Cloudflare can sit between visitors and your Traxio site as a CDN and security layer. It’s the only CDN Traxio supports. It works well once DNS, SSL and email are set up correctly.
What changes
Cloudflare becomes your domain’s DNS provider. Your nameservers point to Cloudflare, so DNS records are managed at Cloudflare, and Account Manager then DNS Management in DirectAdmin no longer affects the live domain.
1. Note your current records
Before switching, list the records from Account Manager then DNS Management: A records, mail, MX, SPF, DKIM (x._domainkey) and DMARC. Cloudflare’s import usually finds most of them, but check each one.
2. Set the proxy status correctly
| Record | Proxy |
|---|---|
@ and www A/CNAME | Proxied (orange cloud) |
mail A record | DNS only (grey cloud) |
| MX, TXT | Not proxyable |
| Anything used for FTP, SFTP or DirectAdmin on port 2222 | DNS only |
Cloudflare’s proxy only carries web traffic. Proxying mail breaks email apps.
3. Choose the SSL mode
Set SSL/TLS encryption mode to Full (strict). It requires a valid certificate on your Traxio site.
- Flexible connects to your site over plain HTTP and, combined with an HTTPS redirect on your site, causes an endless redirect loop. “Too many redirects” and HTTPS redirect loops
4. SSL certificate renewal
Your site’s own certificate must stay valid for Full (strict) to work. Free certificate renewal needs to reach your site over the web; with Cloudflare proxying, most renewals still succeed. If your certificate expires, temporarily set the @ and www records to DNS only, let it renew, then re-enable the proxy. SSL certificate not issued or not renewing
5. Caching
Cloudflare caches static files by default. If you change CSS or images and don’t see the update, purge Cloudflare’s cache. For WordPress admin pages, make sure no rule caches /wp-admin/ or logged-in pages.