Skip to main content

Connect a domain through your own Cloudflare

If the domain's zone is already in your own Cloudflare account and you want to keep it there, connect the domain with the Through my Cloudflare option. Qubix doesn't ask for the key to your Cloudflare account and doesn't change the zone's settings: you point the domain at the server and turn on a few settings in Cloudflare yourself. Visitors reach the server through your Cloudflare: the domain's record stays proxied (the orange cloud).

When to choose this option​

  • The domain's zone is in your Cloudflare account, and you don't want to give Qubix a key to it.
  • If you're ready to save a key to that account in Qubix, you can keep the zone in your account with Option A — Via Cloudflare instead: save the key as your personal key and pick it in the Cloudflare account picker. Then Qubix sets the zone up itself — and changes the settings of the whole zone: the encryption mode, Always Use HTTPS, the minimum TLS version, caching and Authenticated Origin Pulls. If other sites of this zone need different settings, choose Through my Cloudflare.
  • If the domain should be served without proxying (the gray cloud), connect it with your own DNS.

All the ways to connect a domain are compared in Connect an existing domain.

Before you start​

  • Access to the domain's zone in your Cloudflare account. You will add a DNS record, change two SSL/TLS settings and, sometimes, create a rule.
  • The right to set up domains in Qubix. Without it, the Add domain menu has no Connect your own domain item.
  • The Via Cloudflare method among the Connection methods of your access template. Without it, the window doesn't offer Through my Cloudflare — ask the administrator. The other cases when this option isn't offered are listed after Step 1.

No Cloudflare key is needed.

Step 1. Connect the domain in Qubix​

  1. Open Domains, click Add domain and choose Connect your own domain.
  2. Enter the domain (for example, mygames.click) and click Check.
  3. On the Through my Cloudflare card, click Via your Cloudflare.
  4. The window shows the steps under In your Cloudflare account, with the domain, the server's address and, when needed, the port already filled in. Keep it open: the Check connection button is under the steps.

In the Desktop look, the Add domain button opens a wizard: on the What we add step choose Connect your own domain and at least one domain role, on Domain name enter the domain, on Traffic delivery choose Through my Cloudflare, and on Review click Connect. The wizard's last screen shows the same steps and the same button.

Which options the window offers depends on the domain:

  • a domain that is served through a Cloudflare zone Qubix manages doesn't get Through my Cloudflare;
  • a domain already connected through your own Cloudflare whose first check hasn't passed yet gets only this option — choosing it again brings back the steps and the check button;
  • a domain connected through your own Cloudflare that has already passed a check gets no options: the window says This domain is already added. Manage it on the domain card.

Step 2. Set up the zone in your Cloudflare account​

Do what the window lists, in the Cloudflare dashboard of the account that holds the domain's zone. The window fills in the domain, the server's address and the port; below they are mygames.click, 203.0.113.10 and 8443.

  1. DNS record. DNS → Records: an A record for mygames.click with the address 203.0.113.10, proxy status Proxied (orange cloud).
  2. Encryption mode. SSL/TLS → Overview: encryption mode Full — not Flexible and not Full (strict).
  3. Authenticated Origin Pulls. SSL/TLS → Origin Server → Authenticated Origin Pulls: turn on the switch in the Global section. You do not need to upload a certificate. This is how the server knows a request really came through Cloudflare, so it can trust the visitor's country and address.
  4. Port rule — only if the window shows this step. Rules → Origin Rules: create a rule for mygames.click that sets Destination Port to 8443. This server receives Cloudflare on port 8443; without the rule Cloudflare comes to port 443. When the server's port is 443, the window has no such step and no rule is needed.

The port is one for the whole server; the administrator sets it in the Cloudflare origin port section — see Panel domain.

The encryption mode is set for the whole zone

The mode on the SSL/TLS → Overview page applies to every site of the zone. If other sites in this zone need a different mode, leave it as it is and set Full only for this domain with a rule: Rules → Configuration Rules, a rule for the domain with the SSL setting Full.

