Skip to content
WP Cloud
WP Cloud
    • For Hosts
    • For Agencies
    • For Registrars
    • For Native Hosting
    • Performance
    • Security
    • Real-Time Automated Failover
    • Vertical Scaling and Bursting
    • WordPress Management
    • PanelAlpha Integration: White-Label WordPress Control Panel for Hosts
    • EasyEngine Panel Integration: Visual WordPress Management for WP Cloud
    • FAQs
    • WP Cloud API
    • Partner Portal
    • Documentation
    • New Partner Guide
    • Pressable
    • Convesio
    • Porkbun
    • PanelAlpha
    • Ivapix
    • UNC Greensboro
    • Impressive Hosting
    • Blog
    • Performance Benchmarks
  • Connect With Us
  • Login ↗
Start Here ↗
  • Solutions

    • For Hosts
    • For Agencies
    • For Registrars
    • For Native Hosting
    • Featured Partners

    Features

    • Performance
    • Security
    • Real-Time Automated Failover
    • Vertical Scaling and Bursting
    • WordPress Management

    Integrations

    • PanelAlpha Integration
    • Easy Engine Panel Integration

    Resources

    • FAQs
    • WP Cloud API
    • Partner Portal
    • Documentation
    • New Partner Guide
  • Case Studies
    • PressableA case study about how WP Cloud supports Pressable to power millions of page views daily.
    • Convesio
    • Porkbun
    • PanelAlpha
    • Ivapix
    • UNC Greensboro
    • Newspack
    • Inverse Paradox
  • Insights
    • Podcast
    • BlogWP Cloud blog page with latest news and updates about the platform.
    • Performance Benchmarks
  • Connect With Us
  • Login ↗
Start Here ↗

Browse

    • WP Cloud platform overview
    • Onboard and launch with WP Cloud
    • WP Cloud Partner Portal
    • Get support from WP Cloud
    • WP Cloud glossary
    • Manage and secure API keys
    • Client SSH
    • WP Cloud API quick start
    • Webhooks
    • Run bulk tasks across sites
      • Manage site domains and aliases
      • Domain verification records
      • TLS certificates
      • Manage custom TLS certificates
      • Cloudflare and WP Cloud
    • Clone a site
    • Configure resources, site type, and billing with site meta
    • Delete a site
    • Persistent data
    • Staging sites
    • Migrate a site to WP Cloud
      • SSH and SFTP access models
      • Client SSH
      • User SSH and SFTP access
      • Database credentials
      • phpMyAdmin
      • ABSPATH
      • Default wp-config.php
      • Site constants
      • Configure redirects and headers with custom-redirects.php
      • Akismet and Jetpack
      • Blocked and unsupported plugins
      • PHP lifecycle and supported versions
      • Symlinks and managed software
      • WordPress versions
      • Install Composer and WP-CLI packages
      • Manage platform software with WP-CLI
      • Useful WP-CLI commands
    • Transactional email
    • WordPress multisite
    • Cron scheduling
    • Decoupled and headless WordPress
    • Repair Yoast indexables
      • Page Cache
      • Edge Cache
      • Object Cache
      • Image transformation
      • Offload image sub-sizes
    • Configure lightweight 404s for static files
      • DDoS protection
      • Defensive Mode
      • Rate limiting
      • Network and web application firewalls
      • Bot protection
      • Password protection
      • HTTP and security headers
      • PHP filesystem access permissions
      • Scan a site for malware
    • Backups overview
    • Create an on-demand backup
    • Restore a backup
    • Jetpack backups
      • Error logs
      • Web server logs
    • Metrics
    • Application performance monitoring
    • Automated failover
    • IP ranges
    • Origin and edge servers
    • Server specifications and settings
    • EasyEngine integration
    • PanelAlpha integration
      • White labelling and co-marketing WP Cloud
      • WP Cloud logos
      • Terms of Service & Compliance
      • Prohibited content
      • Copyright infringement and takedown notifications
    • WP Cloud billing
    • WP Cloud for agencies and site networks
    • WP Cloud partner support options
    • Troubleshoot Page and Edge Cache
    • Troubleshoot HTTP 429 and 599 errors
    • WP Cloud HTTP status codes
    • Troubleshoot site performance
    • Cache slow database queries
    • Troubleshoot duplicate core files, wp-config.php, and wp-admin 403 errors
    • Troubleshoot email delivery
    • Troubleshoot PDF thumbnail generation
    • Troubleshoot TLS certificate provisioning
Documentation/Sites/Domains/Cloudflare and WP Cloud

Cloudflare and WP Cloud

LAST UPDATED

3 months ago

    WP Cloud sites are compatible with Cloudflare and, if properly configured, can leverage Cloudflare’s cache and traffic protections.

