How to Protect cPanel Hosting with Cloudflare

This article provides a safe Cloudflare baseline for websites hosted on cPanel.

Overview

For cPanel hosting, Cloudflare should normally proxy the public website records while mail and control-panel services remain DNS Only unless a specific compatible configuration is used.

  1. Proxy the root domain and www record if they serve the website.
  2. Keep MX records and mail-related hostnames such as mail, smtp, imap, and pop as DNS Only.
  3. Do not proxy cPanel, WHM, FTP, or webmail hostnames unless you understand port and protocol limitations.
  4. Enable AutoSSL or install SSL for the domain in cPanel.
  5. Set Cloudflare SSL/TLS to Full (strict).
  6. Protect WordPress login or application admin paths with Cloudflare WAF rules.
  7. Ask support before attempting origin firewall restrictions on shared hosting.

Common Mistakes to Avoid

  • Proxying mail records and causing email delivery or client connection issues.
  • Using Flexible SSL while AutoSSL is available.
  • Pointing old subdomains to the server IP and forgetting to protect them.
  • Blocking Cloudflare IPs accidentally through security plugins or .htaccess rules.
Share this:
FacebookXWhatsAppTelegramLinkedInGmailCopy Link
Updated on June 24, 2026
Was this article helpful?

Related Articles

Need Support?
Can't find the answer you're looking for?
Contact Support