Cloudflare, CDN & Edge

Cloudflare for Indian Websites — The Setup That Actually Pays Off

By Domain India Team · DomainIndia EngineeringPublished 19 min read
Knowledge base article
Contents (17 sections)

Verdict at the top: If your website has a meaningful Indian audience, put Cloudflare in front of it. The free tier caches static content at edge locations inside India, absorbs most automated attack noise, and gives you free edge SSL plus free Cloudflare Origin Certificates for the connection back to your server. The benefit is largest when your hosting server is far from your visitors, because every uncached request has to travel that distance. The paid tiers (Pro, from about $20-25/month, and Business, from about $200-250/month, depending on annual or monthly billing) are worth it for the specific cases this guide names; if those don't apply, the free plan is genuinely sufficient.

Key takeaways

Cloudflare = global CDN + DDoS protection + DNS + free SSL. Indian visitors are served from Cloudflare edge locations in Indian cities such as Mumbai, Chennai, Delhi, Bengaluru, Hyderabad and Kolkata, so cached files arrive in a few milliseconds instead of making a long trip to a distant origin server. The free plan covers most small-business needs. Get the SSL mode right (Full (strict) + a valid origin certificate), don't proxy mail records, and don't put the orange cloud on services that aren't HTTP. Workers, D1, R2 and Pages are bonus features worth using when they fit.

The latency math, with real numbers

Every request that your hosting server answers directly pays one full network round trip between the visitor and the server. The further apart they are, the longer that trip. The numbers below are typical ranges for Indian broadband, used to illustrate the effect; your own results depend on your ISP and on where your origin server sits.

PathTypical RTT (India broadband → endpoint)What this means in practice
India → an origin server in Europe (no Cloudflare)130-180 msEvery request to the site pays this round-trip
India → an origin server in India (no Cloudflare)20-50 msShorter trip, but still no caching or DDoS shield
India → Cloudflare Mumbai (BOM) edge5-15 msCache-hit responses served from the edge
Cloudflare edge → distant origin110-140 msOnly happens on cache miss / dynamic requests

For a typical WordPress page that has ~30 sub-resources (CSS, JS, images, fonts), the difference is significant. With a distant origin and no Cloudflare, every sub-resource pays the full round trip, and the page can take 3-4 seconds to become interactive on Indian broadband. With Cloudflare proxying, static sub-resources come from an Indian edge in a few milliseconds, and the same page often becomes interactive in 1-1.5 seconds.

It's the difference between "this site feels sluggish" and "this site feels fast" for Indian users, and it's the single biggest perceived-performance win you can apply without changing anything in your application. If you don't know where your hosting server is, a ping or traceroute to your site from India gives you a good idea; you can also ask our support team.

What Cloudflare actually gives you on the free plan

  • Global CDN — 330+ cities worldwide, including several in India: Mumbai (BOM), Chennai (MAA), Delhi (DEL), Bengaluru (BLR), Hyderabad (HYD) and Kolkata (CCU).
  • Free Universal SSL — a Cloudflare-managed certificate at the edge, auto-renewing, covering your apex domain and first-level subdomains. Plus Cloudflare Origin Certificates — a free certificate, valid for up to 15 years, that you install on your origin server so the Cloudflare → origin leg is also encrypted.
  • Unmetered DDoS protection — Layer 3/4/7 mitigation. Cloudflare doesn't charge extra for this, even on the free plan.
  • Performance features — Brotli compression, HTTP/3 (QUIC), Early Hints.
  • Basic WAF — free managed rules for high-impact vulnerabilities, plus Bot Fight Mode to block much of the simple automated scraping.
  • DNS — fast authoritative DNS, free, with API control.
  • Analytics — requests, bandwidth, threat events, cache-hit ratio.
  • Rules — Cache Rules, Redirect Rules and Configuration Rules (the modern replacements for Page Rules), with a free allowance on every plan.
  • Workers — 100,000 requests/day free, then $5/month for 10M.
  • Pages — static-site hosting with unlimited requests on the free plan, including for commercial sites.

The paid tiers add features many sites don't need:

  • Pro — Polish image compression, more WAF managed rules, more rules per zone. Worth it for sites with image-heavy traffic.
  • Business — an uptime SLA from Cloudflare, custom WAF rules, prioritised support, a higher upload limit (200 MB). Worth it for revenue-critical sites.
  • Enterprise — quote-based; full custom contracts, dedicated support engineers, regulatory compliance options. Out of scope for this article.

