Cloudflare setup South Africa

A calmer, more deliberate Cloudflare setup.

DNS, CDN, WAF, TLS and rate-limiting configuration for South African SMEs—with clear ownership, safe changes and testing that reflects how your website actually works.

01 · DNS & proxying

Make the traffic path understandable.

Review records, nameservers and proxy status; separate web traffic from email and verification records; and document the origin dependencies before making a change.

Read Cloudflare’s documentation ↗

02 · CDN & cache

Improve delivery without stale surprises.

Use Cloudflare’s cache defaults and Cache Rules deliberately. Dynamic pages, logged-in areas and checkout flows are treated differently from cacheable static assets.

Read Cloudflare’s documentation ↗

03 · WAF

Apply request controls with context.

Review managed and custom rules around the application paths that matter. A rule is tested for useful mitigation and the risk of blocking legitimate customers.

Read Cloudflare’s documentation ↗

04 · TLS & HTTPS

Connect both sides securely.

Check the edge certificate, origin certificate and encryption mode together. Full (strict) requires a valid, unexpired origin certificate, so we verify the origin before selecting it.

Read Cloudflare’s documentation ↗

05 · Rate limiting

Slow down abuse-prone endpoints.

Define a path, characteristic, period and action for a specific risk such as login abuse or API exhaustion. Thresholds are tested against normal customer behaviour.

Read Cloudflare’s documentation ↗

06 · Handover & monitoring

Leave your team with a workable system.

Record owners, recovery contacts, rule intent, tests, exclusions and review points. Ongoing monitoring is agreed separately so responsibilities stay visible.

Read Cloudflare’s documentation ↗

Right-sized, not over-sold

Protection that respects your business.

Cloudflare can sit between visitors and your origin to proxy web traffic, cache eligible content and apply request rules. It is a useful control layer, not a substitute for secure application code, patching, backups, identity controls or an incident plan.

We make those boundaries explicit. Your configuration is scoped to your domains, origins, traffic patterns and tolerance for false positives. No setup is presented as a guarantee of security, uptime or regulatory compliance.

Good candidates for this service

  • A public website: you want DNS and HTTPS settings reviewed before a launch or migration.
  • A busy contact or login flow: you need carefully tested rules around abuse-prone endpoints.
  • A growing team: you want documented access, change ownership and a handover you can operate.
  • A confusing existing zone: you need records, proxy status, origin dependencies and exclusions mapped first.

A controlled change process

From discovery to handover and monitoring.

Every engagement starts with the current state and ends with someone knowing what changed, how to test it and what to do if it needs to be reversed.

  1. 1

    Discovery

    Domains, registrar, DNS, host, email, origins, integrations, account owners and current symptoms.

  2. 2

    Scope

    Written in-scope controls, exclusions, access plan, risks, rollback triggers and who approves changes.

  3. 3

    Configure

    Back up the current state, make the approved DNS, CDN, WAF, TLS and rate-limit changes in stages.

  4. 4

    Test

    Check DNS, HTTPS, origin reachability, cache behaviour, forms, logins, APIs, email and representative user journeys.

  5. 5

    Handover & monitor

    Share the change record and ownership notes, then review alerts and rule results where ongoing monitoring is included.

What you can expect to receive

  • Current-state record and dependency notes
  • Agreed DNS, proxy, cache, TLS and security-rule scope
  • Change log, test results and any accepted risks
  • Admin ownership, recovery contacts and operating notes
  • Monitoring or review tasks where included in the proposal

The details that matter

Nameserver changes, email records, third-party verification records, origin certificates, webhooks, APIs, CMS logins and payment flows all need different treatment. We keep non-web records DNS-only where appropriate and do not change a record merely to make the dashboard look tidy.

Cloudflare plan availability and limits can change. Third-party licences, registrar work, hosting changes, application fixes and emergency response are separate unless your written scope says otherwise.

Want your Cloudflare setup mapped properly?

Share your domain, host, current pain point and who should own the account. We will start with fit and a safe scope.

Start a Cloudflare conversation