What Cloudflare does and why you'd install it on a VPS

Cloudflare is a content delivery network (CDN) and security service that sits between your visitors and your VPS. When you point your domain to Cloudflare instead of directly to your server, Cloudflare caches your site's content on servers around the world, routes traffic through its network, and filters out malicious requests before they reach your VPS.

Installing Cloudflare on a VPS is different from using it on shared hosting. On shared hosting, you simply change your domain's nameservers and Cloudflare handles everything. On a VPS, you own the server itself, so you're choosing whether to route traffic through Cloudflare's network and how to configure that routing. You're not installing software on the VPS in the traditional sense — you're changing your domain's DNS records to point to Cloudflare first, then telling Cloudflare where your actual VPS lives.

The main reasons to do this: your site loads faster for visitors far from your server's location, Cloudflare's free tier blocks common attacks, and you can use Cloudflare's security rules without touching your VPS configuration. The trade-off is an extra layer between your visitors and your server, which adds a small amount of latency and means Cloudflare sees all your traffic.

Key Takeaways

  • Cloudflare works by changing your domain's nameservers or DNS records to point to Cloudflare first, not by installing software on your VPS itself.
  • You need to know your VPS's IP address and have access to your domain registrar's DNS settings before you start.
  • The setup process takes about 15 minutes and involves creating a Cloudflare account, adding your domain, updating nameservers at your registrar, and pointing Cloudflare back to your VPS's IP.
  • After setup, your VPS will receive requests from Cloudflare's IP addresses, not directly from visitors, which may require changes to your firewall or logging configuration.
  • Cloudflare's free tier includes caching, basic DDoS protection, and a Web Application Firewall, with paid tiers adding more features.

Step 1: Create a Cloudflare account and add your domain

Go to cloudflare.com and click Sign Up. Enter your email address and create a password. Cloudflare will send you a verification email — click the link to confirm your account.

Once logged in, click "Add a Site" or the plus icon. Type your domain name (for example, example.com, not www.example.com). Cloudflare will scan your domain's current DNS records and show you what it finds. This scan usually takes 30 seconds to a few minutes. Review the records it discovered — these should match what your registrar currently has set up. Click Continue.

Cloudflare will ask you to choose a plan. The free tier is sufficient for most small to medium sites and includes caching, basic DDoS protection, and a Web Application Firewall. Select the free plan and click Continue.

Step 2: Update your domain's nameservers at your registrar

Cloudflare will display two nameservers that look like ns1.cloudflare.com and ns2.cloudflare.com (the exact names vary). Copy these exactly — they are case-sensitive in some systems, though most registrars ignore case.

Log into your domain registrar's website (GoDaddy, Namecheap, Google Domains, or wherever you registered your domain). Find the DNS or Nameservers section — this is usually under Domain Settings or Advanced DNS. Delete the old nameservers and enter Cloudflare's two nameservers. Save the changes.

Nameserver changes can take anywhere from 30 minutes to 48 hours to propagate across the internet, though most complete within a few hours. Cloudflare will send you an email when it detects the change. You can check the status by going back to your Cloudflare dashboard and looking for a "Nameservers Updated" message.

Step 3: Point Cloudflare back to your VPS's IP address

While you're waiting for nameservers to update, log into your Cloudflare dashboard and go to the DNS section for your domain. You should see the DNS records that Cloudflare scanned earlier. Look for an A record pointing to your old hosting provider's IP address.

Edit that A record and change the IP address to your VPS's IP. If you don't know your VPS's IP, log into your VPS provider's control panel (Linode, DigitalOcean, Vultr, or your provider's dashboard) and find the IP address listed under your server details. It will look like 192.0.2.1 or similar.

Make sure the A record is set to Proxied (orange cloud icon in Cloudflare), not DNS Only (gray cloud). Proxied means traffic flows through Cloudflare's network. If you see other records like MX records for email or CNAME records for subdomains, leave those as DNS Only unless you want email or those subdomains to route through Cloudflare as well.

Step 4: Configure your VPS to accept traffic from Cloudflare

Once nameservers have updated and your site is live through Cloudflare, your VPS will start receiving requests from Cloudflare's IP addresses instead of directly from visitors. This can cause two problems: your firewall might block Cloudflare's IPs, and your server logs will show Cloudflare's IPs instead of the actual visitor IPs.

