PR
SERVER

Cloudflare × WordPress Complete Setup Guide [Updated for 2026]

Are you struggling with readers leaving your WordPress site because they feel it loads too slowly, or worried about server overload and potential downtime during traffic spikes? Before you consider upgrading to a higher-tier server plan, the most cost-effective and reliable solution you should try first is implementing Cloudflare.

Cloudflare is more than just a CDN (Content Delivery Network). Even with the free plan, you gain access to enterprise-grade features designed to make your WordPress site blazing fast and secure, including a global edge network, a powerful WAF (Web Application Firewall), state-of-the-art SSL/TLS encryption, and granular control over cache rules.

However, when it comes to actually implementing and configuring Cloudflare, many people run into obstacles—such as worrying that “changing the nameservers might cause the site to go down,” encountering “redirect loops (ERR_TOO_MANY_REDIRECTS)” that make the site inaccessible after setup, or finding that “caching affects the admin panel, preventing article updates”—and end up abandoning the project.

In this article, we’ll provide a complete, step-by-step guide to implementing Cloudflare on WordPress, based on settings and best practices used in real-world environments. From creating an account and migrating DNS to setting up caching rules and WAF configurations that maximize effectiveness, this article is designed to help you complete the setup without any confusion.

  1. The Overwhelming Benefits of Implementing Cloudflare on WordPress
    1. Dramatic Improvement in Page Load Speed via Edge Servers
    2. Significant Reduction in Origin Server Traffic and Backend Load
    3. Robust Security and WAF Available for Free
  2. Step 1. Creating a Cloudflare Account and Registering a Domain
    1. Steps to Create a Cloudflare Account
    2. Adding a Domain and Selecting the Right Plan
    3. Check Existing DNS Record Results
  3. Step 2. Switch Nameservers (DNS Migration)
    1. Change the nameservers to Cloudflare in your domain management panel
    2. Waiting for Changes to Take Effect and Verifying Status
  4. Step 3. Optimizing SSL/TLS Settings for WordPress
    1. Select “Full” or “Full (Strict)” as the encryption mode
    2. [Important] Implementing Cloudflare Origin Certificates to Simplify Operations
    3. Enabling “Always Use HTTPS”
  5. Step 4. Latest Cache Rules Best Practices
    1. What is the difference between Page Rules and Cache Rules?
    2. Creating bypass rules to exclude admin functions and logged-in users
    3. Creating a rule to aggressively cache dynamic HTML pages
  6. Step 5. Recommended Settings for WAF and Security Rules
    1. Rule to Block Unnecessary Access to `xmlrpc.php`
    2. Impose restrictions on access to the admin panel from overseas
  7. Step 6. Integration with the Official Cloudflare Plugin
    1. Configuring the API Key and Applying Default Optimizations
    2. Automatic Cache Purge (Clear) Feature When Updating Posts
    3. If you’re aiming for even greater performance, consider implementing APO
  8. Common Issues When Implementing Cloudflare and How to Fix Them
    1. ERR_TOO_MANY_REDIRECTS (Redirect Loop)
    2. Mixed Content Causing Layout Breakage
  9. Frequently Asked Questions (FAQ)
    1. What features of Cloudflare are available for free?
    2. I made minor adjustments to the design, but they aren’t showing up. How do I clear the cache?
  10. Summary

The Overwhelming Benefits of Implementing Cloudflare on WordPress

Before diving into the specific setup steps, let’s first outline the core mechanisms and benefits of Cloudflare to understand why it’s adopted by so many WordPress sites. Grasping this will help you better understand the necessity of the detailed configurations that follow.

Dramatic Improvement in Page Load Speed via Edge Servers

When you implement Cloudflare, “edge servers” located around the world (including multiple locations within Japan, such as Tokyo and Osaka) act as a proxy in front of your origin server, delivering your website’s data to visitors on your behalf.Not only static resources such as image data, CSS, and JavaScript, but also HTML data—which is normally generated on the server side each time—can be returned directly and quickly from edge servers if caching rules are set appropriately. This dramatically reduces page load times (TTFB: Time to First Byte) for readers, providing a comfortable browsing experience.

Significant Reduction in Origin Server Traffic and Backend Load

When edge servers return cached content, it means that the number of access requests reaching the underlying origin server (such as a shared hosting server or VPS) is drastically reduced.Since the number of PHP executions—which are central to WordPress’s operation—and the number of queries issued to the database (such as MySQL or MariaDB) are significantly reduced, the server’s CPU and memory load drops dramatically. Even during large-scale traffic spikes or sudden viral surges (so-called “traffic bombardment”), the risk of server downtime can be effectively mitigated.

