Area of work

Cloudflare: DNS, CDN and protection

Cloudflare does a great deal, and on its defaults it sometimes does damage: the difference is in how it is configured.

When you need it

  • The site is slow for anyone opening it from far away, or falls over when real traffic arrives.
  • Bots and login attempts fill the logs, and the server spends its day serving them.
  • DNS lives in an awkward panel, and every change means phoning the provider.

What's included

  • Moving DNS to Cloudflare without interruption, record by record.
  • Cache and speed rules tuned to this site rather than to a generic preset.
  • WAF, rate limiting and DDoS protection, with exceptions for whoever must get through.
  • Access to internal systems over Zero Trust, without opening ports to the internet.

How I work

  1. 1Copy the current DNS zone and compare it record by record before touching the nameservers.
  2. 2Turn it on in stages: DNS first, then cache, then the security rules.
  3. 3Check site, mail and integrations after each step, with a rollback ready.

Frequently asked questions

Yes, with a distinction that confuses people. Cloudflare Registrar does not accept .it, so the domain stays registered where it is. What moves to Cloudflare is DNS management, and with it the cache, HTTPS, WAF and protection. They are two separate things: you change nameservers, not registrar.

For most company sites, yes: DNS, HTTPS, cache and basic protection are included. A paid plan earns its place when you need specific WAF rules, retained logs or image optimisation, and that is decided from the traffic numbers rather than on principle.

It is the most common mistake in the move: nameservers get switched and the MX records are forgotten, or the proxy is turned on for a mail record that has to stay direct. That is why the zone is copied and compared first, and the mail is tested immediately after the change.

Outcome

  • Faster pages, and traffic spikes absorbed instead of felt.
  • Automated traffic filtered before it reaches the server.
  • DNS in a panel where a change takes a minute.

Tools

Cloudflare DNS WAF CDN & Cache Zero Trust Rules & Workers

How is your own domain doing?

Expiry, registrant, SPF, DMARC: ten seconds, free, without leaving an address.

Check your domain

Want to know if this is the right area for your situation?

Let's talk