First, whitelist Cloudflare's IP ranges in your firewall. Cloudflare publishes its IP ranges at cloudflare.com/ips. If you're using a VPS provider's built-in firewall (like Linode's Cloud Firewall or DigitalOcean's Cloud Firewall), add rules to allow traffic from those IP ranges on ports 80 (HTTP) and 443 (HTTPS). If you're using a firewall on the VPS itself (like UFW on Ubuntu or firewalld on CentOS), add the same rules there.

Second, configure your web server to log the real visitor IP. If you're running Nginx, add this line to your server block configuration: proxy_set_header CF-Connecting-IP $http_cf_connecting_ip; and then use that header in your logs. If you're running Apache, enable the mod_remoteip module and add RemoteIPHeader CF-Connecting-IP to your configuration. Restart your web server after making these changes.

Step 5: Test and monitor your setup

Visit your domain in a browser and check that your site loads. Open your browser's developer tools (press F12), go to the Network tab, and look at the response headers. You should see a header that says cf-ray with a code like 7a8b9c0d1e2f3g4h. This confirms traffic is flowing through Cloudflare.

Check your VPS's access logs to confirm you're seeing Cloudflare's IP addresses, not visitor IPs directly. On a Linux VPS, this is usually in /var/log/nginx/access.log or /var/log/apache2/access.log. If you see Cloudflare IPs but your real visitor IPs aren't showing up, you didn't configure the header correctly in step 4 — go back and check your web server configuration.

Go to your Cloudflare dashboard and click on Analytics. You should see traffic data appearing within a few minutes. If you see zero traffic after an hour, something went wrong — check that your A record points to the correct VPS IP and that your firewall isn't blocking Cloudflare's IPs.

Common issues and how to fix them

Your site shows "Error 522: Connection timed out" — Cloudflare can't reach your VPS. Check that your A record points to the correct IP address, that your VPS is actually running and responding to web requests, and that your firewall isn't blocking Cloudflare's IP ranges. Test by temporarily allowing all traffic on port 80 and 443, then add Cloudflare's IPs back one range at a time to find which one is blocked.

Your site loads but very slowly — Cloudflare's caching might not be working. Go to your Cloudflare dashboard, click Caching, and check that caching is enabled. If your site serves mostly dynamic content (like a web application that changes per user), caching won't help much. You can also check the Cache Rules section to set custom caching behavior for specific URLs.

SSL certificate errors or mixed content warnings — Make sure your VPS has an SSL certificate installed (from Let's Encrypt or your certificate provider). In your Cloudflare dashboard, go to SSL/TLS and set the encryption mode to "Full" or "Full (strict)". Full means Cloudflare encrypts traffic to your VPS but doesn't verify the certificate; Full (strict) verifies it. If you see errors, start with Full mode.

Email isn't working — If you have MX records for email, make sure they're set to DNS Only (gray cloud), not Proxied (orange cloud). Cloudflare can't proxy email traffic. Check that your MX records point to the correct mail server and that the mail server's IP is correct.

Frequently Asked Questions

Do I need to install anything on my VPS to use Cloudflare?

No. Cloudflare works by routing traffic through its network before it reaches your VPS. You don't install software on the VPS itself. You only need to change your domain's nameservers and point Cloudflare to your VPS's IP address. You may need to configure your firewall and web server logs to work properly with Cloudflare, but that's configuration, not installation.

Will Cloudflare slow down my site?

Usually no — it speeds up most sites by caching content on servers near your visitors. The trade-off is a small amount of latency added by the extra hop through Cloudflare's network, but this is almost always outweighed by the speed gain from caching. If your site is already very fast and mostly serves dynamic content, the improvement will be smaller.

Can I use Cloudflare with an SSL certificate I already have?

Yes. Keep your existing certificate on your VPS and set Cloudflare's SSL mode to Full or Full (strict). Cloudflare will encrypt traffic between visitors and Cloudflare, and your certificate will encrypt traffic between Cloudflare and your VPS. You don't need to do anything special — just make sure the certificate is installed and valid.

What happens if Cloudflare goes down?

Your site goes down too, because visitors can't reach it without going through Cloudflare's nameservers. This is rare — Cloudflare has very high uptime — but it's a real risk. If you need to bypass Cloudflare in an emergency, you can temporarily change your nameservers back to your registrar's default nameservers, though this takes time to propagate.

Can I use Cloudflare with a subdomain instead of my main domain?

Not with nameserver changes. If you change your nameservers to Cloudflare, your entire domain routes through Cloudflare. You can use Cloudflare's CNAME setup for subdomains instead, which routes only that subdomain through Cloudflare while keeping your main domain elsewhere, but this requires your registrar to support CNAME at the root domain, which most don't.