Connecting your website to Cloudflare is a great idea. The service acts as a protective shield for your site, improving speed, performance, and uptime all around, while enhancing security.
Cloudflare acts as a content delivery network (CDN), which allows users to load the site from a server closest to them, provides both cybersecurity and DDoS protection, along with domain and DNS management services.
Here, we’ll show you how to set your HostGator site up with Cloudflare. From start to finish, including ways to add the domain, update the nameservers, and verify everything is working properly.
The best part? You’ll get it right the first time, as I’ve made a bunch of mistakes while writing this, so you don’t have to. We’ll save you the trouble, get Cloudflare connected on the first try, and make you the smartest DNS (Domain Name Server) expert in the room!
Step 1: Prepare Your Website Before Connecting Cloudflare
The first step is so simple and obvious you may be tempted to skip it entirely. Don’t.
You need to verify your site is already live on HostGator and working properly. Now you may be reading this and thinking, “of course my site is live,” but a five second check now might save you hours of troubleshooting down the line.
If you want to get going on HostGator with an excellent intro offer, say no more:
- Free domain name, SSL certificate, and CDN included
- Unmetered bandwidth — no limits on traffic or storage
- 1-click WordPress install and easy cPanel control panel
- 30-day money-back guarantee, no long-term contracts
- Get 66% OFF by buying 36 months upfront
- Get started on HostGator now.
HostGator is a solid compromise between performance and price. Its shared hosting includes unmetered bandwidth, cPanel, one-click WordPress installs, and support for domain-based email through tiered cPanel email plans, including an unlimited-mailbox option.
Go to full review »| Money Back Guarantee | Disk Space | Domain Name | Setup Time |
| 30 days | 10 GB SSD – 100 GB SSD | FREE (1 year) | 4 minutes |
The really obvious things are rarely double-checked when troubleshooting more complex stuff further down the line. If you’ve ever talked an elderly relative through a computer or appliance fix over the phone, only to ask them if they’ve actually plugged the thing in 45 minutes down the line, this prevents the hosting version of that.
Not to say that you’re a geriatric fellow, but when you get the foundational stuff correct, everything else falls into line.
In addition to checking if your site is live, you’ll also want to verify the domain is active and accessible and note down your current nameservers so you can back them up.
If you have custom DNS records you should locate these as well as it will speed things up later on.
For domains purchased through HostGator:
- Go to the Domains tab
- Click said domain
- Then click the DNS tab
External domains will have their DNS records right on the page once you click the domain in the domains tab.
Step 2: Add Your Domain to Cloudflare
Once you’re sure your site actually works, it’s time to add it to Cloudflare.
To be fair to Cloudflare, the company has made this part incredibly easy. You need a Cloudflare account to use the service, and you can create one by entering your details much like anywhere else. Alternatively, to save some time, you can connect with a Google, Apple, or GitHub account.
Once your account is up and running, select the “connect your domain” option.
This takes you to a screen where you add the web address of your domain and select a few bot-related options. Bots might sound like something you want to avoid, but they’re a key part of the internet.
The good and helpful internet bots crawl your site so it can be indexed by search engines and perform AI-related tasks, such as pulling information from your site to answer queries and training AI agents. You can use Cloudflare to block these bots on this screen (or change your mind later), though disabling the first one will stop your site from showing up on Google.
Many businesses work hard to get their brand and website information recommended directly by LLMs, as it is basically free marketing, brand visibility, and authority building.
Once that’s out of the way, it’s time to choose your plan. Cloudflare offers multiple plans to suit a wide variety of sites and businesses. But if you’re running a relatively small site, the “free” plan is likely your best option. As this is just a test site that will get zero traffic (unless you readers are bored enough to look it up) I went with the free option.
Remember, you can always upgrade these types of services later on.
Finally, Cloudflare will ask you for permission to scan the site’s DNS records. As the alternative is entering all of this information manually, you should probably just click “yes”. Those records are central to the next step.