Visitors who open the domain over http

Also turn on SSL/TLS → Edge Certificates → Always Use HTTPS, or create a redirect to https for this domain only. Otherwise a visitor who opened the address over http may get an error page instead of the site. The check won't show this: it only sends requests over https.

Step 3. Check the connection​

Click Check connection. Qubix sends a request to the domain through Cloudflare and checks that it reached this server.

  • If it did, the window says Ready: requests through your Cloudflare reach this server.
  • If not, the window names the reason — see What the check says. Fix what it names in Cloudflare and click the button again.

You don't have to keep the window open: Qubix checks such domains by itself every 5 minutes. Each round of checks is limited in time, so when there are many such domains, some of them are checked in one of the following rounds. Until a check passes:

  • in the list, the NS / CF column shows Awaiting check; once a check has named a reason, it is in the hint next to the status;
  • in the Desktop look, the domain sits in the Awaiting check group, and its card shows the same status in the Nameservers row;
  • the domain isn't offered when you choose a domain for a campaign.

When a check passes, the column shows Ready, in the Desktop look the domain moves to Working, and you can use it in campaigns.

Until the first check passes, you can get back to the steps and the button by opening the connect window for this domain again: Add domain → Connect your own domain.

What the check says​

The window and the hint in the list fill in the domain, the server's address and the server's port; below they are mygames.click, 203.0.113.10 and 8443.

The window saysWhat to do
Ready: requests through your Cloudflare reach this server.Nothing: the domain is ready.
mygames.click does not resolve yet. Add the A record from step 1.The domain has no A record yet, or the record hasn't spread through DNS yet. Create the record from step 1, then check again.
The record points straight at this server with a grey cloud. Turn the proxy on (orange cloud).The record points at the server's address with proxying off, so requests bypass Cloudflare. Turn the orange cloud on for the record.
Requests through Cloudflare reach another server. Check that the A record has the address 203.0.113.10.The record leads to another address. Put the server's address from the message into the A record.
Cloudflare did not present its certificate. Turn on Authenticated Origin Pulls in the Global section (step 3).Authenticated Origin Pulls is off. Turn on the switch in the Global section.
Cloudflare presented a certificate you uploaded instead of its own. Use the Global switch, not a zone-level certificate (step 3).A certificate is uploaded for the zone in Authenticated Origin Pulls. Use the Global switch instead.
Encryption mode is Full (strict), and Cloudflare does not accept this server's certificate. Switch it to Full (step 2).Switch the encryption mode to Full.
Encryption mode is Flexible, so Cloudflare connects to the server without encryption. Switch it to Full (step 2).Switch the encryption mode to Full.
Cloudflare comes to port 443, but this server expects it on port 8443. Create the rule from step 4.Create the Origin Rules rule with the port from the message.
Cloudflare could not connect to this server. Go through the steps above, starting with the encryption mode.Cloudflare could not connect to the server at the address in the record. Check the address in the A record (step 1), the port rule if the window shows step 4, and the encryption mode (step 2).
Port 8443 of this server cannot be reached from the internet. This is a server setting, not a Cloudflare one: open the port or contact the server administrator.The server's port for Cloudflare is closed from the outside. It is opened on the server, not in Cloudflare — see Panel domain.
Cloudflare does not have a certificate for mygames.click yet. Wait a little and check again.Cloudflare hasn't issued its certificate for the domain yet: wait and check again. If the domain is a subdomain two or more levels deep (for example, promo.shop.example.com), waiting won't help: Cloudflare's free certificate covers only the zone's own name and its first-level subdomains. Such a name needs a certificate ordered or uploaded in your Cloudflare — Advanced Certificate Manager or a custom certificate.
The check did not reach this server: Cloudflare answered with code 1020. Go through the steps above once more.Cloudflare answered the check itself with the code shown — for example, a security rule or bot protection in your Cloudflare stopped the request. The check is a request from this server's address to a path starting with /.well-known/qubix-origin-check/; add an exception for it in the rules of your zone.
The server could not run the check. Try again later.The server could not run the check this time. Click the button again later — or wait for the next automatic check.