Setting it up — 30 minutes end-to-end

Step 1 — Add the domain to Cloudflare

  1. Sign up
    at cloudflare.com (free).
  2. Add your domain
    (e.g. yourcompany.com, no www).
  3. Choose the Free plan.
  4. Cloudflare scans your existing DNS.
    This scan misses records sometimes — open the DNS zone editor wherever your DNS is managed today (your cPanel, DirectAdmin or Plesk zone editor if you use your hosting nameservers), compare every record, and manually add anything missing. The most common omissions: _dmarc TXT, DKIM TXT records, _acme-challenge TXT (if you use external SSL automation), and MX records for non-default mail providers.
  5. Cloudflare assigns two nameservers
    to your account, e.g. alice.ns.cloudflare.com and bob.ns.cloudflare.com. Note them.

Step 2 — Change nameservers at Domain India

Before changing nameservers, note down your current ones. They are shown on the domain's Nameservers tab in the client area. If anything goes wrong, you can put them back.

  1. Sign in
    to the client area.
  2. Open Domains → My domains
    and select the domain.
  3. Open the Nameservers tab
    and click Edit.
  4. Replace the current entries
    with the two Cloudflare nameservers, exactly as Cloudflare shows them.
  5. Click Save.
    The client area confirms "Nameservers updated".

The change usually takes effect within a few hours and can take up to 24-48 hours to reach every network. Cloudflare emails you when the domain is active. For the full walkthrough, including how to check the change, read How do I change my nameservers. If the domain is registered with another company, change the nameservers there instead.

Step 3 — Configure SSL (the most-misconfigured step)

Cloudflare offers four main SSL modes:

ModeEdge ↔ visitorCloudflare ↔ originVerdict
OffHTTPanyDon't use
FlexibleHTTPSHTTPRisky — visitors trust the lock icon, but origin traffic is plaintext
FullHTTPSHTTPS (any cert, including self-signed)Acceptable
Full (strict)HTTPSHTTPS (valid cert)Best — use this

Always use Full (strict). Two ways to get a valid origin cert:

Path 1 — the free SSL included with your hosting. Domain India hosting includes free SSL: AutoSSL/Let's Encrypt on cPanel, and Let's Encrypt in DirectAdmin and Plesk. Check in your control panel that a valid certificate is installed for the domain and www.

Path 2 — Cloudflare Origin Certificate (recommended). In Cloudflare → SSL/TLS → Origin Server → Create Certificate. It generates a certificate (wildcard if you choose) valid for up to 15 years, trusted only by Cloudflare, not by browsers. Install it on your origin server; in cPanel, use the SSL/TLS page. Why this is often better than Let's Encrypt behind Cloudflare: no 90-day renewals to go wrong. The trade-off: anyone who reaches your origin directly, bypassing Cloudflare, sees a certificate browsers don't trust, so only use it for hostnames that stay orange-clouded.

Then enable, in SSL/TLS → Edge Certificates:

  • Always Use HTTPS = On
  • Automatic HTTPS Rewrites = On
  • Minimum TLS Version = TLS 1.2 (or 1.3 if all your visitors are modern browsers)
  • HSTS — enable carefully, with a 6-month max-age first; once confirmed all subdomains have certs, ramp to 12 months + preload.

Step 4 — Tune caching

Cloudflare caches static assets (images, CSS, JS) by default. HTML is not cached unless you tell it to.

For brochureware / blog sites (mostly cacheable HTML):

  • Caching → Configuration → Browser Cache TTL = 4 hours
  • A Cache Rule for your hostname → Eligible for cache, Edge TTL 2 hours
  • Mandatory — a second Cache Rule, placed first: URI path starts with /wp-admin or /wp-login.php (or your admin path) → Bypass cache. Also bypass when a WordPress login or WooCommerce cart cookie is present. Without this, logged-in admins see stale content and wonder what's wrong.

For dynamic sites (e-commerce, dashboards, anything with sessions):

  • Leave HTML uncached. Let Cloudflare cache only static assets (its default).
  • Use Cache-Control headers in your application code for fine control.
  • Use Cache Rules for path-based exceptions. Older setups use Page Rules, which Cloudflare is replacing with Rules.

Step 5 — DNS records — what to proxy and what not to

In Cloudflare DNS, each record has an "orange cloud" (proxied through Cloudflare) or "grey cloud" (DNS-only).

