Cloudflare DNS records can work in two different modes: proxied or DNS only. This setting affects how traffic reaches your website and whether Cloudflare stands between the visitor and your hosting environment.
The proxy setting is important because it can affect website visibility, SSL behavior, caching, and email configuration. In mybox, you may see this option when managing DNS records for a domain connected through Cloudflare.
Table of Contents
What the Cloudflare proxy does
When the Cloudflare proxy is enabled for a DNS record, traffic does not go directly from the visitor to your hosting server. Instead, the visitor connects to Cloudflare first, and Cloudflare then connects to the server where your website is hosted.
This is usually shown in Cloudflare as an orange cloud.
When the proxy is disabled, Cloudflare only answers DNS queries. Visitors are sent directly to the server defined in the DNS record.
This is usually shown as a gray cloud and is often called DNS only.
Proxied vs DNS only
| Setting | What it means | Typical use |
|---|---|---|
| Proxied | Cloudflare sits between the visitor and the website server | Website traffic, caching, Cloudflare protection |
| DNS only | Cloudflare only points the domain to the correct server | Email records, verification records, some service records |
The proxy setting does not change the DNS record itself. It changes how Cloudflare handles traffic for that record.
What it means for your website
For website records, such as A, AAAA, or CNAME records used by the main domain or www, the proxy can usually be enabled.
When proxy is enabled, Cloudflare may provide caching, traffic filtering, HTTPS handling, and other website-related features. The visitor sees Cloudflare as the first connection point, while your website still loads from the hosting environment behind it.
If the proxy is disabled, the website still works, but traffic goes directly to the server. Cloudflare acts only as DNS in this case.
Both modes can be valid. The correct setting depends on how the domain, SSL certificate, and website are configured.
What it means for SSL
SSL behavior can be affected when Cloudflare proxy is enabled.
With the proxy turned on, the visitor connects to Cloudflare over HTTPS. Cloudflare then connects from its own network to the hosting server. This means there are two parts to the connection:
- Visitor → Cloudflare
- Cloudflare → hosting server
For a stable HTTPS configuration, the website should also have a valid SSL certificate on the hosting side. This helps Cloudflare connect securely to the server and prevents SSL errors.
If the website shows SSL errors after enabling the proxy, check the Cloudflare SSL/TLS mode and confirm that the domain has a valid SSL certificate in mybox.
What it means for email
Email records should normally remain DNS only.
Cloudflare’s proxy is designed for web traffic, not mail traffic. Records used for email delivery and email client configuration should not be proxied.
This includes records such as:
MXTXTSPFDKIMDMARC- mail-related
CNAMErecords - records such as
mail,imap,smtp, orwebmail, if they are used for email access
If mail records are proxied, email services may stop working correctly because mail servers need to connect directly to the correct mail host.
For mybox email, make sure email-related records point to the correct mybox mail services and remain DNS only.
Common examples
| DNS record | Recommended proxy setting | Reason |
|---|---|---|
example.com pointing to website hosting | Proxied or DNS only | Both can work, depending on SSL and Cloudflare setup |
www.example.com pointing to website hosting | Proxied or DNS only | Usually safe to proxy for website traffic |
mail.example.com | DNS only | Mail services should not pass through Cloudflare proxy |
MX record | DNS only | Mail delivery requires direct DNS resolution |
TXT records for SPF, DKIM, or DMARC | DNS only | These records are used for verification and email authentication |
| Verification records | DNS only | External services need to read the DNS value directly |
What is normal after changing the proxy setting
Changes to the Cloudflare proxy setting usually apply quickly, but some effects may take time to appear because of caching.
After enabling the proxy, you may notice that:
- the website starts showing Cloudflare IP addresses instead of the hosting server IP;
- cached content may continue to appear for a while;
- SSL behavior may change depending on the Cloudflare SSL/TLS mode;
- server logs may show Cloudflare connections instead of direct visitor IPs.
After disabling the proxy, traffic starts going directly to the hosting server again. DNS propagation and local cache can still cause temporary differences between networks.
When to keep proxy enabled
Proxy is usually useful for website records when you want Cloudflare to manage web traffic between visitors and your hosting environment.
This can be appropriate for:
- the main website domain;
- the
wwwversion of the domain; - website subdomains;
- static content subdomains, if they serve normal web traffic.
Before enabling it, make sure the website works correctly over HTTPS and that the SSL configuration is valid.
When to keep proxy disabled
Proxy should usually stay disabled for records that are not used for normal website traffic.
This includes:
- email records;
- mail hostnames;
- FTP hostnames;
- verification records;
- service records that must expose the real destination;
- any third-party service that specifically asks for DNS only.
If a service does not work after enabling the proxy, switching the record back to DNS only is often the correct first step.
Summary
Cloudflare proxy controls whether Cloudflare only manages DNS or also handles website traffic. For website records, proxy can be enabled when SSL and website configuration are correct. For email and verification records, DNS only is usually the correct setting.
The practical rule is simple: proxy website traffic when needed, but keep email and service records DNS only.