The Cloudflare dashboard holds dozens of switches, all with names promising speed or safety. Some are worth having: switch on, forget about. Others break sites in ways that take days to find, because the site does not throw an error, it just quietly misbehaves.
|
None of this is switched on in your panel with us. We do not sell a CDN. These options all live in the account you hold at Cloudflare, and what appears there depends on the plan you have with them.
|
The rule that matters more than the list
|
One at a time, and use the site properly after each one. Open the menu on a phone, submit the form, sign into the dashboard, and buy something if you sell. Switching six options on in an afternoon may go fine, but on the day it breaks you will not know which one did it, and you will switch off all six.
|
The ones worth having
| Option |
Why |
| SSL mode on Full (strict) |
Not a choice, the only right answer here. See switching on SSL without breaking the site. |
| Always use HTTPS |
Corrects the unencrypted request at the door, before it travels. Safe, as long as the mode is right. |
| Text compression |
Real gain, no risk. It does not touch your content. |
| Newer transport protocol versions |
Switch on and work. A browser that does not know them uses the previous one. |
| Browser cache lifetime |
Tells visitors to keep images longer. Almost always a good idea. |
| Static file caching |
What a CDN does best, and it comes on by default. |
The ones that need thinking twice about
| Option |
The risk |
| Page caching |
Excellent, after the exclusions are written. Before that, it shows one person page to another. See cache rules for a WordPress site. |
| Bot fighting mode |
It stops automated traffic, including the automated traffic you want: payment callbacks, monitoring tools, integrations. Switch it on and then confirm your payments still confirm. |
| Rules that block countries |
They also block your own customers while travelling, and services that write to you from abroad. The symptom is always silent. |
| Hotlink protection |
It breaks the images you yourself display elsewhere: social networks, marketplaces, newsletters. |
| Hiding e-mail addresses in the text |
A good idea against spam robots, but it breaks themes that build addresses in script. |
| Serving an old version when the server is down |
Comforting, and dangerous in a shop: it can show prices or stock that no longer exist. |
The ones that cause real trouble
| Option |
What happens |
| Flexible SSL mode |
An endless redirect loop. Never, under any circumstances, on this hosting. |
| Proxying the mail records |
E-mail stops immediately. It is mistake number one for everyone who makes this move. |
| Rewriting, combining or deferring scripts |
Menus, forms and carts break with impressive ease, and the gain is counted in tenths of a second. |
| HSTS switched on too early |
Browsers obey for however long you set, even after you switch it off. Leave it to the end, when everything is settled. |
| Attack mode left on permanently |
Every visitor passes a check before seeing the site. During an attack it is the rescue; permanently, it drives visitors away and gets in the way of search engines. See being found on Google. |
|
The payments case deserves a paragraph of its own. If your site receives callbacks from a payment method, any rule that challenges or blocks automated traffic can block them. The customer pays, the money leaves, and the order is never confirmed. There is no error on anybody screen. After switching on any protection, put a test purchase all the way through. See an online shop with local payment methods.
|
When something breaks
| 2 |
If it goes away, an option did it. Switch the CDN back on and switch off the last thing you touched.
|
|
| 3 |
If it does not go away, the problem is the site, and the CDN was only hiding or delaying the symptom.
|
|
| 4 |
Purge every cache before concluding anything: the site one, theirs, and the browser.
|
|
| 5 |
Write down what you changed and when. If you ask us for help, that list saves half the work.
|
|
What we do at our end, which holds with or without a CDN, is in what we do about security. And if what got blocked was your own access, why your IP gets blocked by the firewall.
|
Switched options on and the site went strange? Tell us which ones and in what order.
Open a support ticket
|
RECOMMENDED PRODUCT Web hosting with cPanel Domain and SSL included, daily backups and the panel you already know. from $10.00/mo See plans |