Cloudflare DNS Records: Proxied vs DNS Only

This article explains when to use the orange cloud proxy and when to keep a DNS record as DNS Only.

Overview

Proxied records send web traffic through Cloudflare so Cloudflare features can apply. DNS Only records only return the target IP or hostname and do not receive Cloudflare WAF, caching, or HTTP security processing.

  1. Use Proxied for normal website records such as example.com and www.
  2. Use DNS Only for MX records and mail hostnames such as mail, smtp, imap, and pop.
  3. Use DNS Only for FTP, SSH, and most non-HTTP services unless a Cloudflare feature such as Tunnel, Access, or Spectrum is configured.
  4. Check that public web subdomains are intentionally proxied.
  5. Remove unused DNS records that expose server IPs.
  6. Avoid creating direct.example.com or origin.example.com unless it is restricted and documented.

Common Mistakes to Avoid

  • Proxying mail and breaking email clients.
  • Leaving website subdomains DNS Only by mistake.
  • Assuming DNS Only traffic is protected by Cloudflare WAF.
  • Keeping old records that reveal the origin IP.
Share this:
FacebookXWhatsAppTelegramLinkedInGmailCopy Link
Updated on June 24, 2026
Was this article helpful?

Related Articles

Need Support?
Can't find the answer you're looking for?
Contact Support