    However, in the majority of cases, WP Cloud host partners should advise their end users to avoid proxying WP Cloud site traffic through Cloudflare unless a required Cloudflare feature depends on the proxy.

    We’ve found that most sites leveraging Cloudflare are not properly caching and are not properly configured to mitigate bad traffic. This means a site may end up being slower, consuming more resources, and allowing unwanted traffic through.

    Like Cloudflare, WP Cloud operates an Anycast network. WP Cloud receives inbound traffic and routes requests through regional edge load balancers and services, protecting the origin server and its IP address.

    WP Cloud applies traffic classification, rate limiting, and distributed denial-of-service (DDoS) mitigation at its edge and load balancers. Edge Cache can also serve eligible responses without sending the request to the origin. An additional Cloudflare proxy is therefore unnecessary for many WP Cloud sites and can interfere with WP Cloud caching and traffic protection.

    Cloudflare can still provide DNS without proxying site traffic. Host partners can use the guidance below in their own documentation and support responses. If an end user’s site must use the Cloudflare proxy, review both the proxy and TLS settings below.

    Avoid Cloudflare proxying when possible

    Advise end users to configure the site’s A and CNAME records as DNS only in Cloudflare unless a required Cloudflare feature depends on proxied records. This is commonly called disabling the proxy or orange cloud. Visitors then connect to WP Cloud’s Anycast edge network instead of passing through an additional proxy.

    When Cloudflare proxies a request, WP Cloud receives the connection from Cloudflare instead of directly from the visitor. This can hide connection signals that WP Cloud uses to classify requests and apply traffic protection. If Cloudflare does not stop an attack, the changed request information can contribute to unexpected rate limiting or increased use of PHP and other site resources.

    Some Cloudflare features require proxied records. If an end user chooses one of those features, the host partner should treat proxying as an intentional tradeoff and test the site’s cache behavior, legitimate automated clients, and traffic protections after the change.

    Prevent HTTPS conflicts

    When a proxied site has redirect loops or other HTTPS problems, check the Cloudflare SSL/TLS settings before changing the WP Cloud certificate or domain configuration.

    • Set the Cloudflare SSL/TLS encryption mode to Full. Do not use a mode that sends unencrypted HTTP requests from Cloudflare to WP Cloud.
    • If the site enters a redirect loop, disable Always Use HTTPS under SSL/TLS > Edge Certificates and let WP Cloud handle the HTTPS redirect.
    • If Cloudflare rewrites links or resources unexpectedly, disable Automatic HTTPS Rewrites under SSL/TLS > Edge Certificates.

    Change only the setting related to the observed conflict. Cloudflare changes can affect customer traffic immediately, so confirm that the primary domain, aliases, WordPress administration, and important automated requests still load afterward.

    With DNS-only records, visitors connect directly to WP Cloud. When proxying is required, the expected result is a site that loads over HTTPS without a redirect loop or rewritten resources. Proxying still changes the connection information that reaches WP Cloud; these TLS settings do not make proxied traffic equivalent to a direct connection.

    Previous Manage custom TLS certificates
    Next Clone a site

    Related Guides

    • Manage site domains and aliases

      Manage primary and secondary WP Cloud site domains, control alias canonicalization, retrieve suggested DNS addresses,…

      4 Min.

      READ

    • Domain verification records

      Publish WP Cloud DNS TXT verification records when a domain is already assigned to a…

      2 Min.

      READ

    • TLS certificates

      Understand how WP Cloud provisions, installs, and renews TLS certificates for site domains.

      2 Min.

      READ

    On this page

      Contact support

      Contact us with Support issues and questions related to WP Cloud, the WP Cloud Atomic API, API-key IP allow list changes, Station, and more.

      Check the FAQs

      Have questions? Please visit our FAQ to learn more.

      An Automattic venture

      Work With Us

      Press

      Privacy Policy

      © 2021-2026 Automattic Inc.

      Notifications