How to Protect Plesk Hosting with Cloudflare

This article explains the recommended Cloudflare setup for websites hosted on Plesk.

Overview

Plesk can manage SSL certificates and hosting settings, while Cloudflare provides proxy, WAF, caching, and edge security. Both sides must be aligned.

  1. Install or renew the SSL certificate for the domain in Plesk.
  2. Confirm the website loads over HTTPS from the hosting side.
  3. Proxy only website records such as root and www.
  4. Keep mail and service records DNS Only unless a supported Cloudflare feature is being used.
  5. Set Cloudflare SSL/TLS to Full (strict).
  6. Use Plesk firewall or server firewall restrictions only if you manage the server and understand the impact.
  7. Use Cloudflare WAF rules for login paths and common CMS admin areas.

Common Mistakes to Avoid

  • Changing Cloudflare SSL mode before the Plesk certificate is valid.
  • Proxying mail services.
  • Blocking direct access without allowing Cloudflare IP ranges.
  • Forgetting that some Plesk services use non-standard ports that may not be proxied normally.
Share this:
FacebookXWhatsAppTelegramLinkedInGmailCopy Link
Updated on June 24, 2026
Was this article helpful?

Related Articles

Need Support?
Can't find the answer you're looking for?
Contact Support