Step 3: Review and Verify Imported DNS Records
While Cloudflare can import your DNS records automatically, mistakes can happen. So it’s important to take a close look at the original records alongside the imported ones and make sure they both match.
Any errors here will prevent your website from working properly, and while this seems like an incredibly boring step, it’s easier than trying to work out where things went wrong further down the line. It’s the difference between putting a cap on your coffee travel mug now and cleaning up a mess in your car later on, if you catch my drift.
To find the HostGator DNS records:
- Click the “Domains” tab
- Then the three dots “•••” to the right of your site’s name
- And “Advanced DNS”
The Cloudflare DNS records should be right in front of you after you tell the site to import the DNS records.
And thus begins the somewhat tedious task of making sure every line matches.
Though the most important DNS Record lines are:
- The A records (the ones with an “A” in the “type” column)
- The CNAME records
- And if your email is linked to your site, the MX and TXT records.
Now I know what you’re thinking. “Can I just use AI for this?”
Well, on the face of it this is what AI is perfect for. You could give something like Gemini or Claude access to both pages, or just dump a screen shot of each record set, then ask if they match. Or ask it to point out any discrepancies between the two.
But AI gets things wrong, a lot, and confidently says it’s correct anyway. At least my AI loves to gaslight me.
If something is wrong with the DNS Records, your site or email will be broken. It’s something that can be fixed, but it’s often quicker to just get things right on this step. You can and probably should use an AI program as a second set of eyes, though. An extra check doesn’t hurt, and humans are capable of missing things while proofreading, too.
Step 4: Update Your Domain’s Nameservers to Cloudflare
Okay, so we’re done with the tedious part, and now it’s on to what is arguably the most complex part of this guide. And it really isn’t that complex. You need to update your domain’s Nameservers to Cloudflare. This will essentially give Cloudflare permission to say where that web address directs to. Simple.
Cloudflare is nice enough to dump the addresses you need right in front of you on this stage of the setup. In a different tab, you’ll need to go to your domain registrar.
If this is HostGator:
- Go to the “Domains” tab
- Click your site’s address
- Then click the ”Nameservers” tab
- There’s a button that says “Change Nameservers”
- Click that and paste in the new nameservers (there are two of them)
- Save the changes and you’re done
If your domain registrar is a third party, you’ll need to log in to that third party’s site and change the nameservers there.
You don’t do anything with HostGator on this step. Obviously, the exact location of the box you’ll use to edit your nameservers will vary by provider. But it’s usually easy to find, and in a worst-case scenario, you can look up how to change nameservers on that particular provider’s site.
We might even have a guide on it, so check out our chat box HostHelper™ in another window. Once this is done, Cloudflare becomes the authoritative DNS provider for your site.
DNS propagation then begins. If you’re wondering what that means and how it’s going to affect your setup, that’s what our next step is all about.
Step 5: Wait for DNS Propagation and Verify Activation
DNS propagation is a bit weird. In my experience, it’s always been pretty much instant. You edit your nameservers, then you’re ready to move on within a few minutes. Yet there’s always a chance that this is where the process stalls for a day or two.
Everywhere, including this guide, will tell you that it can take a few minutes, 24 hours, or even up to 48 hours.
That being said, if you’ve completed Step Four but your DNS settings don’t seem to have changed, don’t panic. Go outside, feed the ducks, read that book you’ve been meaning to read, go to the gym, find love, fall out, get stuck in a horrific custody battle over your pet cat Colonel Mittens, learn a new skill, see the world.
You can do a lot in 48 hours. What you shouldn’t do is mess with your DNS settings in that time, as propagation is likely still in progress.
Check your Cloudflare dashboard, though, because like I said, it’s all usually quite quick. That dashboard will let you know when activation is complete, and you’ll be able to move on. If your website has visitors from around the world, global DNS propagation times can also vary. But it should all be wrapped up everywhere within a couple of days.
If you’re really stuck here, which I don’t foresee, you can always use a Free DNS Checker tool.
