Migrate to RunxBuild today!! Deploy More while Spending Less

Calculate your savings
unxBuild
Back to Blog Explainer

What Is Cloudflare Used For: DNS, CDN, WAF, and What It Is Not

Sean

Platform Writer

Sep 22, 2026
8 min read

Cloudflare is used as a reverse proxy and CDN in front of a website, plus DNS, DDoS protection, a web application firewall, TLS termination, and increasingly a small application platform through Workers, Pages, and R2, with Zero Trust for access control on top. A small site typically needs three of those, DNS, the proxy, and TLS, not the whole list. What Cloudflare does not do is host the application itself: something still has to run the origin server that Cloudflare sits in front of.

What Is Cloudflare Used For: DNS, CDN, WAF, and What It Is Not

Cloudflare’s own feature list runs long enough that the question of what Cloudflare is actually used for gets lost in it. Most of that list is optional for a typical site, and the part that trips people up is not a missing feature, it is the assumption that Cloudflare replaces the server behind it.

Table of contents

The Short Answer: Cloudflare Sits in Front of Your Site

Cloudflare is a layer that requests pass through before they reach your server. DNS points your domain at Cloudflare, Cloudflare answers or forwards the request, and your origin server, wherever it actually runs, only ever sees traffic that has already been through Cloudflare’s network. That single position is what makes DNS, the proxy, the firewall, and TLS termination all possible from one service.

It is not, by itself, a place your application runs. That distinction matters more than any individual feature on the list, and it is the one most comparison articles skip past on their way to the longer feature table.

DNS: The Part Almost Everyone Uses

Moving a domain’s nameservers to Cloudflare is usually the first step, and it is free on every plan. Once Cloudflare is authoritative for the domain, every other feature becomes available for individual records, because Cloudflare only acts on traffic for records it is answering.

  • A records and CNAMEs work as with any DNS provider
  • Proxied records (orange cloud) route through Cloudflare’s network
  • DNS-only records (grey cloud) resolve straight to your server, skipping the proxy entirely
  • MX and TXT records generally need to stay DNS-only, since mail and verification traffic does not go through the proxy

Changing nameservers takes effect once the domain’s registrar propagates the change, typically within a few hours, and every record’s proxy status can be toggled independently afterward without touching DNS again.

Reverse Proxy and CDN: Proxied vs DNS-Only

Turning the proxy on for a record is what makes Cloudflare a CDN and a shield at the same time: static assets get cached at the edge, and the DDoS protection and WAF only apply to proxied traffic. Turning it off, DNS-only, means Cloudflare just resolves the name and every other Cloudflare feature for that record stops applying.

The common mistake is leaving a record DNS-only and assuming the firewall or caching is active for it, an easy oversight on a subdomain added after the main site was already configured, such as an API host that quietly serves unprotected traffic.

DDoS Protection and the WAF

Layer 3/4 DDoS mitigation runs automatically on the free plan for proxied traffic. The web application firewall, which inspects requests for SQL injection, common exploit patterns, and bot traffic, is available with managed rulesets on the free plan too, with more granular custom rules on paid plans.

Both only see proxied traffic. A DNS-only record gets none of it, which is the main reason to proxy a record in the first place rather than using Cloudflare purely for DNS. Rate limiting rules and bot-management scoring sit in the same category, useful, and only active on records actually routed through the proxy.

TLS: Certificates and the SSL Mode That Breaks Sites

Cloudflare issues a free certificate for the connection between the visitor and Cloudflare’s edge. What happens between Cloudflare and your origin server is a separate setting, and it is the one that causes the most support tickets: Flexible mode encrypts visitor-to-Cloudflare but sends plain HTTP to the origin, which produces redirect loops if the origin also tries to force HTTPS.

Full or Full (Strict) mode encrypts both hops, and Full (Strict) additionally validates the origin’s certificate. See Cloudflare’s own SSL mode documentation for the exact behaviour of each. If the origin has a valid certificate of its own, Full (Strict) is the mode to use, Flexible exists for origins that cannot terminate TLS at all, and it should not be the default choice.

Workers, Pages, and R2: The Platform Layer

Beyond the proxy, Cloudflare also runs a serverless compute product (Workers), static site hosting (Pages), and object storage (R2). These are separate products from the CDN and DNS features, a site can use Cloudflare purely as a proxy in front of a server hosted elsewhere and never touch any of the three.

They matter for small-site owners mainly as an edge-logic option: rewriting a header, redirecting a path, or running a small function without deploying a whole service for it. None of them are required to use the proxy, DNS, or WAF features, and a site can adopt one without the others.

Zero Trust: Access Control, Not Hosting

Zero Trust is Cloudflare’s identity and access product, putting an internal tool or admin panel behind a login before a request reaches it, without a VPN. It is unrelated to whether Cloudflare is proxying your public site, and most small sites do not need it unless there is an internal dashboard to lock down.

It works by intercepting requests to a hostname before they reach the origin, checking the visitor’s identity against a policy, and only forwarding the request once that check passes. That makes it a good fit for a staging environment or an admin panel that should never be public, rather than for the site itself.

What Cloudflare Does Not Replace: The Origin

Every feature above assumes a server exists to proxy requests to. Cloudflare caches, filters, and terminates TLS in front of that server; it does not run your application code, your database, or your build process. A site pointed at Cloudflare with no origin behind it is a domain with nothing to show.

That is the gap that catches people evaluating Cloudflare as if it were a hosting provider: it is the layer in front of hosting, and the two are not substitutes for each other. A domain, a proxy, and a certificate with nothing running behind them is a configuration, not a website.

How this fits the rest of the stack

Cloudflare handles the DNS, the proxy, and the certificate; the origin still has to run somewhere, with its own deploy path and its own domain configuration to match whatever Cloudflare is pointed at. A static site or service with custom domains and certificates handled directly covers that origin side, proxied through Cloudflare or not. What it costs alongside everything else is what the RunxBuild hosting calculator works out.

Useful related references:

FAQ

What does Cloudflare actually do?

It sits between visitors and your server as a reverse proxy, handling DNS, caching static content at the edge, filtering traffic through a firewall and DDoS protection, and terminating TLS. Optional products on top include serverless functions, static hosting, object storage, and access control for internal tools.

Is Cloudflare free?

The free plan includes DNS, a shared certificate, basic DDoS protection, a managed firewall ruleset, and CDN caching for proxied records. Paid plans add custom WAF rules, more cache control, image optimisation, and higher rate limits, but a small site can run entirely on the free tier.

Do I need Cloudflare for my website?

Not strictly. A small site works without it, but Cloudflare adds a free certificate, basic DDoS protection, and CDN caching in front of a server for no extra infrastructure. The main reason to skip it is wanting the origin’s real IP and headers to reach visitors unmodified.

Is Cloudflare a hosting provider?

No. It proxies, caches, and protects traffic in front of a server, but the server itself, the application, the database, the build process, has to run somewhere else. Confusing the two is the most common setup mistake: pointing a domain at Cloudflare with nothing behind it to serve the site.

#cloudflare uses#what does cloudflare do#cloudflare cdn#cloudflare dns#cloudflare zero trust