Orange cloud (proxy on):

  • @ (apex) → your origin IP, proxy on
  • www → your origin IP, proxy on
  • Any subdomain serving HTTP/HTTPS to end users (e.g. app.yourcompany.com)

Grey cloud (DNS only — proxy off) — these break things if proxied:

  • mail.yourcompany.com — IMAP/SMTP traffic isn't HTTP; Cloudflare can't proxy it.
  • cpanel.yourcompany.com, webmail.yourcompany.com — control panel access; the free plan's 100 MB upload limit breaks large uploads, and panel logins behave oddly behind a proxy.
  • The hostnames your MX records point to — mail servers don't speak HTTP.
  • FTP / SFTP / SSH endpoints (e.g. ssh.yourcompany.com) — non-HTTP protocols, Cloudflare can't help.
  • _dmarc, _acme-challenge, SPF and DKIM (TXT records) — these are text records; "proxy" doesn't apply.
  • A subdomain pointing to a different host you don't want exposed via Cloudflare.

A common mistake: a customer enables Cloudflare, the mail hostname gets orange-clouded, and mail stops flowing because the MX target (mail.yourcompany.com) now resolves to a Cloudflare proxy that doesn't handle SMTP. Symptom: "my email broke after I enabled Cloudflare". Fix: grey-cloud the mail-related A/AAAA records.

Common mistakes — the recurring shape of the support ticket

The same Cloudflare problems come up again and again:

Mistake 1: Origin IP leaked via subdomain. You proxy www and the apex through Cloudflare, but leave cpanel.yourcompany.com or direct.yourcompany.com pointing directly at the origin IP. An attacker finds the subdomain, gets the origin IP, bypasses Cloudflare entirely and attacks the origin directly. Fix: orange-cloud every subdomain that doesn't need to be unproxied, and don't publish hostnames you only use for direct access. On a server you control, you can also allow web traffic only from Cloudflare's published IP ranges.

Mistake 2: Flexible SSL with origin redirect to HTTPS. The origin sees an HTTP request from Cloudflare and redirects to HTTPS; the browser follows the redirect back to Cloudflare, which again asks the origin over HTTP; the origin redirects again, and the loop never ends. Symptom: "my site shows ERR_TOO_MANY_REDIRECTS after I enabled Cloudflare." Fix: set SSL mode to Full (strict). Done.

Mistake 3: Cache too aggressive on dynamic content. A "cache everything" rule on a site with logins can show one visitor another visitor's logged-in page. Fix: never cache pages that have user-specific content. Bypass cache for authenticated paths and cookies, and send Cache-Control: private from your app for personal pages.

Mistake 4: DDoS attack survives because the attacker found the origin IP via old DNS history. Tools like SecurityTrails and DNSdumpster archive historical DNS records. If your origin IP was ever public (it usually was, before Cloudflare), an attacker can find it. Fix: on your own VPS, move to a new origin IP after enabling Cloudflare. On shared hosting the IP belongs to the server and can't be changed, so keep every subdomain proxied and leave no DNS-only records pointing at it.

Mistake 5: Cloudflare Workers used for things that should be on the origin. Workers tempt people into stuffing application logic at the edge. For login flows, payment, anything stateful — that's almost always wrong. Workers shine for: redirects, A/B test routing, header manipulation, simple authentication checks (with KV-stored tokens), edge caching of API responses. They don't shine for: complex business logic, anything that needs a real database, anything with multi-step transactions.

Set it up before you need it

A Layer-7 flood aimed at one page can exhaust a hosting account's PHP workers long before it looks like a large attack. Cloudflare's edge absorbs most of that traffic, but only if it is already in front of your site. Nameserver changes take hours to reach every network, so don't wait for an attack to enable Cloudflare: set it up in advance, while it costs nothing on the free tier.

Workers, D1, R2, Pages — the 2026 platform play

Cloudflare has expanded beyond CDN into edge compute. Worth knowing what each is. Free allowances change from time to time, so check Cloudflare's pricing pages before you rely on them.

Workers — JavaScript/TypeScript code running across Cloudflare's edge network. Free tier: 100,000 requests/day, 10 ms CPU each. Paid: from $5/month, including 10M requests. Use for: redirects, A/B testing, edge caching, simple API gateways.

D1 — Cloudflare's SQLite-based serverless database. Free tier: 5 GB storage, 5M rows read/day, 100k rows written/day. Useful for: small datasets and read-heavy lookups. Don't use for: anything write-heavy.