Step 6: Configure SSL and HTTPS Settings in Cloudflare
With your DNS propagated, it’s time to configure your SSL and HTTPS settings in Cloudflare. These are essential for security, and this is one area where getting things wrong could temporarily break the site.
To configure your SSL mode:
- Select SSL/TLS from the sidebar
- Click the blue configure button in the top right corner
- You’ll have five options: automatic, full, full (strict), flexible, and off
- Click “full”
While Cloudflare has an “automatic” mode and selects the most secure SSL mode your server supports, I’d recommend making sure it’s set to “full” at the very least. Clicking “full” won’t cost you anything extra, and it will stop your site from getting stuck in a looping error when it’s trying to load.
In addition to the fact that they’ll make your site less secure, both the “off” and “flexible” settings are basically legacy options that do not apply to sites based on HostGator. They’re from the days when getting an SSL certificate on an origin server was both complex and expensive. Those were also the days when you could just get away with ignoring it.
For the next part of this step, select “edge certificates” from the side bar.
Here you can enable automatic HTTPS rewrites, which will redirect HTTP links to the more secure HTTPS protocol. You can also select an “automatic HTTPS Rewrites” option that automatically changes older image or script links to HTTPS and helps you avoid mixed content warnings.
Finally, check the HTTPS settings are working by typing out your web address with “http://” at the beginning, and then checking it redirects (or changes itself) to “https://” when the site loads. The “S” means secure.
Step 7: Enable Basic Performance and Security Features
Cloudflare offers its users increased speed and reduced server load. To make the most of that, you’ll need to enable a few of the site’s performance features. One of the best ways you can reduce latency is through caching.
Caching stores snapshots of your website on Cloudflare’s servers or a user’s device, which can then be used to make the pages load faster.
I don’t know if you’ve seen the stats, but load time makes a big difference for user bounce rate. Cloudflare’s caching service does this on its global servers, which is a huge benefit if you get visitors from around the world.
It means that users in Australia (or wherever) can load a good amount of the site from a local server instead of having to drag it all from a server based in Boston, Massachusetts, or wherever else your site is being hosted. Believe it or not, but it actually takes time for data to travel a physical distance from the server to the user.
Configure Caching
To configure caching, go to caching and then configuration on the sidebar. Caching should be set to standard by default, but double-check that’s the case. You can also set your Browser Cache TTL here; this tells your users’ browser how often it should save assets locally.
Set Cache TTL to at least once per month, though you can adjust it to a more frequent setting if your site updates regularly.
The more clued-in you are, the more you may be wondering about Brotli compression. That’s the tool that compresses your site’s files so visitors can load everything faster, especially on slow connections. Well, the good news is that this is enabled by default. Cloudflare doesn’t even have a toggle for it these days.
Next, navigate to security and security settings on the sidebar. This is where you control things like bot access (which you may have already set when adding the site).
Vital security functions should be enabled by default, but double-check that things like:
- Network-layer DDoS attack protection
- Browser Integrity check
- And Email Address Obfuscation
Are all enabled.
There are a ton of useful tools in the security settings section, including many new tools that are designed to manage the various AI bots trawling the web.
Website security is a bit of a balancing act. You want to make your site as safe as possible, while not hampering usability, search rankings, or the functions of the site itself. The same applies to a lot of Cloudflare’s tools. There’s a bit of redundancy.
Personally, I’d start with the basics. The bare minimum. And explore the various tools as your site develops. Some more aggressive settings can change how the site loads, and may break things in the process. So always enable things one at a time, make sure you understand them before you enable them, and test your site immediately afterward.
Step 8: Test Your Website Through Cloudflare
Welcome to step eight. You’ve essentially done everything you need to do. So relax, breathe, and congratulate yourself on a job well done. With that being said, there is one more step, and you may have to take those congratulations back temporarily.
We need to test everything to make sure nothing was broken in the process. It’s better to find any errors now while the whole process is fresh in your mind, as it makes a fix easier to implement. It’s not just your sanity on the line. Broken sites tend to frustrate visitors, too.