Robust Security and WAF Available for Free

Due to its overwhelming popularity, WordPress is inevitably a prime target for brute-force attacks via bots from around the world, as well as attacks exploiting known vulnerabilities in plugins. By using Cloudflare as a cloud-based defense barrier, the majority of malicious traffic and DDoS attacks involving massive traffic volumes are blocked at the edge server level, ensuring that only legitimate access from genuine users reaches the origin server.

Step 1. Creating a Cloudflare Account and Registering a Domain

Now, let’s move on to the actual setup procedure. The first step is to sign up for Cloudflare and register the domain you want to manage and protect.

Steps to Create a Cloudflare Account

First, visit the official Cloudflare website and create a new account. You can either set up a unique email address and password, or sign up by linking your existing Google Account. After registration, a confirmation email will be sent to the address you provided. Be sure to click the link in the email to verify your account first.

Adding a Domain and Selecting the Right Plan

After logging into the dashboard, click the “Add Site” button. Enter the domain name of the WordPress site you want to manage (in a format that does not include subdomains, e.g., madoromi.org). On the next screen, you will be asked to select a pricing plan. For personal blogs or standard corporate websites, start by selecting the “Free” plan at the bottom.Even with the Free Plan, you can fully benefit from features such as CDN, SSL, and caching rules. If you need more advanced features like WAF or dedicated analytics in the future, you can simply consider upgrading to the Pro Plan at that time.

Check Existing DNS Record Results

Once you select a plan, Cloudflare will scan your domain’s current DNS settings and automatically import them. After the scan completes, a list of A records, CNAME records, MX records, and others will be displayed. At this stage, be sure to verify that the IP addresses displayed are associated with the server you are currently using.Also, verify that the “Proxy Status” (cloud icon) for your WordPress domain is orange (Proxied). If it remains gray (DNS Only), Cloudflare’s CDN and WAF features will not function, so be sure to click it to turn it orange. We strongly recommend taking a screenshot or otherwise backing up the list of your current records in advance, just in case you need to revert the changes later.

Step 2. Switch Nameservers (DNS Migration)

Once you have verified and corrected the DNS records, you will proceed to the “Change Nameservers” step, which is the most critical part of the Cloudflare setup process. This ensures that all global traffic to your domain will now route through Cloudflare.

Change the nameservers to Cloudflare in your domain management panel

You will see two “Cloudflare nameservers” (e.g., anna.ns.cloudflare.com and bob.ns.cloudflare.com) displayed on the Cloudflare screen. Copy these and keep them handy. Next, log in to the management console of the service where you registered and manage your domain (e.g., Onamae.com, XDomain, MuuMuu Domain, etc.). Open the “Name Server Settings” screen for the relevant domain, delete the current name server information specific to your service provider, replace it with the two Cloudflare name servers you copied earlier, and save the changes.

Waiting for Changes to Take Effect and Verifying Status

It may take anywhere from a few minutes to several hours, or up to 48 hours depending on your environment, for the changes to your nameserver settings to propagate across the internet.Return to the Cloudflare dashboard, click the “Verify Nameservers” button, and wait for the status of the target domain to change from “Pending” to “Active.” While your site generally won’t go down (experience downtime) during this transition period, we recommend using your browser’s incognito mode to verify that the switch was successful.

Step 3. Optimizing SSL/TLS Settings for WordPress

Once the site status changes to “Active,” review the SSL/TLS settings to ensure communication is properly encrypted. This is the step where mistakes are most likely to occur when setting up Cloudflare for WordPress, and it is the primary cause of “redirect loops.”

Select “Full” or “Full (Strict)” as the encryption mode

Open “SSL/TLS” from the left-hand menu in the Cloudflare dashboard. Several options will be displayed under “Encryption Mode.” If your origin server is already configured to support “https://” communication, select an option based on the following guidelines: ・”Full”: If the origin server uses a self-signed certificate or similar. ・”Full (Strict)”: If the origin server uses a public SSL certificate such as “Let’s Encrypt” or a “Origin Certificate” issued by Cloudflare. Since Let’s Encrypt is commonly used in production environments, selecting “Full (Strict)” is the most secure best practice. If you carelessly select “Flexible” here, communication from Cloudflare to the origin server will be unencrypted (HTTP). Since WordPress will attempt to redirect to HTTPS, an infinite loop of “HTTP→HTTPS” requests will occur (resulting in an ERR_TOO_MANY_REDIRECTS error), rendering the site inaccessible.

[Important] Implementing Cloudflare Origin Certificates to Simplify Operations

If you are using “Let’s Encrypt” in a production environment, you need to be cautious about future operations. If you leave Cloudflare’s proxy feature (the orange cloud) enabled, the communication required for Let’s Encrypt’s automatic renewal (domain authentication process), which occurs every three months, will be blocked by Cloudflare, resulting in a high probability of renewal failure (error). The most reliable and cost-effective solution to prevent this is to install the “Origin Certificate”—which can be issued for free via the Cloudflare dashboard—on your server. Since this certificate can be set to expire after a maximum of “15 years,” once implemented, you will be freed from the hassle of regular certificate renewals for an extended period.

