How to use Cloudflare with my Webway hosting
Cloudflare sits between visitors and your Webway server, caching pages and filtering bad traffic. It's optional. It works well once set up, but three settings cause almost every problem: proxying the mail record, the wrong SSL mode, and switching before the free SSL certificate exists.
Once you use Cloudflare, your DNS lives at Cloudflare. The zone editor in cPanel or DirectAdmin no longer has any effect, and subdomains you create in the control panel need a record added at Cloudflare by hand.
Before you start
- Make sure the site already works on Webway at
https://yourdomainwith a valid padlock. The free certificate issues automatically once DNS points to the server; wait for it before adding Cloudflare. - Write down your server's IP address. cPanel shows it as Shared IP Address in the General Information panel on the home page. On DirectAdmin, ask support if you can't see it.
- Note every subdomain and DNS record you rely on, especially MX, SPF, DKIM and any verification TXT records.
Step 1: Add the site to Cloudflare
- Sign up at cloudflare.com and add your domain. The Free plan is enough.
- Cloudflare scans your existing records and imports them. Check the list against your zone. Add anything missing: MX, TXT records, subdomains.
- Don't change nameservers yet.
Step 2: Proxied or DNS only
Each A and CNAME record has a cloud icon. Orange (proxied) sends traffic through Cloudflare. Grey (DNS only) points straight at your server.
| Record | Setting | Why |
|---|---|---|
@ (the domain) and www |
Orange, proxied | This is what Cloudflare is for |
mail |
Grey, DNS only | Cloudflare only proxies web traffic. A proxied mail record breaks every email program |
ftp |
Grey, DNS only | Same reason |
Anything you use with :2083 or :2222 |
Grey, DNS only | Control panel ports aren't passed through Cloudflare |
| MX record target | Must point to a grey name (mail.yourdomain) |
Mail delivery must reach the server directly |
| Other website subdomains | Orange if you want them cached and protected, grey if not | Your choice |
Step 3: SSL mode
In Cloudflare, go to SSL/TLS → Overview.
- Choose Full (strict). Cloudflare connects to your server over HTTPS and checks the certificate. Your Webway certificate is a valid Let's Encrypt certificate, so this works.
- Never choose Flexible. It connects to your server over plain HTTP. Combined with a force-HTTPS rule on the server, it causes the endless redirect loop
ERR_TOO_MANY_REDIRECTS. - If you see a 526 error after switching, the server's certificate wasn't valid at that moment. Switch to Full temporarily, or wait for the certificate to issue, then return to Full (strict).
Step 4: Change the nameservers
- Cloudflare shows two nameservers, for example
anna.ns.cloudflare.comandbob.ns.cloudflare.com. - At your domain's registrar, or in your Webway client area under Domains → My Domains → the domain → Nameservers if it's registered with us, replace
dns1.webway.hostanddns2.webway.hostwith the two Cloudflare names. - Wait. Cloudflare emails you when it becomes active, usually within an hour, sometimes up to 24. See How long does DNS propagation take?
Step 5: Check everything
- Open
https://yourdomainin a private window. Padlock, no warning, no redirect loop. - Send and receive a test email on a device using
mail.yourdomain. - Log in to your control panel. See How to log in to cPanel or DirectAdmin.
- Test any subdomains and your contact form.
Keeping SSL renewing
The server renews your free certificate automatically by proving it controls the domain over HTTP. With Cloudflare proxying, this still works as long as:
- SSL mode is Full or Full (strict), not Flexible.
- You haven't added a Cloudflare rule that blocks or redirects
/.well-known/acme-challenge/.
Visitors see Cloudflare's certificate in the padlock; that's normal. Cloudflare sees your server's.
Recommended Cloudflare settings for a Webway site
| Setting | Value |
|---|---|
| SSL/TLS mode | Full (strict) |
| Always Use HTTPS | On |
| Automatic HTTPS Rewrites | On (helps with mixed content) |
| Rocket Loader | Off unless tested. It breaks some WordPress themes and forms |
| Development Mode | Turn on while making site changes so you see them immediately; it switches off after 3 hours |
After changing files or a WordPress theme, if visitors still see the old version, use Caching → Purge Everything.
Common problems
| Problem | Cause | Fix |
|---|---|---|
ERR_TOO_MANY_REDIRECTS |
SSL mode Flexible with HTTPS forced on the server | Set SSL mode to Full (strict) |
| Error 526 "Invalid SSL certificate" | Server certificate missing or expired | Wait for issuance, or use Full temporarily |
| Error 521 or 522 | Cloudflare can't reach the server | Check the A record IP is right. If the server is down, see status.webway.host |
| Email stopped working | mail record proxied (orange) |
Set it to DNS only (grey) |
| Can't reach the control panel or FTP | Record proxied | Set it to DNS only |
| New subdomain shows a Cloudflare error | No record at Cloudflare | Add an A record for it in Cloudflare's DNS |
| Contact forms or plugins see every visitor as the same IP | The IP is Cloudflare's | Install Cloudflare's WordPress plugin, or open a support ticket |
| DNS changes in cPanel or DirectAdmin do nothing | DNS is at Cloudflare now | Edit records at Cloudflare |
To take Cloudflare out again, set the nameservers back to dns1.webway.host and dns2.webway.host and recreate any records you added at Cloudflare in the control panel's zone editor.
Still stuck?
Open a support ticket and include:
- Your domain.
- The Cloudflare error number, if any (521, 522, 526), or the exact browser message.
- Your Cloudflare SSL/TLS mode.
- A screenshot of your Cloudflare DNS records showing the cloud icons.
- Whether the site loads when Cloudflare is paused.
Did this answer it?