R2 — S3-compatible object storage with no egress fees. Free tier: 10 GB storage, 1M Class A operations/month, 10M Class B/month. Significantly cheaper than S3 for bandwidth-heavy use cases (image hosting, downloads). Use for: media storage when you'd otherwise pay for egress. See Cloudflare Workers and R2 storage.

Pages — static-site hosting with a build pipeline (works with Next.js, Astro, Hugo, plain HTML), connected to GitHub or GitLab. The cleanest path for documentation sites, marketing splash pages and static blog migrations.

Hyperdrive — a connection pooler and query cache in front of your existing Postgres or MySQL, reducing connection overhead from Workers. Useful when Workers need to hit a relational DB and you don't want to migrate to D1.

For a Domain India customer, the practical upgrade path is: start with free Cloudflare for CDN/SSL/DDoS in front of your existing hosting, then optionally use Pages for static documentation, R2 for image hosting, Workers for redirects. D1/Hyperdrive are advanced tooling — fine to ignore unless you have a specific use case.

The Indian ISP peering reality

Indian internet routing has historically been fragmented, with different ISPs taking different paths and peering unevenly. NIXI (National Internet Exchange of India) runs exchange points in several Indian cities, where networks can connect to each other directly.

Cloudflare connects with many Indian networks, so most Indian visitors reach an Indian Cloudflare edge with low latency. It still varies by ISP: some providers route part of their traffic to Cloudflare through another city or country. You don't need to do anything to take advantage of the good paths — it's automatic. If you're comparing CDNs, test from the ISPs your visitors actually use (Jio, Airtel, BSNL, ACT and others) rather than trusting a map of locations.

Performance settings worth turning on

Under Speed → Optimization (menu names move between Cloudflare dashboard versions):

  • Brotli — On where offered (better compression than gzip; near-universal browser support in 2026).
  • Early Hints — On (HTTP 103 responses for faster paint).
  • Rocket Loader — Off for most sites. Defers JS execution, which sounds good but breaks WordPress themes and many third-party widgets in subtle ways. Turn on only after testing.
  • Polish (Pro plan) — auto-compresses images, optionally converts to WebP/AVIF.

Cloudflare retired Auto Minify and Mirage in 2024. Minify CSS and JavaScript in your build or with a caching plugin, and use native loading="lazy" for images.

Under Speed → Image Optimization:

  • Image Resizing / Images (paid) — generate multiple sizes per image and serve the right one for each device.

Under Network:

  • HTTP/3 (with QUIC) — On.
  • 0-RTT Connection Resumption — On (faster handshakes for returning visitors).

When Cloudflare is NOT enough

  • Streaming media at scale — Cloudflare Stream is a separate paid product; don't try to serve large video files through the free CDN (you'll hit the 100 MB request limit, and Cloudflare's terms restrict using the CDN mainly for video).
  • Real-time apps — Cloudflare proxies WebSockets, but it adds a hop. For very latency-sensitive traffic, such as multiplayer games, test carefully or connect clients to the origin directly.
  • Services needing a fixed IP — Cloudflare's anycast IPs aren't yours; if a client needs a stable IP for allow-listing, give them a dedicated DNS-only hostname that points to your server.
  • Apps where you control both ends and don't need a CDN — internal tools behind a VPN, B2B APIs with known clients in fixed regions.

For most consumer-facing Indian websites with a Domain India hosting backend, Cloudflare free is a clear win.

Verifying everything works

From your laptop:

bash
# Check nameservers resolve to Cloudflare
dig NS yourcompany.com +short
# Should return two *.ns.cloudflare.com entries

# Check Cloudflare is in front
curl -sI https://yourcompany.com | grep -i cf-ray
# Should return: cf-ray: <random-id>-XXX
# (XXX is the airport code of the edge serving you)

# Check cache (run twice — second request should be HIT)
curl -sI https://yourcompany.com/logo.png | grep -i cf-cache-status
# First call: MISS or DYNAMIC
# Second call: HIT

# Check SSL
curl -sIv https://yourcompany.com 2>&1 | grep -E "subject:|issuer:"
# Shows the edge certificate that Cloudflare serves to visitors

# Latency from your location
curl -w '%{time_namelookup} %{time_connect} %{time_starttransfer} %{time_total}\n' \
     -o /dev/null -s https://yourcompany.com/
# Indian users on home broadband: total is often ~0.05-0.15s for cached pages

Where Domain India fits

Cloudflare works in front of every Domain India hosting type: cPanel, DirectAdmin and Webuzo shared hosting, Windows (Plesk) hosting and VPS. Your files, databases and email stay on your hosting; Cloudflare only answers DNS and proxies web traffic. On a VPS you control the web server yourself, so you can install a Cloudflare Origin Certificate in nginx, Caddy or Apache and allow web traffic only from Cloudflare.

