Cloudflare Free: Make Your Domain Legit, Fast & Secure — A Practical Checklist
What you get for $0 (high‑impact highlights) • Authoritative DNS with global anycast • Universal SSL/TLS certificates (DV), Auto-renew • CDN caching + Brotli/Gzip compression • DDoS mitigation (L3/4/7) when proxied (orange cloud) • HTTP/2 and HTTP/3 (QUIC) support • WAF Managed Rules (free ruleset) + basic firewall • Bot Fight Mode (basic bot protection) • Bulk & Single Redirects (for www→apex, legacy URLs) • Email Routing (free inbound forwarding) + DMARC Management • DNSSEC (sign your zone) • Transform Rules (add security headers) Step‑by‑step setup (15–30 minutes) 1) Add your domain → change nameservers at your registrar to Cloudflare’s. 2) Proxy only web traffic you want protected/accelerated (orange cloud). Leave mail-related DNS records (MX, mail.) unproxied (gray cloud). 3) Enable DNSSEC → copy DS record into your registrar. 4) SSL/TLS → set mode to “Full (strict)” after you install a valid cert on origin (or use Cloudflare Origin CA). 5) Edge certificates → Universal SSL ON...