Cloudflare is the world's most popular CDN and security service. Even the free plan offers CDN, DDoS protection, free SSL, and DNS management. This guide walks you through setting it up on your hosting step by step.
Benefits of Cloudflare
- CDN: Caches static files (images, CSS, JS) across 300+ global PoPs — making pages load faster worldwide.
- DDoS Protection: Automatically blocks Layer 3/4 DDoS attacks (free).
- Free SSL: Cloudflare issues free Edge Certificates on the free plan.
- DNS Management: Faster propagation and an easy-to-use interface.
- Analytics: Real-time traffic, bot, and threat data.
Step 1: Sign Up and Add Your Domain
- Go to
https://dash.cloudflare.comand create a free account. - Click Add a Site and enter your domain.
- Select the Free plan.
- Cloudflare automatically scans existing DNS records — verify they are complete.
Step 2: Review DNS Records
Cloudflare imports DNS records automatically. Verify these critical records exist:
- A Record pointing to your hosting server's IP address.
- CNAME www pointing to @.
- MX Records for email (if using AsiaGB email hosting, verify these are correct).
If you use a separate email host, disable the orange cloud (proxy) on MX records and mail.domain.com.
Step 3: Change Nameservers at Your Registrar
Cloudflare provides 2 nameservers like ada.ns.cloudflare.com and zod.ns.cloudflare.com.
- Log in to your domain registrar (e.g., billing.in.th for AsiaGB customers).
- Go to Manage Domain → Nameservers.
- Replace existing nameservers with the two Cloudflare ones.
- Wait 1–48 hours for propagation (usually 10–30 minutes).
Step 4: Configure SSL/TLS Mode
Go to SSL/TLS in Cloudflare Dashboard and choose the appropriate mode:
- Flexible: Browser → Cloudflare uses HTTPS, but Cloudflare → Origin uses HTTP (not recommended).
- Full: Encrypts everything but doesn't verify the Origin certificate.
- Full (Strict): Recommended — requires a valid SSL certificate at the Origin server.
Setting Up Cloudflare on Hosting (DNS + Nameserver): The Full Checklist
If you want a condensed checklist you can follow from start to finish, here is the complete flow. Doing these steps in order — without skipping — is the single best way to avoid the temporary outages that catch people out during a DNS migration:
- Add your site to Cloudflare (Add a Site): Create a free account at
dash.cloudflare.com, enter your root domain (the bare domain — no www, no https), then select the Free plan. - Copy and verify your DNS records: Cloudflare auto-scans your existing records. Compare them against your current DNS zone in AsiaGB's DirectAdmin and make sure everything is present — especially the A record pointing to your hosting IP, the CNAME for www, your MX records, and TXT records (SPF/DKIM) for email. If anything is missing, add it manually before you change nameservers.
- Change nameservers at your registrar: Take the two nameservers Cloudflare assigns and replace your old nameservers at your registrar (AsiaGB customers manage this at billing.in.th). Remove the old ones entirely and use only the Cloudflare pair.
- Wait for DNS propagation: This usually takes 10–30 minutes but can take up to 24–48 hours. Once Cloudflare detects the nameserver change, it sends a confirmation email and your domain status becomes Active.
- Set SSL mode to Full or Full (Strict): After the domain is Active, go to SSL/TLS and pick the correct mode (do not leave it on Flexible) so the connection is encrypted end to end and you avoid redirect loops.
Once these five steps are complete, your site instantly routes through Cloudflare's network — gaining CDN, DDoS protection, and free SSL — without changing anything on the hosting itself.
Cloudflare SSL Modes (Flexible / Full / Full Strict): Which to Choose
The SSL mode is the setting that most often breaks sites after enabling Cloudflare, because each mode determines whether the connection between Cloudflare and your origin server (your hosting) is encrypted. The table below makes the choice clear:
| SSL Mode | Browser ↔ Cloudflare | Cloudflare ↔ Origin | Best for |
|---|---|---|---|
| Off | HTTP | HTTP | Not recommended — no encryption at all. |
| Flexible | HTTPS | HTTP | Origins without SSL — high redirect-loop risk, not recommended. |
| Full | HTTPS | HTTPS (no verify) | Any SSL on origin (incl. self-signed) — works in most cases. |
| Full (Strict) | HTTPS | HTTPS (verifies cert) | Recommended — origin has a valid SSL (Let's Encrypt / paid). |
With AsiaGB Hosting on DirectAdmin, you can already issue a free Let's Encrypt SSL right from the control panel. Once your origin has a valid certificate, choose Full (Strict) for maximum security. If you haven't installed an origin SSL yet, use Full for now and upgrade to Strict later.
