
Cloudflare is a free CDN and reverse proxy that works as a middle layer between your visitors and your DirectAdmin hosting server. When you move your domain's nameservers to Cloudflare, traffic flows through Cloudflare's network before reaching the real server — speeding up your site, filtering malicious traffic, and hiding your server's real IP. This guide explains the setup step by step, including the common pitfalls with MX records and SSL.
Before You Start: Back Up Your DNS Records
In DirectAdmin, go to DNS Management and note down the important records before making any changes:
- A Records (your domain and www)
- MX Records (email routing)
- TXT Records (SPF, DKIM, domain verification)
- CNAME Records if any
Step 1: Add Your Domain to Cloudflare
- Create a free account at cloudflare.com
- Click Add a Site and enter your domain
- Select the Free plan
- Cloudflare scans your DNS and imports existing records automatically
- Review the imported records carefully — make sure A, MX, and TXT records are all present
Step 2: Update Nameservers at AsiaGB
- Log in to billing.in.th
- Go to Domains → select your domain → Nameservers
- Replace the existing nameservers with the two Cloudflare nameservers provided
- Save and wait 24–48 hours for propagation
Step 3: Configure SSL in Cloudflare
Go to SSL/TLS → Overview and select the appropriate mode:
- Full (Strict) — if your hosting already has a valid SSL certificate (recommended)
- Full — if your hosting has a self-signed certificate
- Flexible — only if your hosting has no SSL at all (avoid if possible)
DNS Management After Cloudflare
Once Cloudflare is active as your authoritative DNS, all DNS changes must be made in the Cloudflare Dashboard, not in DirectAdmin's DNS Management. DirectAdmin's DNS panel is no longer authoritative.
Fix: Real IP Being Blocked
Some server configurations may block requests because they see Cloudflare's IP instead of the visitor's real IP. To restore real visitor IPs:
- Enable Cloudflare's mod_cloudflare or use the Restore Visitor IP feature in your server config
- Alternatively, add Cloudflare's IP ranges to your server's trusted proxy list
SSL Warning: Never use Cloudflare's "Flexible" SSL mode on a site that already forces HTTPS. The combination creates an infinite redirect loop (HTTP → Cloudflare SSL → HTTP on your server → redirect to HTTPS → loop). Use Full or Full (Strict) instead.
Frequently Asked Questions
Do I have to drop DirectAdmin to use Cloudflare?
No. DirectAdmin still stores your website and manages your hosting as before. Cloudflare only takes over DNS and acts as a proxy in front.
Why does my email stop working after moving to Cloudflare?
The most common cause is the MX record being set to Proxied (orange cloud). It must always be DNS-only (grey cloud), because Cloudflare does not proxy email traffic.
Is the Cloudflare Free plan enough?
It is enough for most websites — you get CDN, SSL, and basic protection. Paid plans suit only sites needing advanced security features.
Why Use Cloudflare with DirectAdmin Hosting?
Cloudflare delivers three major benefits for free the moment you point your domain's nameservers to it. The first is a global CDN (Content Delivery Network). Cloudflare operates over 300 edge servers worldwide. When visitors access your site from overseas, static files — images, CSS, and JavaScript — are served from the nearest edge location instead of travelling all the way from your Thai server. This significantly improves page load speed for visitors in Europe, the Americas, or anywhere far from your server's location.
The second benefit is basic DDoS protection. Cloudflare analyses traffic patterns in real time and filters out malicious bots and suspicious requests before they reach your actual server. This reduces server load during attacks and helps keep your site available even when targeted. The third benefit is a free SSL certificate. Cloudflare issues a Universal SSL certificate for your domain automatically. Even if your hosting already has SSL installed, Cloudflare's edge SSL layer ensures visitors always see HTTPS, without you doing anything extra.
