What actually changes, and what does not
Your website ends up behind Cloudflare without moving your nameservers, your hosting or your files. This page walks through the exact change we ask for, in the order it happens.
One name moves, not the whole domain
Putting a site behind Cloudflare normally means handing over your nameservers, and that is every DNS record you have. It is a real change with real risk, and it is the part most people refuse. A CNAME record is a much smaller thing: one name inside the DNS you already have, pointing somewhere else.
Changing nameservers
The usual way to put a site behind Cloudflare
- Your websitemoves
- Emailmoves
- Other subdomainsmoves
- Verification recordsmoves
A different company answers all of it from then on. That is four things to carry over correctly, not one.
Adding one CNAME
What we ask for instead
- Your website
gw.onelineshield.com - Emailunchanged
- Other subdomainsunchanged
- Verification recordsunchanged
Your nameservers stay put, so the other three keep being answered by whoever answers them today.
Nameservers answer a broad question, which is who is in charge of this domain. A CNAME answers a narrow one, which is where this single name points. We only need the narrow answer, so the company holding your DNS today keeps holding it, including the records you would rather not touch.
Three steps, in the order they actually run
The order below is not a presentation choice. Step 2 has to finish before step 3 can start, and doing those two the other way around breaks a working website instead of protecting it.
- 1
You check the domain, and we check it again
First you type the name and read what public DNS says about it. No account for that part. Adding the website for real does need one, and it is an email address plus a link we send you; there is no password to choose. Then that same check runs a second time on our side. One answer means we stop instead of continuing: if your domain is already served through the Cloudflare proxy, registering it here would hand your visitors error 1014 rather than protection. That case gets refused, not worked around.
You also tell us where your real server is. That address belongs to your hostname alone, and it is the address Cloudflare sends requests to.
- 2
We register your hostname with Cloudflare before you touch DNS
The name has to exist on Cloudflare first. Point your DNS at Cloudflare before Cloudflare knows the name and visitors get error 1014 for real, on a website that was working ten minutes earlier. So the hostname is created first, with your own server recorded as its origin, and only then does the setup screen have anything to show you.
If that registration fails, you get no records to copy at all. That is deliberate, and submitting again continues from where it stopped instead of creating a second hostname.
- 3
You add two DNS records, and the screen turns on by itself
Both records go in wherever your DNS is managed today. The setup page keeps checking every few seconds, shows you how many times it has checked, and flips to protected on its own the moment Cloudflare confirms. Nothing to refresh, nothing to install on your server.
DNS changes usually take between five and sixty minutes to reach us. Seeing no change in the first minutes is normal, and the setup page says exactly that instead of marking it as an error.
Two records, and only one of them is the famous line
One line of DNS is how we describe where your website points, and that part holds: a single CNAME decides it. The second record is a permission, not a destination. It is not optional, and leaving it out is the kind of mistake that looks like success for months.
Record 1 decides where your website points
A CNAME on the name of your website, pointing at gw.onelineshield.com.
Without it, nothing has changed. Visitors keep arriving at your server directly, exactly as they do today.
Record 2 keeps the certificate renewing itself
A CNAME on _acme-challenge. in front of that same name, pointing at a Cloudflare address that begins with your own hostname.
Security certificates expire and have to be renewed. This record is how Cloudflare proves it still controls the name at renewal time, without coming back to ask you for anything.
Without it, everything works for months. Then a renewal fails and your visitors meet a security warning on a site nobody touched. That silent failure is a large part of why this product exists, so both records are shown together and both are checked from then on.
From that moment your website is reached through Cloudflare. What follows is what that actually means for a request.
Where a visitor request goes afterwards
Nothing about your hosting changes. What changes is the address DNS hands out for your website.
- 1DNS hands out Cloudflare addresses for your website instead of your server address. That is the whole effect of the record you added.
- 2The request lands on the Cloudflare network, which answers it using a certificate issued for your hostname. Filtering and caching happen here, before anything reaches you.
- 3Cloudflare forwards what is left to the origin recorded for that hostname, which is your server, at the address you gave us and nowhere else.
- 4Your server answers the way it always has. Same files, same database, same hosting company, no software added.
There is one more hop than before, and there is a cache in front of your static files. We do not put a single number on that, because the honest answer depends on where your server sits and where your visitors are. A percentage quoted before anyone measured your site is a number about someone else.
The check on the home page draws this path using the addresses your domain returns right now, which is the only version of it worth trusting.
What does not happen
Each line below is something this product deliberately does not do. They are easier to verify than promises, and easier to hold us to.
Your traffic never passes through a machine we run
The shield is the Cloudflare network, configured under our account. Requests go from Cloudflare straight to your server, using the origin recorded for your hostname alone. We hold your settings and the results of our checks. We never sit in the path of your visitors, and there is no shared server of ours for your traffic to fall back to.
Your nameservers do not move
Email, other subdomains and verification records keep being answered by whoever answers them today. We never ask for access to your DNS account, so every record stays in your hands, including the two you add for us.
We do not sell a stronger firewall
Your website sits behind the same Cloudflare protection as every other site on the zone, at the same strength. Firewall rules written per hostname are an Enterprise feature, and we would rather say that plainly than let a price list imply otherwise. What we add is getting you behind that protection with one record, and telling you when the setup quietly stops working.
You are not held here
Point that one record back at your server and visitors reach it directly again, as soon as DNS caches expire. There is no ticket to open, nobody to ask, and no step that needs us to be online. Leaving is the same kind of change as arriving.
The quickest way to know whether any of this applies to you is to read your own DNS. Two public queries, no account, and we will say so when the answer is that you do not need us.
Check my domain