# Cloudflare DNS Management UK

Source: https://dijituldns.co.uk/cloudflare-dns-management/
Updated: 2026-10-08

> dijitul sets up and manages Cloudflare DNS for every site on dijitul Complete Hosting, £1 a day + VAT. We add and maintain your DNS records, decide which records are proxied, set the SSL mode to Full (strict), configure sensible caching and basic firewall rules, and publish SPF, DKIM and DMARC records so your email is trusted.

## Key facts

- Cloudflare DNS setup and ongoing management included in the £1 a day + VAT plan
- A, AAAA, CNAME, MX, TXT, SRV and CAA records maintained
- Proxying chosen per record, with mail and FTP records left unproxied
- SSL/TLS mode set to Full (strict) with a valid certificate on the server
- Caching rules for static files, with admin areas and checkouts bypassed
- Basic WAF and bot settings configured
- SPF, DKIM and DMARC published for your email provider

## Why we use Cloudflare for DNS

DNS is the phone book that sends visitors and email to the right place. If it's wrong, your website disappears and your email bounces. We put every site we host on Cloudflare because its DNS is fast, changes take effect quickly, and it adds a layer of protection in front of your server.

Most customers never need to see the Cloudflare dashboard. We make the changes for you when you ask, for example to verify a Google or Microsoft account, add a mailing platform, or point a subdomain at a booking system.

## What we manage

- **DNS records:** A and AAAA for your site, CNAMEs for subdomains, MX for mail, TXT for verification, SRV where needed, and CAA to control which authorities can issue certificates.
- **Proxying:** web records go through Cloudflare's proxy (the orange cloud), which hides your server's IP and enables caching. Mail, FTP and some API records are set to DNS only, because proxying would break them.
- **SSL mode:** we use Full (strict), which encrypts traffic between Cloudflare and our server and checks the server certificate. Flexible mode causes redirect loops and isn't secure end to end, so we avoid it.
- **Redirects:** www to non-www (or the reverse), HTTP to HTTPS, and old domains to new ones.
- **DNSSEC** where your registrar supports it.

## Caching and performance

Cloudflare can cache images, CSS and JavaScript close to your visitors, which takes load off the server and speeds up pages. We set caching so it helps without causing problems: static files are cached, while admin areas, logins, baskets and checkouts are always passed straight through. When you change your site, we can purge the cache so visitors see the update straight away.

## WAF and security basics

We configure Cloudflare's security settings to block obvious attacks before they reach the server. That includes the security level, bot protection, and custom firewall rules such as challenging repeated hits on *wp-login.php* or *xmlrpc.php*, or blocking traffic to admin paths from outside the UK if you ask. This sits alongside the server-side protection described on [website security](https://dijituldns.co.uk/website-security/).

## Email records: SPF, DKIM and DMARC

Big mailbox providers now expect senders to authenticate their email. We publish:

- **SPF:** lists the services allowed to send email for your domain, such as Microsoft 365, Google Workspace, your website and your newsletter tool.
- **DKIM:** a public key that lets receivers check your messages weren't altered.
- **DMARC:** tells receivers what to do with mail that fails SPF and DKIM, starting with a monitoring policy and tightening it once everything passes.

This is included with [dijitul Complete Hosting](https://dijituldns.co.uk/complete-hosting/). See also [email hosting](https://dijituldns.co.uk/email-hosting/).

## FAQs

### Should I use Cloudflare for my website's DNS?

For most small business sites, yes. Cloudflare DNS is fast, free at the basic level, and adds caching and protection in front of your server. dijitul sets it up and manages it for you as part of its £1 a day + VAT hosting.

### What SSL mode should I use in Cloudflare?

Use Full (strict) whenever your server has a valid certificate. It encrypts traffic all the way to the server and checks the certificate. Flexible mode leaves the server leg unencrypted and often causes redirect loops. dijitul sets Full (strict) by default.

### Should my MX record be proxied in Cloudflare?

No. Cloudflare's proxy only handles web traffic, so mail-related records must be set to DNS only (grey cloud). The same applies to FTP and some API hostnames. dijitul checks this when it sets up your zone.

### Why are my emails going to spam?

Often because SPF, DKIM or DMARC records are missing or wrong, so receivers can't verify your mail. Each service that sends for your domain must be included. dijitul publishes and maintains these records in Cloudflare for its hosting customers.

### Will Cloudflare caching break my online shop?

Not if it's configured properly. Static files can be cached, but baskets, checkouts, account pages and admin areas must bypass the cache. dijitul sets these rules so customers always see live prices and stock.

### Do I need a Cloudflare account to host with dijitul?

No. dijitul sets up and manages the Cloudflare DNS zone for you. If you already use Cloudflare and want to keep your own account, we can work with that instead.

## Pricing and ordering

dijitul Complete Hosting is £1 a day + VAT (£365 a year + VAT). Order at https://clients.dijitul.uk/order?product=complete-hosting&ref=dijituldns&src=cloudflare-dns-management or call 01623 650333.
