In the modern 2026 web environment, Cloudflare’s proxy is the default for most sites. However, for specialized services like development environments on mybox, direct database connections, or legacy mail servers, you may need to “bypass” the proxy to establish a direct connection to your origin IP.
Disabling the proxy for a specific subdomain is a “DNS-only” operation that takes effect across the internet in minutes.
Table of Contents
When Should You Disable Cloudflare for a Subdomain?
- Development & Staging: When testing new code on your mybox dev site where Cloudflare’s cache or “Under Attack” mode might interfere with debugging.
- Direct IP Services: If you are using FTP, SSH, or direct SQL connections that require the server’s real IP rather than a proxied one.
- Email Services: While Cloudflare handles web traffic (HTTP/S), mail records (IMAP/SMTP) should generally remain unproxied (Gray Cloud) to prevent delivery failures.
- VPNs & VoIP: Applications that rely on non-standard ports or protocols that Cloudflare’s CDN doesn’t support on free plans.
How to Disable the Proxy (Step-by-Step)
1. Access the DNS Management
Log in to your Cloudflare Dashboard, select your domain, and click on the DNS tab in the sidebar.
2. Identify the Subdomain Record
Scroll through your DNS records to find the specific A, AAAA, or CNAME record for your subdomain (e.g., dev, test, or mail).
3. Toggle the Proxy Status
Look for the Proxy status column.
- Orange Cloud: Traffic is proxied through Cloudflare (CDN, WAF, and Caching are ON).
- Gray Cloud: Traffic goes directly to your mybox server (Cloudflare only acts as a DNS provider).
Click the Edit button on that specific row, then click the Orange Cloud icon to turn it Gray.
4. Save Changes
Click Save. The cloud icon will now be gray, and the status will change to DNS only.
Important: Security Implications
When you “Gray Cloud” a subdomain, you are exposing your mybox origin IP address to the public internet.
- DDoS Risk: That specific subdomain will no longer be protected by Cloudflare’s DDoS mitigation.
- SSL/TLS: You must ensure that your mybox server has a valid SSL certificate (like Let’s Encrypt) installed locally, as Cloudflare’s “Universal SSL” will no longer be encrypting the traffic for that subdomain.
Troubleshooting: Why is it still proxied?
If you’ve turned the cloud gray but still see Cloudflare headers in your browser, check the following:
- Local DNS Cache: Your computer might still be remembering the old Cloudflare IP. Open your terminal and run
ipconfig /flushdns(Windows) orsudo killall -HUP mDNSResponder(Mac). - Browser Cache: Hard-refresh your browser (
Ctrl + F5orCmd + Shift + R). - CNAME Flattening: If your subdomain is a CNAME pointing to the root domain, and the root domain is proxied, the subdomain might still inherit the proxy. Ensure the CNAME itself is “Gray Clouded.”
Summary
| Status | Orange Cloud | Gray Cloud (DNS Only) |
| IP Visibility | Hidden (Cloudflare IP) | Exposed (Your Real IP) |
| Performance | CDN & Caching Active | Direct Server Speed |
| Security | WAF & DDoS Active | Server-Level Security Only |
| Best For | Main Website / Blog | Email, FTP, Dev Sites |