How to use Cloudflare with my Webway hosting

Cloudflare sits between visitors and your Webway server, caching pages and filtering bad traffic. It's optional. It works well once set up, but three settings cause almost every problem: proxying the mail record, the wrong SSL mode, and switching before the free SSL certificate exists.

Once you use Cloudflare, your DNS lives at Cloudflare. The zone editor in cPanel or DirectAdmin no longer has any effect, and subdomains you create in the control panel need a record added at Cloudflare by hand.

Before you start

  1. Make sure the site already works on Webway at https://yourdomain with a valid padlock. The free certificate issues automatically once DNS points to the server; wait for it before adding Cloudflare.
  2. Write down your server's IP address. cPanel shows it as Shared IP Address in the General Information panel on the home page. On DirectAdmin, ask support if you can't see it.
  3. Note every subdomain and DNS record you rely on, especially MX, SPF, DKIM and any verification TXT records.

Step 1: Add the site to Cloudflare

  1. Sign up at cloudflare.com and add your domain. The Free plan is enough.
  2. Cloudflare scans your existing records and imports them. Check the list against your zone. Add anything missing: MX, TXT records, subdomains.
  3. Don't change nameservers yet.

Step 2: Proxied or DNS only

Each A and CNAME record has a cloud icon. Orange (proxied) sends traffic through Cloudflare. Grey (DNS only) points straight at your server.

Record Setting Why
@ (the domain) and www Orange, proxied This is what Cloudflare is for
mail Grey, DNS only Cloudflare only proxies web traffic. A proxied mail record breaks every email program
ftp Grey, DNS only Same reason
Anything you use with :2083 or :2222 Grey, DNS only Control panel ports aren't passed through Cloudflare
MX record target Must point to a grey name (mail.yourdomain) Mail delivery must reach the server directly
Other website subdomains Orange if you want them cached and protected, grey if not Your choice

Step 3: SSL mode

In Cloudflare, go to SSL/TLS → Overview.

  • Choose Full (strict). Cloudflare connects to your server over HTTPS and checks the certificate. Your Webway certificate is a valid Let's Encrypt certificate, so this works.
  • Never choose Flexible. It connects to your server over plain HTTP. Combined with a force-HTTPS rule on the server, it causes the endless redirect loop ERR_TOO_MANY_REDIRECTS.
  • If you see a 526 error after switching, the server's certificate wasn't valid at that moment. Switch to Full temporarily, or wait for the certificate to issue, then return to Full (strict).

Step 4: Change the nameservers

  1. Cloudflare shows two nameservers, for example anna.ns.cloudflare.com and bob.ns.cloudflare.com.
  2. At your domain's registrar, or in your Webway client area under Domains → My Domains → the domain → Nameservers if it's registered with us, replace dns1.webway.host and dns2.webway.host with the two Cloudflare names.
  3. Wait. Cloudflare emails you when it becomes active, usually within an hour, sometimes up to 24. See How long does DNS propagation take?

Step 5: Check everything

  1. Open https://yourdomain in a private window. Padlock, no warning, no redirect loop.
  2. Send and receive a test email on a device using mail.yourdomain.
  3. Log in to your control panel. See How to log in to cPanel or DirectAdmin.
  4. Test any subdomains and your contact form.

Keeping SSL renewing

The server renews your free certificate automatically by proving it controls the domain over HTTP. With Cloudflare proxying, this still works as long as:

  • SSL mode is Full or Full (strict), not Flexible.
  • You haven't added a Cloudflare rule that blocks or redirects /.well-known/acme-challenge/.

Visitors see Cloudflare's certificate in the padlock; that's normal. Cloudflare sees your server's.

Setting Value
SSL/TLS mode Full (strict)
Always Use HTTPS On
Automatic HTTPS Rewrites On (helps with mixed content)
Rocket Loader Off unless tested. It breaks some WordPress themes and forms
Development Mode Turn on while making site changes so you see them immediately; it switches off after 3 hours

After changing files or a WordPress theme, if visitors still see the old version, use Caching → Purge Everything.

Common problems

Problem Cause Fix
ERR_TOO_MANY_REDIRECTS SSL mode Flexible with HTTPS forced on the server Set SSL mode to Full (strict)
Error 526 "Invalid SSL certificate" Server certificate missing or expired Wait for issuance, or use Full temporarily
Error 521 or 522 Cloudflare can't reach the server Check the A record IP is right. If the server is down, see status.webway.host
Email stopped working mail record proxied (orange) Set it to DNS only (grey)
Can't reach the control panel or FTP Record proxied Set it to DNS only
New subdomain shows a Cloudflare error No record at Cloudflare Add an A record for it in Cloudflare's DNS
Contact forms or plugins see every visitor as the same IP The IP is Cloudflare's Install Cloudflare's WordPress plugin, or open a support ticket
DNS changes in cPanel or DirectAdmin do nothing DNS is at Cloudflare now Edit records at Cloudflare

To take Cloudflare out again, set the nameservers back to dns1.webway.host and dns2.webway.host and recreate any records you added at Cloudflare in the control panel's zone editor.

Still stuck?

Open a support ticket and include:

  • Your domain.
  • The Cloudflare error number, if any (521, 522, 526), or the exact browser message.
  • Your Cloudflare SSL/TLS mode.
  • A screenshot of your Cloudflare DNS records showing the cloud icons.
  • Whether the site loads when Cloudflare is paused.

Did this answer it?