Blog
4 min read

Cloudflare Proxied vs DNS Only: The Orange Cloud Explained

In Cloudflare's DNS settings, the orange cloud sends traffic through Cloudflare and the grey cloud doesn't. What changes with each, which records must be grey, the SSL modes that avoid redirect loops, and how proxying interacts with your host's automatic SSL.

Every DNS record in Cloudflare has a little cloud icon next to it. It's one of the most consequential switches in the dashboard:

  • ๐ŸŸ  Proxied (orange cloud): visitors connect to Cloudflare, which connects to your server.
  • โšช DNS only (grey cloud): Cloudflare just answers "this domain is at this IP," and visitors connect directly to your server.

(New to Cloudflare? What is Cloudflare?)

What changes when you proxy

Proxied ๐ŸŸ  DNS only โšช
What dig yourapp.com shows Cloudflare's IPs Your server's real IP
Caching / CDN Yes No
DDoS protection, firewall rules Yes No
Your server's IP hidden Yes (mostly) No
SSL certificate visitors see Cloudflare's Your server's
Works for any port/protocol HTTP/HTTPS (and some ports) Everything
Upload size and timeout limits Cloudflare's plan limits Your server's

Records that must be grey

Proxying only works for web traffic. These should be DNS only:

  • Mail records โ€” MX records can't be proxied, and the hostnames they point to (like mail.yourapp.com) need grey A records.
  • SSH, database, game servers โ€” anything that isn't HTTP(S) on standard ports.
  • TXT records (verification, SPF, DKIM) โ€” not proxyable anyway.
  • Hostnames your host needs to reach directly for verification, if it says so.

The SSL mode trap

When proxied, there are two connections: visitor โ†’ Cloudflare, and Cloudflare โ†’ your server. Cloudflare's SSL/TLS mode controls the second:

Mode Cloudflare โ†’ server Use it?
Off No HTTPS anywhere Never
Flexible Plain HTTP Avoid โ€” causes redirect loops and isn't secure end-to-end
Full HTTPS, any certificate OK as a stopgap
Full (strict) HTTPS, valid certificate Use this

The classic problem: your server redirects HTTP to HTTPS, Cloudflare is on Flexible and connects over HTTP, gets redirected, tries again over HTTPโ€ฆ โ†’ ERR_TOO_MANY_REDIRECTS. Fix: switch to Full (strict). (ERR_TOO_MANY_REDIRECTS)

For Full (strict), your server needs a valid certificate โ€” from your host's automatic SSL, from Let's Encrypt, or a free Cloudflare Origin certificate installed on your server.

Proxying and your host's automatic SSL

Many hosts issue Let's Encrypt certificates automatically by proving they control your domain. With the orange cloud on, that check can fail, because requests hit Cloudflare first. Common approach:

  1. Add the domain in your host with the record grey.
  2. Wait until the host shows the certificate as active.
  3. Turn the cloud orange and set SSL to Full (strict).

Renewals usually keep working (HTTP-based checks pass through Cloudflare), but if your host's docs say otherwise, follow them. (How automatic SSL works)

Other side effects of proxying

  • Visitor IPs. Your server sees Cloudflare's IP. Read the real one from the CF-Connecting-IP header (or configure your proxy to trust Cloudflare's ranges) โ€” otherwise logs and rate limiting treat every visitor as the same few IPs.
  • Caching after deploys. Static files may be cached at Cloudflare; purge the cache or use hashed file names.
  • Long requests can time out at Cloudflare's limit (around 100 seconds on standard plans) even if your server would have answered.
  • Large uploads are capped by plan.
  • The IP isn't truly secret if it leaked before (old DNS records, email headers). Firewall your server to accept web traffic only from Cloudflare's IP ranges if hiding it matters.

When to use which

  • Starting out, or debugging: grey. Fewer moving parts.
  • Under attack, high traffic, or want caching and firewall rules: orange, with Full (strict).
  • Mail, SSH, databases: always grey.

The summary

  • Orange = traffic through Cloudflare (CDN, protection, hidden IP). Grey = DNS only.
  • Mail and non-web services must be grey.
  • With orange, always use SSL mode Full (strict).
  • Let your host issue its certificate before turning the cloud orange.

EasySpawn issues SSL certificates for your custom domains automatically and works with Cloudflare in either mode. See how it works or join the waitlist.

Related: What Is Cloudflare? ยท ERR_TOO_MANY_REDIRECTS ยท DNS Records Explained ยท How to Connect a Custom Domain

Keep reading