//Server Security

Cloudflare with cPanel or Plesk: Complete Setup Guide (2026)

How to point Cloudflare at a cPanel or Plesk server correctly: SSL mode, restoring the real visitor IP, and firewalling the origin so it cannot be bypassed.

4 min read
Cloudflare with cPanel or Plesk: Complete Setup Guide (2026)

Putting Cloudflare in front of a cPanel or Plesk server is one of the most common setup steps for a new site, and also one of the easiest to get subtly wrong. Done correctly it adds free DDoS protection, caching, and a CDN in front of your origin server; done carelessly it can break SSL, hide your visitors' real IP addresses from your logs, or leave your actual server IP exposed to attackers anyway. Here is how to set it up properly.

What Cloudflare actually changes

Cloudflare works by becoming your domain's DNS provider and proxying traffic through its own network before it reaches your server. Visitors connect to Cloudflare's edge servers, not directly to your cPanel or Plesk box, which is what enables the caching and DDoS protection — but it also means your server's logs, by default, show Cloudflare's IP addresses as the visitor instead of the real one, unless you configure your panel to trust Cloudflare's forwarded headers.

Step-by-step setup on cPanel or Plesk

  1. Add your domain to Cloudflare and update your registrar's nameservers to the two Cloudflare nameservers it assigns, which typically takes a few hours to propagate fully.
  2. Set the DNS records to "Proxied" (orange cloud) for the records you want protected (usually the A record for your main domain and www), while leaving records like mail (MX) and any direct-access subdomains as "DNS only" (grey cloud), since email and some services do not work through Cloudflare's proxy.
  3. Set the SSL/TLS mode to "Full (Strict)" in Cloudflare, not "Flexible." Flexible mode encrypts traffic between the visitor and Cloudflare but sends plain, unencrypted traffic from Cloudflare to your server, which both weakens security and can cause redirect loops with WordPress and other apps that force HTTPS.
  4. Install a valid SSL certificate on the origin server itself (cPanel's AutoSSL or Plesk's Let's Encrypt integration both work), which Full (Strict) mode requires in order to verify the connection to your actual server.
  5. Restore the real visitor IP in your server logs by installing Cloudflare's official module (mod_cloudflare for Apache, or the equivalent for LiteSpeed/Nginx), so your access logs, security tools like Imunify360, and analytics see the actual visitor IP rather than Cloudflare's proxy IP for every request.

Common mistakes and how to avoid them

MistakeEffectFix
Leaving SSL mode on "Flexible"Redirect loops, weaker encryptionSwitch to Full (Strict) with a valid origin certificate
Not restoring the real visitor IPSecurity tools and logs see Cloudflare's IP, not the attacker'sInstall the Cloudflare IP-restoration module for your web server
Proxying the MX recordEmail delivery breaksKeep mail-related DNS records as "DNS only" (grey cloud)
Origin server IP still reachable directlyAttackers can bypass Cloudflare entirely by hitting the server IPFirewall the origin to only accept web traffic from Cloudflare's published IP ranges

Actually hiding your origin IP

Adding Cloudflare's orange cloud does not, by itself, protect your server if the origin IP address is still discoverable and directly reachable — through an old DNS record, an SSL certificate transparency log, or a subdomain you forgot to proxy. The complete setup firewalls your server so that port 80/443 only accepts connections from Cloudflare's published IP ranges, which both cPanel's Firewall app (via CSF) and Plesk's firewall extension support with an IP allow-list. Without this step, a determined visitor can often find your real server IP and simply bypass Cloudflare's protection by connecting to it directly.

Frequently asked questions

Does Cloudflare work with cPanel's AutoSSL?

Yes, as long as you use Full (Strict) mode and AutoSSL has successfully issued a certificate on the origin server; Cloudflare then verifies against that certificate rather than accepting an unencrypted connection.

Why do my server logs show Cloudflare's IP instead of the visitor's?

Because Cloudflare proxies the connection, your web server sees Cloudflare's edge IP as the source by default; installing the real-IP restoration module for your web server (Apache, Nginx or LiteSpeed) fixes this by reading the visitor's real IP from Cloudflare's forwarded header.

Should I proxy my mail server's DNS record through Cloudflare?

No, email protocols are not supported by Cloudflare's proxy; keep MX records and any record used for direct mail server access set to "DNS only."

Conclusion

Cloudflare in front of cPanel or Plesk is genuinely valuable, but only when set up completely: Full (Strict) SSL with a real origin certificate, the real-IP module installed so your logs and security tools still work correctly, and a firewall rule limiting the origin to Cloudflare's IP ranges so the protection cannot simply be bypassed. Skipping any one of those three steps leaves a real gap even though the site looks protected on the surface.

cloudflare cpanelcloudflare pleskcloudflare ssl full strictrestore visitor ip cloudflarehide origin ip cloudflarecloudflare ddos protectioncloudflare setup guide

Try it on your own server

Follow along on a Cloud VPS with full root access, or read the step-by-step knowledge base guides.