Testing is pretty simple, but here are the extra steps:
- Make sure you clear your browser cache before testing your site, or use something like Chrome’s incognito mode.
This will stop an older version of your site from making the test inaccurate.
- Enter your site’s URL into the address bar (both with and without the www.) and see if it loads. Click through all of the pages, links, forms, and anything else your site uses.
You should also make sure HTTPS is working correctly.
- Look for a padlock to the left of the URL in your browser. Click on it, and check that the security certificate is both valid and issued by a Cloudflare-managed authority, like Google Trust Services, not Hostgator or cPanel.
If it’s the latter, your DNS changes haven’t propagated yet, or there’s an issue with the security certificate. You should also check that your site automatically redirects from HTTP to HTTPS.
Again, this is an easy one. Just make sure the start of the web address says “http://” and click enter. If everything is working properly that should automatically change to “https://”. Because we live in 2026 and it’s all about that extra security. You definitely don’t want a “This Site is Not Secure” warning popping up for new visitors.
If everything works and your site seems to load normally, then you can give yourself those congratulations back. If something did break, then don’t worry. We have your back in the next section. That’s where we troubleshoot the most common problems that occur when you’re setting up a HostGator site on Cloudflare.
Troubleshoot: Common Cloudflare and HostGator Issues
Do you remember back in Step 3 when we talked about checking the DNS records and making sure everything matched? Well, if you skipped that step or failed to spot an error, you’re probably wondering why your website is offline right now.
Luckily, HostGator’s copy of your DNS records and Cloudflare’s copy are both still there.
DNS Records
Go through again and make sure both records match. The only exception to the original records is the domain’s nameservers, which will now point to Cloudflare.
If DNS changes aren’t appearing at all, that’s probably because it’s all still propagating. Reminder, DNS propagation is usually instant, but it can take up to 48 hours in some cases. So give it a day or two to see if it resolves itself. Sometimes, patience is the easiest fix.
SSL Error (redirect loop)
If you’re noticing an SSL error (which commonly manifests as a redirect loop and subsequent ERR_TOO_MANY_REDIRECTS error), then something likely went wrong in Step Six. Head to Cloudflare’s SSL settings and make sure the correct SSL mode is selected for your site. You can also repeat all of Step Six if necessary.
Email Not Working
If your site has an email attached to it, and that email is no longer working, then there could be an issue with the MX record. It could be a case of Cloudflare messing up when importing the record, or simply not importing it at all.
To fix this, go to Cloudflare’s DNS Dashboard and make sure an MX record is present. If it isn’t, or it contains errors, you’ll have to copy over the record from HostGator.
Persistent Errors
Finally, if an error persists despite the changes you have made, it may just be a caching error. Caching reduces latency and server load, but also means the site you see may be drawing from older files. If an error seems to persist past a fix, clear both Cloudflare’s cache and your browser cache. This will force the site to load from the updated files and could fix the problem.
Your Website Is Now Protected by Cloudflare
Hopefully, none of this was too taxing, and (DNS proliferation aside) you can get the whole thing wrapped in well under an hour. It’s definitely worth the time as Cloudflare is a fantastic way to boost performance and security while vastly simplifying DNS management.
With that being said, this article barely scratches the surface. The free Cloudflare plan we used for this piece should be seen as an entry point, so take your time to explore more advanced professional and enterprise tools as your site grows:
- Security: custom WAF rules
- Performance: Argo smart routing
- Connectivity: private interconnects and WAN expansion
- Analytics: Log Explorer and 24/7 dedicated support
We have instructions on many of those features, along with easy-to-follow videos, on our social media channels and how-to guides. So, don’t forget to follow us and explore our site further with our smart tool, HostHelper™ chat. If you’re looking for guides on WordPress, website management, or hosting in general, we have you covered there too.
Want more options? If you’re in the market for a better host, check out or Best Cheap Hosts recommendations. Thank you for checking this article out. I hope you found it useful!