After the domain is ready​

A domain connected through your own Cloudflare has no buttons and no connection-method switch in its row: instead, it shows Via your Cloudflare, with a hint that the zone is in your Cloudflare account and Qubix doesn't change it. In the Desktop look, the card shows the same in the Serving row and has no Set up CF button.

The zone stays yours: its records and settings are changed in your Cloudflare account. If you've saved a key to this account in Qubix as your personal key, you can also view and edit the zone's records on the domain's DNS tab — see DNS records.

Qubix keeps checking the domain​

Every 5 minutes Qubix checks ready domains through Cloudflare again; each round is limited in time, so when there are many such domains, some of them are checked in one of the following rounds. The recheck looks for one thing — whether the domain's record still leads to this server: the record is gone, requests reach another server, or Cloudflare can't connect to the address in the record. Qubix counts such checks until one of them succeeds; a restart of Qubix starts the count over. When there are three of them and at least 10 minutes have passed since the first, the domain goes back to Awaiting check with the reason “Requests through Cloudflare reach another server. Check that the A record has the address …” and the server's current address. A single Cloudflare hiccup doesn't set the domain back.

  • The domain keeps serving the visitors who reach it; it just isn't offered for new campaigns until a check passes again.
  • One message about it goes to the Telegram chat assigned to the Cloudflare role — see Connections.
  • When a check passes again, the domain works as before. No message is sent about that.

Changes to other settings of the zone — for example, the encryption mode or Authenticated Origin Pulls — the recheck may not notice: the domain then stays Ready, and no message is sent. A ready domain has no check button, neither in the list nor in the card, so after changing the zone's settings, open the site yourself to make sure it works.

If the server moves or its port changes​

  • New server address. Change the address in the domain's A record in your Cloudflare: Qubix doesn't change the zones of domains connected this way, even if a key to the account is saved. When the main Cloudflare key is saved in Qubix settings → Connections → Cloudflare, the Update the address and re-apply button there updates the zones Qubix manages and lists the domains connected through your own Cloudflare separately, with the address to set.
  • New port for Cloudflare. Qubix doesn't change the rule in your Cloudflare. When the administrator chooses a new port in the Cloudflare origin port section (Panel domain), the section lists these domains. The server moves to the new port at once, and until their rule matches it, these domains may stop opening — so the owners of these domains should be warned before the change. Moving from 443 to another port — create the rule from step 4; from one port other than 443 to another — change the port in the rule; back to 443 — delete the rule.

Limits and refusals​

The connection method isn't changed from Qubix. For such a domain Qubix refuses Set up CF, connecting it through Cloudflare or with your own DNS, the method switch, the zone setup by the assistant under the main key or a company key, moving the panel onto this domain and buying this name. To those allowed to perform the action, all of them answer with the same message: “This domain's zone is in your own Cloudflare account, so the domain cannot be moved to our Cloudflare from here. Delete it and connect it again.” With your personal key — saved or pasted into the chat — the assistant works in your own Cloudflare account and, once you approve, sets up the zone; in proxy mode this changes the settings of the whole zone.

To move the domain to another option, delete it in its card and connect it again. Qubix won't delete a domain that an active campaign still uses — free it there first (see Domain settings). Until you connect it again, the domain isn't served.

When you connect, Qubix may refuse:

  • “This domain is already live on this server. Only a new domain, or one whose connection has not finished, can be connected through your Cloudflare.” — the domain already works on this server with another option.
  • “This domain, its parent domain or one of its subdomains is already on our Cloudflare, so it cannot be connected through your Cloudflare. Connect it with “Through Cloudflare” instead.” — the zone of this name, of its parent domain or of one of its subdomains is in Qubix's Cloudflare account. Connect the domain with Option A — Via Cloudflare.
  • “Domain mygames.click is not available to you: you do not have rights to it. If you need it, ask an administrator.” — the domain is recorded in Qubix under another person, or its zone in Qubix's Cloudflare account isn't linked to your domains. Ask the administrator.

What's next​