Why you should avoid Flexible: The browser sees HTTPS, but Cloudflare actually talks to your origin over plain HTTP. If your hosting forces an HTTP → HTTPS redirect (which DirectAdmin commonly does), you get an endless redirect loop (ERR_TOO_MANY_REDIRECTS) immediately.
Free Cloudflare Features Worth Enabling
After the basic setup, Cloudflare offers several free features that make your site faster and more resilient at no extra cost. We recommend enabling these:
- Caching (Standard): Under Caching → Configuration, set Caching Level to Standard so Cloudflare caches static files (images, CSS, JS) at the edge — reducing hosting load and speeding up international visitors.
- Auto Minify / Speed: Compresses and trims HTML/CSS/JS. For WordPress sites, enable it alongside a cache plugin, but always test pages afterward to make sure no scripts break.
- Always Online: Cloudflare keeps a cached copy of your pages, so if your origin server goes down temporarily, visitors still see a cached version — preserving the experience during an outage.
- Brotli Compression: Enable it under Speed → Optimization. It compresses better than gzip, reducing bandwidth and load time.
- Always Use HTTPS: Forces every HTTP request to HTTPS at the edge. Once this is on, you should remove any duplicate HTTPS redirect in your .htaccess to avoid a redirect loop.
- Automatic HTTPS Rewrites: Automatically rewrites internal http:// links to https://, reducing mixed-content warnings.
Things to Watch Out For With Cloudflare
Cloudflare is hugely useful, but a few settings can take your site or email offline if misconfigured. Pay special attention to these:
- Wrong SSL mode = redirect loop: If you set Flexible while your origin forces HTTPS, you'll hit ERR_TOO_MANY_REDIRECTS. Fix it by switching to Full / Full (Strict) and checking that your .htaccess doesn't duplicate Cloudflare's force-HTTPS.
- Losing the real visitor IP: When proxy (orange cloud) is on, every request appears to come from Cloudflare's IP, so your server logs only see Cloudflare instead of the real visitor. Configure your server to read the
CF-Connecting-IPheader to restore real IPs — otherwise rate-limiting and IP bans will misbehave. - Email records must bypass proxy: All mail-related records —
MX, themail.domain.comA record, and any mail subdomains — must be set to DNS only (grey cloud). Never proxy them, because Cloudflare does not proxy email protocols (SMTP/IMAP/POP3), which would break sending and receiving mail. - Development Mode / cache: While redesigning your site, enable Development Mode (3 hours) or Purge Cache; otherwise you'll see a stale version cached by Cloudflare.
- Conflicting Page Rules: If you set multiple Page Rules or Redirect Rules, make sure they don't overlap or point at each other, which can also create a redirect loop.
Important: If you get a redirect loop after switching to Cloudflare, check the SSL mode and ensure your .htaccess doesn't have duplicate force-HTTPS redirects.
Frequently Asked Questions (FAQ)
If I use free Cloudflare, do I still need SSL on my hosting?
It's recommended. To use the safest SSL mode — Full (Strict) — your origin server must have a valid certificate too. AsiaGB Hosting runs on DirectAdmin, which can issue a free Let's Encrypt SSL right from the control panel. Install it and choose Full (Strict) rather than using Flexible, which risks a redirect loop.
Will my site go down while DNS propagates after changing nameservers?
Generally no — as long as you copied all your DNS records into Cloudflare before changing nameservers. During propagation, some visitors resolve via the old DNS and some via Cloudflare, but both point to the same IP, so the site stays reachable. Problems usually arise only when a record is missing, such as a forgotten CNAME www or MX record.
Why can't I send email after enabling Cloudflare?
Almost always because proxy (orange cloud) was left on for mail records. Cloudflare does not proxy SMTP/IMAP/POP3, so your MX record and mail.domain.com must be set to DNS only (grey cloud). Once corrected, email returns to normal within a few minutes.
Does free Cloudflare really help SEO and speed?
Yes, especially for international visitors, because static files are cached at the edge close to users — cutting load time and hosting load. On top of that, HTTPS, Brotli, and Always Online all improve Core Web Vitals, which are part of Google's ranking signals.
Hosting That Works Seamlessly with Cloudflare
AsiaGB Hosting is fully compatible with Cloudflare. Just change nameservers and you're done. Plans from 500 THB/year.
View Hosting Plans