VPS Starter
₹552.65/mo + GST
  • 1 vCPU
  • 2 GB DDR4 RAM
  • 64 GB NVMe SSD Storage
  • 2 TB Monthly Bandwidth
See plan details

If you get stuck with the move, particularly working out which mail records to grey-cloud or installing an Origin Certificate, our support team can help by 24/7 live chat or a support ticket; tickets get a first response within 15 minutes. There is no phone support.

Frequently asked questions

Is Cloudflare really free, with no catches?

Yes. The Free plan covers most small-to-medium Indian sites, including CDN, DDoS protection, DNS and edge SSL. You pay only if you need features such as image optimisation, more WAF rules, an SLA, or higher upload limits.

Does Cloudflare replace my Domain India hosting?

No. Cloudflare is a proxy, CDN and DNS layer. Your application files, databases and email still live on your Domain India hosting. Cloudflare caches and shields; it doesn't host your site.

Will Cloudflare break my email?

Only if you orange-cloud the mail-related DNS records. Keep mail.yourcompany.com, the hostnames your MX records point to, and any IMAP or SMTP hostname on grey cloud (DNS only). Also make sure your MX, SPF, DKIM and DMARC records were copied to Cloudflare before you change nameservers.

Can I use Cloudflare on shared cPanel hosting?

Yes. Add the domain to Cloudflare, copy your DNS records, change the nameservers on the domain's Nameservers tab in the Domain India client area, and set SSL to Full (strict) using the hosting's free SSL or a Cloudflare Origin Certificate installed in cPanel.

What if my site needs file uploads larger than 100 MB?

The Free and Pro plans cap a single request body at 100 MB. Business raises it to 200 MB and Enterprise to 500 MB or more. Alternatively, use a dedicated upload subdomain on grey cloud (DNS only) so the upload goes straight to your server.

How do I handle data sovereignty concerns?

Cloudflare's Free and Pro plans route through their global network, including edges outside India. For strict data localisation, for example under DPDPA for sensitive personal data, Cloudflare's Data Localization Suite (an Enterprise add-on) restricts where traffic is processed. Most marketing and brochure sites don't need this; healthcare, fintech and government sites often do.

Will switching to Cloudflare hurt my SEO?

Almost always no. Faster sites rank better, and search engines crawl Cloudflare-fronted sites every day. The one risk is a misconfigured cache that serves the wrong page; avoid it by not caching HTML that differs per user and by bypassing cache for logged-in visitors.

I host my site on a Domain India VPS. Same setup?

Yes. The Cloudflare setup is the same, and on a VPS you control the origin, so you can install a Cloudflare Origin Certificate in nginx, Caddy or Apache and firewall web traffic to Cloudflare's IP ranges. See the VPS security checklist for hardening.

What's the difference between Cloudflare and a CDN like Akamai or AWS CloudFront?

Akamai and CloudFront are CDNs with usage-based pricing and more setup. Cloudflare combines DNS, CDN and DDoS protection in one product with a free tier. For a small-to-medium Indian website, Cloudflare's free tier usually delivers the most value for the least effort.

Bottom line

Every Indian-audience website should consider running Cloudflare in front, and the case is strongest when the hosting server is far from its visitors. The free tier alone gets you the latency win for static content, the DDoS protection, free SSL and the basic WAF. Setup takes about 30 minutes, and the rollback is one nameserver change away.

Ready to put Cloudflare in front of your site? Update your nameservers from the client area using the steps in How do I change my nameservers, harden your origin with the VPS security checklist, or open a support ticket (or use the public ticket form) if you want help with the move.

Want an origin server you fully control?

A Domain India VPS gives you root access to run nginx, Caddy or Apache the way you want, with a Cloudflare Origin Certificate and a firewall that only accepts Cloudflare traffic.

See VPS plans

Was this article helpful?

Your answer helps us decide what to improve next.

Still need help? Open a support ticket and our team will reply.

Prefer an app? Add this site to your home screen.Get the app