Enabling “Always Use HTTPS”

Next, open the “Edge Certificates” tab in the same menu and toggle “Always Use HTTPS” on. This ensures that even if a reader accidentally accesses the site using the old http:// URL format, Cloudflare will automatically redirect them to the secure, encrypted https:// connection.

Step 4. Latest Cache Rules Best Practices

The true value of Cloudflare lies in its flexible cache control. While settings were previously configured using a feature called Page Rules, it is now recommended to use “Cache Rules,” which allow for more complex and sophisticated conditional logic.

What is the difference between Page Rules and Cache Rules?

Traditional Page Rules were based on simple pattern matching using URL wildcards, but the free plan had an extremely strict limit of only three rules.With the new Cache Rules, you can control caching behavior by freely combining complex conditions—such as the presence of cookie data, HTTP request header information, and query parameters—rather than relying solely on URL patterns. The limit on the number of rules has also been increased (10 rules are available even on the free plan), enabling detailed and practical caching management tailored to the specific characteristics of WordPress.

Creating bypass rules to exclude admin functions and logged-in users

This is the most important rule you should set up first. While you want to actively cache WordPress’s front-end pages, applying caching to the admin panel (dashboard) or logged-in users can cause serious issues, such as preventing you from seeing updates you’ve made to posts or causing admin functions to malfunction. Therefore, a conditional rule to intentionally “bypass” caching is essential. Open “Cache Rules” under “Cache” in the left-hand menu, and click the “Create Rule” button to create a single top-priority rule with the following settings.

  • Rule Name: Bypass WP Admin and Logged in
  • Condition: Set the following in “Edit Custom Rule Expression”
  • (Use AND or OR to specify multiple conditions)
  • ・Field: “URI Path” / Operator: “Contains” / Value: “wp-admin”
  • ・(OR) Field: “URI Path” / Operator: “Contains” / Value: “wp-login.php”
  • ・(OR) Field: “Cookie” / Operator: “Contains” / Value: “wordpress_logged_in”
  • Cache Status: Select “Bypass”

This rule ensures that caching is completely disabled for users accessing the WordPress admin directory or those with specific cookies that manage login status, allowing them to safely use the backend administrative functions.

Creating a rule to aggressively cache dynamic HTML pages

After ensuring the exclusion rules are properly configured, we will now create a rule to cache the entire frontend page viewed by general readers. Add a new rule so that it appears “below” the bypass rule mentioned above.

  • Rule Name: Cache WP Frontend Everything
  • Field: “URI Path” / Operator: “Contains” / Value: “/”
  • Cache Status: Select “Eligible for cache”
  • Edge TTL: Select “Custom” and set an automatic or arbitrary duration (e.g., a few hours to about a week)
  • Browser TTL: Respect existing headers (or set to a few hours)

With this configuration, dynamic HTML output—which would normally be processed and generated by WordPress’s PHP through database interactions—will be cached on Cloudflare’s edge servers for an extended period, just like static files such as images. This proves extremely powerful, delivering astonishing response speeds and significantly reducing server load.Be sure to pay attention to the order of the rules and maintain the correct priority so that, even after reloading the Cloudflare interface, the hierarchy remains “1. Bypass Rules” → “2. Full Cache Rules” from top to bottom.

Step 5. Recommended Settings for WAF and Security Rules

Let’s also optimize Cloudflare’s security features, another key strength of the platform. Open “WAF (Web Application Firewall)” from the “Security” menu and create your own custom rules to proactively prevent and dramatically reduce the troublesome attacks specific to WordPress.

Rule to Block Unnecessary Access to `xmlrpc.php`

`xmlrpc.php`, one of WordPress’s system files, is used for external app integration and pingbacks. However, it has become a hotbed of vulnerabilities that are frequently targeted—either for brute-force attacks where bots relentlessly guess passwords or as a stepping stone for DDoS attacks. If you do not use remote posting from smartphone apps (such as the official WordPress app) or the Jetpack plugin, it is strongly recommended that you completely block access at the WAF level.

  • Rule Name: Block XMLRPC
  • Field: “URI Path” / Operator: “Equals” / Value: “/xmlrpc.php”
  • Action: Block

Impose restrictions on access to the admin panel from overseas

If you perform administrative tasks—such as updating WordPress posts—exclusively from your own environment within Japan, you can significantly reduce the risk of account takeover by restricting direct communication to the `wp-admin` management path from overseas (foreign) IP addresses. By setting up an action to execute a “Managed Challenge” (a non-automated, human verification process in the browser using Turnstile) for requests that meet the AND condition of originating from a country “other than” Japan and containing the URI path `/wp-admin`, you can create a robust security barrier without compromising legitimate user convenience.

