Guide

Moving your DNS to Cloudflare, in the order that cannot hurt you

The move is genuinely worth making and genuinely unforgiving of carelessness, because DNS carries your email as well as your website. Done in the right order it is uneventful. Here is that order.

Moving DNS to Cloudflare means changing your domain's nameservers so Cloudflare answers DNS queries instead of your current provider. Your registrar stays your registrar and your host stays your host; what changes is who holds the address book. In return you get every record on one screen, fast reliable resolution, a free certificate, caching, and protection in front of your site.

The move is safe when one rule is respected: the new zone must match the old one, record for record, before the nameservers change. Cloudflare imports the zone automatically and imports it well, but not perfectly, and anything it missed simply stops existing the moment the switch happens. The order below exists to make that impossible to discover the hard way. If you would rather have it done for you, that is Cloudflare DNS management.

The safe order

  1. Confirm you control the registrar login

    The nameserver change happens at the registrar, so this login is the one you cannot proceed without. Surprisingly often it belongs to a web person from years ago, and recovering it is the real first step.

  2. Record the zone as it stands

    Every record, exported or screenshotted, before anything is touched. This is both your comparison sheet and your way back. Nothing changes until this exists.

  3. Add the domain to Cloudflare and let it import

    Cloudflare scans the existing zone and builds its copy. Treat the result as a draft. The scan cannot see records it was never told about, and hidden records exist in most zones of any age.

  4. Reconcile line by line, mail records first

    Compare the import against your export: MX, then SPF, DKIM and DMARC, then everything else. Verification records, subdomains, the odd record nobody remembers the purpose of. Missing mail records are the classic silent casualty of this move.

  5. Check the proxy status on every record

    Orange cloud for web traffic only. Anything mail depends on stays grey. The import makes a reasonable guess; it is a guess.

  6. Switch the nameservers, then verify both halves

    Make the change at the registrar, then confirm the site loads and, separately, send test mail in both directions. A loading website proves nothing about email; they fail independently.

  7. Only now, configure the extras

    Encryption mode set so both halves of the connection are actually protected, caching to suit how the site updates, redirects to one canonical hostname, protection at a level that blocks bots rather than customers. Each of these is a decision, not a default.

The traps, named

Every one of these comes from a real cleanup. None survives contact with the order above.

  • Trusting the import. It is good and it is not complete. The only defence is the line by line comparison against a zone you recorded yourself.
  • Proxying a mail record. The orange cloud on an MX target breaks delivery while everything on screen looks fine. Grey for mail, always.
  • Switching before reconciling. The moment the nameservers change, missing records stop existing. There is no grace period and no error message.
  • The encryption mode that lies. A mode that does not encrypt the connection between Cloudflare and your host gives you a padlock that overstates reality, or a redirect loop. Set it deliberately.
  • Declaring victory when the site loads. The website resolving says nothing about MX, SPF or the verification records some other service depends on. Test mail both ways.
  • Switching off the old DNS immediately. Cached answers keep some of the internet on the old servers for a while. Leave the old zone intact until traffic has fully moved.

Why bother, and why the trend is real

The case for the move is mostly the case for having your DNS somewhere deliberate. One screen with every record on it, changes that take effect promptly, an audit trail, and DNS resolution that is fast everywhere. Add the certificate, the caching and the filtering in front of your site, and the free tier covers what most small business sites actually need: the honest assessment of when it does not is on the service page.

There is also a quieter reason. DNS scattered across an old host's control panel, managed through a login nobody quite remembers, is a liability waiting for its moment. The move is a natural occasion to take inventory, get the records documented, and end up with the whole zone somewhere the business itself controls. The terms this page keeps using, records, nameservers, MX and the rest, are all defined plainly in the domain and DNS glossary.

Who this is for

  • Businesses whose DNS lives in an old host's panel that nobody trusts or remembers
  • Anyone told to "just point the nameservers at Cloudflare" and rightly suspicious of "just"
  • Owners consolidating scattered domains and records somewhere deliberate
  • Anyone who needs the certificate, caching or protection and wants the move done without drama

When this is not the right fit

  • Anyone whose current DNS setup is documented, controlled and working. The move has real benefits, but risk without a reason is not one of them.
  • Anyone hoping the move fixes a slow or hacked site by itself. It will not; those are their own jobs, and the service page is honest about which.
  • Anyone mid-way through an email migration. Sequence the two projects rather than moving the ground under a mailbox move.

What Tech True Point can help with

We have made this move enough times that the interesting part is not the switch, it is the archaeology before it: finding the records, the logins and the dependencies nobody wrote down.

Common questions

Do I have to move my domain registration to Cloudflare too?

No, and this is the most common misunderstanding in the whole exercise. Your registrar, the company you pay to own the name, stays exactly where it is. What moves is DNS: which servers answer questions about your domain. That is a nameserver setting at your registrar, and changing it does not move the registration anywhere.

Consolidating the registration into Cloudflare as well is a separate decision you can take later, calmly, once the DNS move has proven itself.

Will my website go down during the switch?

Not if the imported records match the old ones. During the changeover the old and new DNS servers are both answering, and if they give the same answers it does not matter which one a visitor hits. The site keeps resolving to the same place throughout.

Downtime enters through mismatches: a record that did not survive the import now answers differently, or not at all, on the new side. That is why the reconciliation step is the whole job and the nameserver change is the trivial part.

How long does the nameserver change take to complete?

The change itself is minutes at the registrar. The propagation, the period where some of the internet still asks the old servers, is governed by caching: resolvers keep the old answer until it expires, so both sets of servers see traffic for a while, commonly settling within a day or two.

Because both sides answer identically when the move was prepared properly, propagation is invisible to your visitors. It only becomes visible when the answers differ, which takes us back to the reconciliation step.

Should I turn the orange cloud on for everything?

No. The proxy, the orange cloud, is for web traffic: it is what puts Cloudflare's caching and protection in front of your site. Mail records must never be proxied. Proxy a hostname your MX records rely on and mail delivery breaks in ways that are genuinely hard to diagnose from the outside, because everything looks configured.

Grey cloud for anything mail touches, orange for the website, and when in doubt, grey: an unproxied record is merely ordinary DNS, which always works.

Get a Quote

Rather have it done than read about it?

Tell us your domain. We will find out where its DNS actually lives, what is in the zone, and what the move involves for your specific setup.

Call now Request a quote