Cloudflare Best Practices for Protecting Your Website

This article explains the baseline Cloudflare configuration Libyan Spider recommends after Cloudflare is enabled for a website.

Overview

Cloudflare can improve security, performance, availability, and filtering, but it must be configured correctly. If the origin server is still reachable directly, attackers may bypass Cloudflare and reach the hosting server without WAF, rate limits, caching, or DDoS filtering.

  1. Proxy the public website records such as the root domain and www through Cloudflare.
  2. Install a valid SSL certificate on the hosting account or server before forcing HTTPS.
  3. Set SSL/TLS mode to Full (strict) whenever possible.
  4. Review DNS records and keep mail, FTP, SSH, and other non-web services as DNS Only unless a supported Cloudflare product is configured.
  5. Protect login pages and admin paths with WAF Custom Rules, Managed Challenge, rate limiting, or Cloudflare Access.
  6. Restrict direct HTTP/HTTPS access to the origin server when firewall control is available.
  7. Use Cloudflare Tunnel for private applications or services that should not be publicly exposed.

Common Mistakes to Avoid

  • Using Flexible SSL for production websites.
  • Leaving the origin IP exposed in DNS records, historical records, or public subdomains.
  • Proxying mail records or control-panel records without checking protocol compatibility.
  • Creating very strict WAF rules without testing legitimate visitor traffic.
Share this:
FacebookXWhatsAppTelegramLinkedInGmailCopy Link
Updated on June 24, 2026
Was this article helpful?

Related Articles

Need Support?
Can't find the answer you're looking for?
Contact Support