Step 6. Integration with the Official Cloudflare Plugin

This completes the dashboard configuration on the Cloudflare side. As a final step, install the official “Cloudflare Plugin” in the WordPress admin panel and complete the integration using the API.

Configuring the API Key and Applying Default Optimizations

In the WordPress “Plugins > Add New” screen, search for “Cloudflare,” install it, and activate it. Go to the plugin settings screen, then sign in by entering the “Global API Key” (which you can obtain and verify under “My Profile > API Tokens” via the account icon in the top-right corner of Cloudflare) and your registered email address.After logging in, simply click the “Apply Default Settings” button on the screen, and the detailed base settings for WordPress operation will be automatically and accurately applied to Cloudflare.

Automatic Cache Purge (Clear) Feature When Updating Posts

The biggest reason and benefit for installing this official plugin is its integration feature that automatically deletes (purges) “old cache” remaining on the relevant Cloudflare edge server when you write and publish a new post or save a rewritten version of an existing post.This prevents the common pitfall of caching—where “even though you’ve added brand-new information to an article, the cache is too persistent, causing readers to continue seeing outdated information”—and ensures that the latest content is always delivered.

If you’re aiming for even greater performance, consider implementing APO

While the free caching control features alone offer more than enough speed improvements, if you’re aiming for even higher levels of performance, consider implementing the paid option “Automatic Platform Optimization (APO)” ($5 per month). APO uses logic specifically tailored for WordPress to fully automate the minimization of TTFB and handle improvements like web font loading, allowing you to achieve blazing-fast performance without having to write detailed manual rules.

Common Issues When Implementing Cloudflare and How to Fix Them

Even if you think you’ve successfully completed the setup, you may encounter unexpected errors, such as a blank page or severe layout breaks. Here, we’ll cover solutions for two common issues that we receive a high volume of support requests for.

ERR_TOO_MANY_REDIRECTS (Redirect Loop)

This is an error where the browser displays a message stating “Too many redirects,” rendering the entire site inaccessible. As noted in Step 3 of this article, this is almost certainly caused by SSL settings. Return to the Cloudflare SSL/TLS settings page and change the encryption mode from “Flexible” to “Full” or “Full (Strict)” to immediately restore normal functionality.

Mixed Content Causing Layout Breakage

If the page itself displays but CSS files are not applied at all, resulting in a broken, text-heavy screen, or if numerous image links are broken, this indicates a “Mixed Content” issue where old HTTP (unencrypted) URLs are mixed within an HTTPS-protected page, causing the browser to block them for security reasons. Open the “Edge Certificates” tab in Cloudflare’s SSL/TLS settings and enable both the “Always Use HTTPS” and “Automatic HTTPS Rewrites” toggles. This will allow Cloudflare’s edge servers to automatically detect these links and force them to be converted to a secure format.

Frequently Asked Questions (FAQ)

What features of Cloudflare are available for free?

All essential features for running a typical small-to-medium-sized personal blog or small business website—including CDN, free SSL certificates, DDoS protection, and a sufficient number of Cache Rules and custom WAF rules—are available for free indefinitely. You’ll get more than your money’s worth if you wait to upgrade to a paid plan until you reach a stage where you need advanced image optimization features, detailed analytics, or more robust business-level support.

I made minor adjustments to the design, but they aren’t showing up. How do I clear the cache?

If you’ve replaced the theme’s CSS files or logo image but the new changes aren’t showing up in your browser, it means old data is being strongly cached in Cloudflare’s edge network.You can force the clearing of cached data worldwide within a few seconds by manually clicking “Purge Everything” under “Purge Cache” in an official plugin installed via the WordPress admin panel, or by clicking “Purge Cache” → “Purge All” in the top right corner of the Cloudflare dashboard. This will restore the page to its latest origin state.


Summary

The combination of Cloudflare and WordPress can be considered the “optimal solution” in the current environment for handling large volumes of traffic requests to prevent downtime, countering security threats, and maximizing site loading speed. Let’s review the key steps of the setup process once again.

  1. Create a Cloudflare account and migrate your nameservers as instructed
  2. To prevent infinite redirects, set the SSL encryption mode to “Full” or “Full (Strict)”
  3. Use Cache Rules to cache the HTML itself while excluding logged-in users
  4. Utilize the WAF feature to block the vulnerable “xmlrpc.php” file and solidify the foundation for proactive defense
  5. Install the official plugin to fully automate cache purging upon article updates

By carefully following these steps in order, you can easily obtain a robust and blazing-fast server infrastructure—one that would otherwise require a very expensive premium server plan to maintain. While the initial setup involves some learning curve, once the configuration is complete, your daily operational workload will be dramatically reduced. We encourage you to use this guide as a starting point to take the first step toward implementing Cloudflare.

Comment

Copied title and URL