This article explains the recommended Cloudflare setup for websites hosted on Plesk.
Overview
Plesk can manage SSL certificates and hosting settings, while Cloudflare provides proxy, WAF, caching, and edge security. Both sides must be aligned.
Recommended Steps
- Install or renew the SSL certificate for the domain in Plesk.
- Confirm the website loads over HTTPS from the hosting side.
- Proxy only website records such as root and
www. - Keep mail and service records DNS Only unless a supported Cloudflare feature is being used.
- Set Cloudflare SSL/TLS to Full (strict).
- Use Plesk firewall or server firewall restrictions only if you manage the server and understand the impact.
- Use Cloudflare WAF rules for login paths and common CMS admin areas.
Common Mistakes to Avoid
- Changing Cloudflare SSL mode before the Plesk certificate is valid.
- Proxying mail services.
- Blocking direct access without allowing Cloudflare IP ranges.
- Forgetting that some Plesk services use non-standard ports that may not be proxied normally.