- CDN — Caches static files at edge nodes globally, reducing latency for international visitors
- DDoS Protection — Filters attack traffic before it reaches your hosting server
- Free SSL — Automatically issues a Universal SSL certificate for your domain
- IP masking — Cloudflare's IP is exposed to the outside world instead of your real server IP
- Bot management — Blocks known malicious crawlers and spam bots at no cost
Configuring DNS Records in Cloudflare to Point to Your Hosting
The core of the setup is creating the correct A records and choosing the right proxy mode for each record. Your root domain A record and www A record should both point to your hosting server's IP address (for example, 203.xxx.xxx.xxx). You can find this IP in DirectAdmin under DNS Management or by contacting AsiaGB support.
The proxy mode toggle — Proxied vs DNS-only — is the most important setting decision:
- Proxied (orange cloud) — Traffic flows through Cloudflare, enabling CDN, DDoS protection, and Cloudflare SSL. Use this for your root domain A record and www A record.
- DNS-only (grey cloud) — Acts only as a DNS pointer to your real server IP with no proxying. Use this for all MX records and any subdomain requiring a direct connection, such as mail.yourdomain.com or ftp.yourdomain.com.
Records that should always be Proxied: the @ (root domain) A record and the www A record.
Records that must always be DNS-only: all MX records, TXT records (SPF, DKIM, domain verification), and service subdomains like mail, ftp, and cpanel.
Tip: Never proxy subdomains used for hosting control panel access — cpanel., ftp., and mail. subdomains must stay DNS-only. Proxying them breaks the services because Cloudflare's proxy only handles HTTP and HTTPS traffic, not other protocols.
Fixing SSL Errors When Using Cloudflare
The most common SSL problem after switching to Cloudflare is ERR_TOO_MANY_REDIRECTS — an infinite redirect loop caused by setting the wrong SSL mode. Cloudflare offers four SSL mode options:
- Off — No SSL at all, pure HTTP. Avoid entirely.
- Flexible — HTTPS between the visitor and Cloudflare, but plain HTTP between Cloudflare and your server. Use only if your hosting has absolutely no SSL certificate installed. If your hosting already forces HTTPS, using Flexible creates an infinite redirect loop immediately.
- Full — HTTPS end-to-end, but accepts self-signed certificates on the hosting side. Use if your hosting has a self-signed certificate rather than one from a trusted CA.
- Full (Strict) — HTTPS end-to-end with a valid certificate required from a trusted CA such as Let's Encrypt. This is the recommended mode for AsiaGB hosting, which provides Let's Encrypt certificates on all plans.
To fix a redirect loop: go to Cloudflare Dashboard → SSL/TLS → Overview, then change the mode from Flexible to Full or Full (Strict). The loop will stop immediately. If Full (Strict) still shows an SSL error, the certificate on your hosting may have expired or not yet been issued — contact AsiaGB Support to install or renew Let's Encrypt first.
Cloudflare Page Rules for WordPress Sites
Page Rules let you define specific Cloudflare behaviour for individual URL patterns. For a WordPress site running on DirectAdmin, three rules are particularly useful:
1. Cache Everything for Static Pages
Set a rule with URL pattern yourdomain.com/* → Cache Level: Cache Everything. This tells Cloudflare to cache entire WordPress pages at the edge, dramatically improving load speed. Be careful — pages with dynamic or personalised content such as shopping carts or logged-in views may serve stale data if cached this way.
2. Bypass Cache for Admin and Login Pages
Set rules for yourdomain.com/wp-admin/* and yourdomain.com/wp-login.php with Cache Level: Bypass. This prevents Cloudflare from caching your WordPress admin area. If login or admin pages get cached, you may be unable to log in or may see outdated admin content.
3. Redirect HTTP to HTTPS at the Edge
Set a rule for http://yourdomain.com/* → Forwarding URL (301) → https://yourdomain.com/$1. This approach is more efficient than using .htaccess redirects because the redirect happens at Cloudflare's edge before the request ever reaches your server, reducing server load.
Note: Cloudflare's Free plan includes a maximum of three Page Rules. Prioritise the rules that matter most for your site. If you need more rules, you will need to upgrade to the Pro plan.
Need Hosting That Works with Cloudflare?
AsiaGB Hosting works seamlessly with Cloudflare — DirectAdmin, SSL certificate, and full .htaccess support on every plan.
View Hosting Plans