Overview¶
This guide moves DNS hosting for a domain from Namecheap to Cloudflare while leaving the domain registered at Namecheap. It then turns on Cloudflare's proxy in front of a site hosted on DigitalOcean App Platform.
Once the proxy is on, you can block abusive bots at the edge. That's covered in Setting Up Cloudflare's WAF to Block Abusive Crawlers.
Two roles are involved:
| Role | Who | What it does |
|---|---|---|
| Registrar | Namecheap | Owns the domain registration and renewals. Unchanged. |
| DNS host + proxy | Cloudflare | Answers DNS queries and proxies HTTP(S). |
Nothing is transferred. Only the domain's nameservers change.
Examples use andrewmercer.net and an App Platform default hostname of my-app-xxxxx.ondigitalocean.app. Substitute your own values.
Cloudflare's dashboard layout changes from time to time. If a menu name below doesn't match exactly, look for the closest equivalent.
Part 1: Prepare¶
Step 1: Inventory your current DNS records¶
In Namecheap, go to Domain List → Manage → Advanced DNS and record every entry:
A/AAAA/CNAMErecords for@andwww- Any other subdomains
MXrecords (email)TXTrecords (SPF, DKIM, DMARC, domain verification such as Google or DigitalOcean)CAArecords, if any
Take a screenshot or copy them into a text file. You'll compare against this list later, and it's your rollback reference.
If your nameservers are already set to something other than Namecheap BasicDNS, your records live at that other provider. Inventory them there instead.
Step 2: Lower TTLs (optional, recommended)¶
A day before the switch, lower the TTL on your main records to 5 minutes. A rollback then propagates quickly if anything goes wrong.
Step 3: Note the App Platform domain settings¶
In DigitalOcean, go to Apps → your app → Settings → Domains and note:
- Which domains are attached (
andrewmercer.net,www.andrewmercer.net) - The target hostname DO tells you to point at (the
*.ondigitalocean.appname)
Part 2: Add the site to Cloudflare¶
Step 4: Create a Cloudflare account and add the domain¶
- Sign up at https://dash.cloudflare.com/sign-up.
- Click Add a domain (or Add site) and enter
andrewmercer.net(the apex, withoutwww). - Choose the Free plan.
- Let Cloudflare scan your existing DNS records.
Step 5: Review the imported records¶
Compare Cloudflare's imported list with your inventory from Step 1. The scan often misses subdomains and sometimes TXT records.
- Add anything missing.
- Delete anything stale.
- Make sure email records (
MX, SPF/DKIM/DMARCTXT) are present and correct. Email breaks silently if these are missing.
Step 6: Set up the web records for App Platform¶
Point both the apex and www at the App Platform hostname:
| Type | Name | Target | Proxy status |
|---|---|---|---|
| CNAME | @ |
my-app-xxxxx.ondigitalocean.app |
DNS only (grey) for now |
| CNAME | www |
my-app-xxxxx.ondigitalocean.app |
DNS only (grey) for now |
Cloudflare allows a CNAME at the apex through CNAME flattening.
Leave them grey-clouded (DNS only) during the cutover. You'll turn on the proxy in Part 4 once DigitalOcean has verified the domain and issued its certificate.
Mail-related records (MX, mail-server A records) must always stay DNS only.
Part 3: Change the nameservers at Namecheap¶
Step 7: Get your Cloudflare nameservers¶
At the end of onboarding, Cloudflare shows two nameservers assigned to your account, something like:
ada.ns.cloudflare.com
bob.ns.cloudflare.com
Use the exact pair shown in your dashboard.
Step 8: Turn off DNSSEC at Namecheap (if enabled)¶
If DNSSEC is on at Namecheap, disable it before changing nameservers. Otherwise resolvers will reject the new answers and the domain will go dark. You'll re-enable it through Cloudflare in Step 11.
Namecheap: Domain List → Manage → Advanced DNS → DNSSEC → off.
Step 9: Switch to custom DNS¶
- Namecheap: Domain List → Manage.
- Under Nameservers, change Namecheap BasicDNS to Custom DNS.
- Enter the two Cloudflare nameservers.
- Click the green checkmark to save.
Step 10: Wait for activation¶
Back in Cloudflare, click Check nameservers. Activation usually takes from a few minutes to a couple of hours, and occasionally up to 24 hours. Cloudflare emails you when the zone is active.
Verify from a terminal:
dig NS andrewmercer.net +short
# should return the two *.ns.cloudflare.com servers
dig andrewmercer.net +short
dig www.andrewmercer.net +short
Then load the site in a browser and confirm it still works.
Step 11: Re-enable DNSSEC (optional)¶
In Cloudflare, go to DNS → Settings → DNSSEC → Enable. Cloudflare will show a DS record. Add it in Namecheap under Advanced DNS → DNSSEC (key tag, algorithm, digest type, digest).
Part 4: Turn on the Cloudflare proxy¶
Step 12: Confirm DigitalOcean is happy¶
In Apps → Settings → Domains, both domains should show as active with a valid certificate. Fix anything flagged before continuing.
Step 13: Set SSL/TLS mode to Full (strict)¶
Cloudflare: SSL/TLS → Overview → set encryption mode to Full (strict).
Do not use Flexible. App Platform redirects HTTP to HTTPS, and Flexible sends HTTP to the origin, which causes an infinite redirect loop.
Also enable these under SSL/TLS → Edge Certificates:
- Always Use HTTPS: on
- Minimum TLS Version: 1.2
Step 14: Orange-cloud the web records¶
In DNS → Records, switch the @ and www CNAMEs from DNS only to Proxied (orange cloud).
Test:
curl -sI https://www.andrewmercer.net | grep -i -E 'server|cf-ray'
# server: cloudflare and a cf-ray header mean traffic is going through Cloudflare
Certificate renewals: App Platform renews its own origin certificate. If DO later reports a domain verification or certificate problem while the records are proxied, set the records to grey cloud temporarily, let DO renew, then switch back to orange.
Next step¶
Traffic now flows through Cloudflare, so its WAF can filter requests before they reach DigitalOcean. Continue with Setting Up Cloudflare's WAF to Block Abusive Crawlers.
Rollback¶
If something goes badly wrong:
- If you enabled DNSSEC through Cloudflare (Step 11), remove the DS record at Namecheap first.
- Namecheap: Domain List → Manage → Nameservers → back to Namecheap BasicDNS.
- Recreate the records from your Step 1 inventory in Advanced DNS (Namecheap may have kept them).
With lowered TTLs, the rollback propagates in minutes.
Quick reference¶
| Task | Where |
|---|---|
| Change nameservers | Namecheap → Domain List → Manage → Nameservers |
| DNSSEC (registrar side) | Namecheap → Advanced DNS → DNSSEC |
| DNSSEC (Cloudflare side) | Cloudflare → DNS → Settings → DNSSEC |
| DNS records | Cloudflare → DNS → Records |
| SSL mode | Cloudflare → SSL/TLS → Overview → Full (strict) |
| App domains and certs | DigitalOcean → Apps → Settings → Domains |