Questions people ask before they change a DNS record
These are the answers we would give you on the phone, including the ones that count against us. Leaving comes first, because it is the question that decides the rest.
How you leave
This group is first on purpose. It is the question that decides whether the rest of the page matters.
If I stop using OneLineShield, does my website go down?
No, as long as you put the DNS record back. Leaving is the same single record you changed to start, edited the other way.
Concretely: open the DNS panel for your domain, find the record you pointed at us, and set it back to the value it had before, which is your own server address or the hostname your hosting company gave you. Delete the second record, the one that lets the certificate renew, at the same time; on its own it does nothing. Visitors reach your server directly again once the old value has spread, and how long that takes is decided by the TTL on the record, not by us.
Write the original value down before you change anything. That one note is the difference between a two minute undo and an afternoon of guessing.
Nothing has to be cancelled first, no support conversation stands in the way, and we do not ask you three times whether you are sure.
What happens if I stop paying, or if you shut down?
Those are two different sizes of problem, and they deserve separate answers.
If you stop paying: what money buys here is the telling, not the watching. The checks keep running and the dashboard still opens, so nothing stops being measured. What stops is the email that reaches you when something changes, which means you have to be the one who goes and reads it. A website does not come off the protection because an invoice did not get paid. If a website ever does have to be taken off our side, you get told what to change and given time to change it, more than once, before anything happens to it.
If we shut down: your record points at a hostname on our Cloudflare zone, so if that zone stopped existing, the name would stop resolving and your website would be unreachable until you pointed the record back at your own server. That is a real risk, and it comes with putting anything at all in front of a website, us included. The undo is the single record edit described above, which is why we keep telling you to write the old value down.
Whether you need us at all
Two of these answers can send you away without paying us anything. They are still the right answers.
I already use Cloudflare. What then?
Then you may already have the thing we sell, and we would rather tell you that than sell it to you twice.
If your domain runs on Cloudflare nameservers and your website record is proxied through them, you are already behind the same network we would put you on. The check on our home page recognises that case, says so, and does not offer you a signup.
There is a second case that looks the same from the outside. Some domains sit on Cloudflare nameservers with the website record set to DNS only, so Cloudflare answers the lookup but never sees a single request. The firewall is already available to you for free inside your own Cloudflare account, and switching it on there is the right move. What we would add on top is the watching afterwards, not the wall.
If you have ever seen error 1014 on a website, that is a record pointing into a Cloudflare account that was not told to expect it. It is also why we register your hostname on our side first and only then show you the record to add. Doing it in the other order is how people break a working website.
How is this different from using Cloudflare for free?
The firewall is not different. It is Cloudflare, it is configured at the zone level, and every website on the zone gets the same rules. Per-hostname firewall rules are a Cloudflare enterprise feature, so nobody who puts you on a shared zone can hand you a stronger wall than the free one. We do not have a stronger wall to sell you.
What is different is the price of getting behind it. Cloudflare free asks you to move your domain nameservers to Cloudflare, which moves every DNS record you have, mail included. We take one website with one record, and the rest of your domain stays exactly where it is, managed by whoever manages it now.
The other difference is that we keep looking after the setup is finished. We run 6 checks on your website every ten minutes: whether the certificate is getting close to expiry, whether the record that renews it quietly disappeared, whether the record that points at us was deleted, whether your server answers the internet directly. Those results sit on your dashboard for you to read. The email that comes to you when one of them changes is the part we have not built yet, and we would rather tell you that here than let you find out by never receiving one.
And if the honest answer for you is that free Cloudflare is enough, then that is the answer. If you can change your nameservers and you are comfortable moving every record for the domain, do that instead. It costs nothing, and you will not need us.
I do not manage my own DNS. Can I still use this?
Usually yes, and the ask is smaller than people expect. Somebody needs to add two records to your domain: one that points the website at us, and one that lets the security certificate renew itself later. Nobody has to move nameservers, change hosting company, or log into your server.
In practice that person is whoever built the site, whoever registered the domain, or the agency that looks after both. The setup screen shows both records field by field, with a copy button on each, and names your DNS provider when we recognise it, so you know who to send them to.
The one case that does not work is a domain nobody you can reach is able to edit. If the two records cannot be added, no product can add them for you, and we would rather say that now than after you have signed up.
What happens to your website
The mechanical answers: where traffic goes, what we hold, and what changes on your side.
Does my traffic go through your servers?
No, and that is a property of how this is built rather than a promise we are making. Every website gets its own origin recorded on the Cloudflare side, and that origin is your server. A visitor request goes to Cloudflare, and Cloudflare sends it to you. There is no hop through anything of ours, and there is no shared address that everybody falls back to.
That is also why our app going down does not take your website with it. The app is where you read results; it is not where your visitors go.
There is one deliberate exception, and it is small. When a check runs, our server makes its own request to your domain and to your server address, the same request anyone on the internet can make. That is us looking at your website from the outside, which is the only way to tell you what the outside can see.
What do you store about me and my website?
Your email address, because that is how you sign in and how an alert would reach you. The hostname you added and the origin address it points at. And the result of every check: what it looked at, what it found, and when it ran.
If you leave an email to tell us an unbuilt feature is worth building, we keep that too, along with which page you left it on.
We also keep a daily tally of how often things happen, like how many domain checks ran and how many of them turned out to be on Cloudflare already. It is a date, a name, and a number. Nothing in it points at a person, and it exists so we can tell what to build next.
Not stored, because it never reaches us: your pages, your files, your orders, your customers, and anything they send you.
Your hostname and your origin address do not go out to third party analytics or logging either. For a product like this, those two strings are infrastructure detail about you, and infrastructure detail is exactly what somebody scanning for a way in is looking for.
That is the short version. The privacy page lists every column by name, including the ones this answer summarises.
Will it slow my website down?
We have not measured this on real customer websites yet, so we are not going to put a number on it. Here is the mechanism instead, so you can judge it yourself.
Requests stop going straight to your server and reach the nearest Cloudflare location first, which for visitors in Vietnam is usually closer to them than your server is. Files that can be cached are answered there without ever reaching you. Anything that cannot be cached takes one extra hop before it gets to you.
Whether that adds up to faster or slower depends on where your server sits and where your visitors are. When we have measurements from real websites, we will publish them with the date they were taken, and not before.
Do I have to change anything on my server or my hosting?
No. Nothing gets installed, no hosting plan changes, and no configuration file on your side is touched. The whole change lives in DNS.
There is one thing worth doing afterwards, and it is optional. Your server keeps answering requests sent straight to its own address, which means somebody who finds that address can reach it without passing through the shield. That is not something we broke; it is how your server behaved before you found us. The difference is that we look for it from the outside and tell you when we can see it, with the address we reached and the time we reached it.
Still not the question you came with?
What the check says about your own domain is usually more useful than another paragraph from us. It reads public DNS, takes no account and no email, and it will tell you when you do not need us.