Four layers, four different faults
A Cloudflare dashboard holds four things that can each break a website in a similar-looking way. The DNS record says where a name points. The proxy status says whether visitors reach your host directly or through Cloudflare. The encryption mode says how Cloudflare talks to your host. The cache says what Cloudflare may remember and reuse. A missing page, a redirect loop, a stale copy and a certificate warning can each come from a different layer, and changing the wrong layer wastes time or makes it worse.
- Wrong or missing record: the name does not reach your host at all.
- Wrong encryption mode: a redirect loop or an unencrypted leg to the host.
- Wrong cache rule: old or shared pages.
Proxied or DNS-only
Cloudflare's documentation says proxy status decides whether web traffic passes through its network or goes straight to your host. Only A, AAAA and CNAME records can be proxied. A proxied record returns Cloudflare's own addresses instead of the host's address, with a fixed lifetime of 300 seconds that cannot be edited. A DNS-only record returns the real host address, which exposes it to anyone who looks it up. Whether a record is proxied is therefore the first thing to check when a name behaves as if it were on a different server.
Mail and verification records stay DNS-only
Cloudflare says MX and TXT records are always DNS-only, and that DNS-only is recommended for records that do not serve web traffic, including email routing and third-party domain verification. The practical rule is that a hostname used for mail must not be proxied, even when its website counterpart is. A mail-server name that has been switched to proxied can look like a DNS fault when it is a setting.
Flattening, verification and empty answers
Cloudflare documents CNAME flattening, which lets an alias-style record work at the bare domain by answering with the address of the target. It warns that turning flattening on for every record can break third-party domain verification, that a CNAME pointing to a different Cloudflare account is prohibited, and that an empty answer appears if the final target has no address records, which can look like a propagation delay. Check each of these before assuming DNS is simply slow.
Which paid outcome fits which layer
Each is a published test price, not yet tested with buyers, payable after sign-off, with your account and logins staying in your name: the bare domain and www repair at £125, the redirect-loop fix at £125 and the caching fix at £195. For moving DNS to Cloudflare in the first place, the DNS move job already exists. Send the symptom, the address and what changed; never an API token or password. We ask for read access or screenshots and make changes only through you or a scoped invitation you can withdraw.
Sources and limits
- Cloudflare: Proxy status Checked 2026-10-11.
- Only A, AAAA and CNAME records can be proxied; MX and TXT records are always DNS-only.
- Proxied records return Cloudflare addresses rather than the origin address, and DNS-only is recommended for records that do not serve web traffic, such as email routing.
- Cloudflare: CNAME flattening Checked 2026-10-11.
- Flattening can let a CNAME-style record sit at the zone apex, can break third-party domain verification if enabled for all records, and gives an empty answer if the target has no address records.
- Cloudflare: SSL/TLS encryption modes Checked 2026-10-11.
- Flexible connects to the origin unencrypted; Full does not validate the origin certificate and Full (strict) does.
- Cloudflare: Default cache behavior Checked 2026-10-11.
- Cloudflare does not cache HTML or JSON by default.