.
The SSL mode trap
When proxied, there are two connections: visitor โ Cloudflare, and Cloudflare โ your server. Cloudflare's SSL/TLS mode controls the second:
| Mode | Cloudflare โ server | Use it? |
|---|---|---|
| Off | No HTTPS anywhere | Never |
| Flexible | Plain HTTP | Avoid โ causes redirect loops and isn't secure end-to-end |
| Full | HTTPS, any certificate | OK as a stopgap |
| Full (strict) | HTTPS, valid certificate | Use this |
The classic problem: your server redirects HTTP to HTTPS, Cloudflare is on Flexible and connects over HTTP, gets redirected, tries again over HTTPโฆ โ ERR_TOO_MANY_REDIRECTS. Fix: switch to Full (strict). (ERR_TOO_MANY_REDIRECTS)
For Full (strict), your server needs a valid certificate โ from your host's automatic SSL, from Let's Encrypt, or a free Cloudflare Origin certificate installed on your server.
Proxying and your host's automatic SSL
Many hosts issue Let's Encrypt certificates automatically by proving they control your domain. With the orange cloud on, that check can fail, because requests hit Cloudflare first. Common approach:
- Add the domain in your host with the record grey.
- Wait until the host shows the certificate as active.
- Turn the cloud orange and set SSL to Full (strict).
Renewals usually keep working (HTTP-based checks pass through Cloudflare), but if your host's docs say otherwise, follow them. (How automatic SSL works)
Other side effects of proxying
- Visitor IPs. Your server sees Cloudflare's IP. Read the real one from the
CF-Connecting-IPheader (or configure your proxy to trust Cloudflare's ranges) โ otherwise logs and rate limiting treat every visitor as the same few IPs. - Caching after deploys. Static files may be cached at Cloudflare; purge the cache or use hashed file names.
- Long requests can time out at Cloudflare's limit (around 100 seconds on standard plans) even if your server would have answered.
- Large uploads are capped by plan.
- The IP isn't truly secret if it leaked before (old DNS records, email headers). Firewall your server to accept web traffic only from Cloudflare's IP ranges if hiding it matters.
When to use which
- Starting out, or debugging: grey. Fewer moving parts.
- Under attack, high traffic, or want caching and firewall rules: orange, with Full (strict).
- Mail, SSH, databases: always grey.
The summary
- Orange = traffic through Cloudflare (CDN, protection, hidden IP). Grey = DNS only.
- Mail and non-web services must be grey.
- With orange, always use SSL mode Full (strict).
- Let your host issue its certificate before turning the cloud orange.
EasySpawn issues SSL certificates for your custom domains automatically and works with Cloudflare in either mode. See how it works or join the waitlist.
Related: What Is Cloudflare? ยท ERR_TOO_MANY_REDIRECTS ยท DNS Records Explained ยท How to Connect a Custom Domain
Keep reading
www vs non-www: Which Should Your Website Use?
example.com or www.example.com? What the difference actually is, why it doesn't matter for SEO as long as you pick one, how to redirect the other, the DNS catch with root domains, and the cookie consideration that makes some teams choose www.
Subdomain vs Subdirectory: blog.example.com or example.com/blog?
Should your blog, docs or app live on a subdomain (app.example.com) or a subdirectory (example.com/app)? The technical differences, what it means for SEO, cookies and hosting, and sensible defaults for a small product.