What Is Cloudflare? What It Does When You Put Your Site Behind It
Cloudflare sits between your visitors and your server: DNS, a CDN, free SSL, DDoS protection and a firewall. What changes when you turn on the orange cloud, what it costs, what it can break, and whether a small app needs it.
Sooner or later, someone tells you to "put it behind Cloudflare." Cloudflare is a company that runs a huge network of servers around the world. When you put your site behind it, your visitors connect to Cloudflare first, and Cloudflare connects to your server on their behalf.
That middle position is what lets it do so many things.
The main things it does
1. DNS. Cloudflare can be where your domain's records live — the address book that says yourapp.com points to your server. It's free, fast, and the dashboard is easier than most registrars'. (DNS records explained)
2. CDN (caching). It keeps copies of your images, CSS and JavaScript in data centres near your visitors, so pages load faster and your server does less work. (What is a CDN?)
3. SSL. Visitors get HTTPS to Cloudflare automatically. (What is HTTPS?)
4. DDoS protection. If someone floods your site with traffic, Cloudflare absorbs it before it reaches your server. (What is a DDoS attack?)
5. Firewall and bot rules. Block countries, challenge suspicious bots, rate-limit a login page.
6. Developer platform. Workers (code that runs on Cloudflare's network), R2 storage, Pages hosting and more. That's a separate product world; you can use the DNS and CDN without touching it.
The orange cloud
In Cloudflare's DNS settings, each record has a cloud icon:
- Orange (proxied): traffic goes through Cloudflare. You get caching, protection and the hidden server IP.
- Grey (DNS only): Cloudflare just answers "where is this site?" and visitors connect straight to your server.
Most of Cloudflare's features only apply to orange-cloud records. We explain when to use each in Cloudflare proxied vs DNS only.
How you set it up
- Create a free Cloudflare account and add your domain.
- Cloudflare scans your existing DNS records. Check them carefully — especially email (MX) records.
- At your registrar, change the domain's nameservers to the two Cloudflare gives you.
- Wait for the change to spread (usually minutes to a few hours). (DNS propagation)
Your domain stays registered where it is; only the DNS moves.
What it costs
The free plan includes DNS, the CDN, SSL, basic DDoS protection and a limited set of firewall rules. That's enough for most small apps. Paid plans add more rules, image optimisation and support.
What it can break
Cloudflare is helpful, but it adds a layer that can confuse things:
- Redirect loops. The classic
ERR_TOO_MANY_REDIRECTShappens when Cloudflare's SSL mode is "Flexible" and your server also redirects to HTTPS. Use "Full (strict)." (Fixing ERR_TOO_MANY_REDIRECTS) - Stale content. Cached files may not update after a deploy until you purge the cache.
- Your server sees Cloudflare's IP, not the visitor's. Logs and rate limits need to read the
CF-Connecting-IPheader. - Automatic SSL on your server can fail if it relies on a challenge Cloudflare intercepts.
- WebSockets and large uploads work, but have plan limits.
Does a small app need it?
Not necessarily. If your host already provides SSL and a CDN, Cloudflare's DNS alone is still a nice upgrade, and proxying can come later — when you get attacked, go viral, or want a firewall. Turning it on is a five-minute job.
The summary
- Cloudflare sits between visitors and your server.
- Free tier: DNS, CDN, SSL, DDoS protection, basic firewall.
- The orange cloud turns those features on for a record; grey is DNS only.
- Use "Full (strict)" SSL to avoid redirect loops.
EasySpawn handles SSL for your custom domain automatically and works with Cloudflare in front, proxied or DNS-only. See how it works or join the waitlist.
Related: How to Connect a Custom Domain to Your App · How to Transfer a Domain · What Is a Domain Name? · Reverse Proxies Explained
Keep reading
What Is HTTPS? The Padlock, Explained for Beginners
HTTPS is why the browser shows a padlock instead of 'Not secure'. What it protects, what it doesn't, what a certificate is, why your app needs it before launch, and how to fix the common 'mixed content' and certificate errors.
"Your Connection Is Not Private" on Your Own Site: Causes and Fixes
When visitors see NET::ERR_CERT_DATE_INVALID, ERR_CERT_COMMON_NAME_INVALID or ERR_CERT_AUTHORITY_INVALID on your site, the SSL certificate is expired, for the wrong name, or incomplete. How to tell which, and how to fix each one.