Here's the map for today — then we're 100% live in the dashboard
One network instead of five vendors. Nothing reaches your infrastructure until it's actually safe to.
We just looked at where that network actually lives, physically, all over the world. Now let's get specific about what happens at each of those points — DNS, encryption, caching, and security, one at a time.
DNS Onboarding
Two ways onto Cloudflare
The difference is whether Cloudflare becomes your authoritative DNS provider — the system that holds the real, final answer for every query about your domain — or just proxies specific hostnames while someone else stays authoritative.
Most common
Full (Primary) Setup
Cloudflare becomes your authoritative DNS provider
Change nameservers at your registrar — one-time step
Manage all DNS records in Cloudflare going forward
DNS-layer DDoS protection included (Cloudflare sees all query traffic)
Available on every plan, including Free
Business/Enterprise only
CNAME (Partial) Setup
Keep your existing authoritative DNS provider
No nameserver change — add CNAME records instead
Only the specific hostnames you point get proxied
No DNS-layer DDoS protection — Cloudflare isn't authoritative
Apex domain needs CNAME flattening support from your provider
💡 Most customers go Full Setup: full protection, one place to manage DNS, zero ongoing coordination with a second provider.
FullEncrypted end-to-end, origin cert not validated
Full (strict)Encrypted end-to-end, origin cert cryptographically validated
💡 "Encrypted" alone isn't a compliance answer. Full (strict) is the difference between encrypted and actually verified end-to-end — the posture auditors and regulated data actually require.
Every request gets scored 1-99. The action taken depends on where it lands — not a binary allow/block.
1Block Definite bot
2-29Challenge Likely bot — not blocked outright
30-99Allow Likely human
💡 The gray zone gets challenged, not blocked — so you're not losing real customers to false positives while still shutting the door on automated abuse.
Cloudflare NetworkAbsorbed & filtered at the edge, globally distributed
✅
Your OriginNever sees the attack traffic at all
🎛️ Under Attack Mode — a manual dial for the application layer during an active incident: adds an extra interstitial check for every visitor. Not the first line of defense — the always-on network layer is.
💡 Uptime matters most during the exact moment it's hardest to guarantee — an active attack, not a normal Tuesday. That's precisely when this stays passive and automatic.