Andrew Mercer
on this page

Overview

This guide moves DNS hosting for a domain from Namecheap to Cloudflare while leaving the domain registered at Namecheap. It then turns on Cloudflare's proxy in front of a site hosted on DigitalOcean App Platform.

Once the proxy is on, you can block abusive bots at the edge. That's covered in Setting Up Cloudflare's WAF to Block Abusive Crawlers.

Two roles are involved:

Role Who What it does
Registrar Namecheap Owns the domain registration and renewals. Unchanged.
DNS host + proxy Cloudflare Answers DNS queries and proxies HTTP(S).

Nothing is transferred. Only the domain's nameservers change.

Examples use andrewmercer.net and an App Platform default hostname of my-app-xxxxx.ondigitalocean.app. Substitute your own values.

Cloudflare's dashboard layout changes from time to time. If a menu name below doesn't match exactly, look for the closest equivalent.


Part 1: Prepare

Step 1: Inventory your current DNS records

In Namecheap, go to Domain List → Manage → Advanced DNS and record every entry:

  • A / AAAA / CNAME records for @ and www
  • Any other subdomains
  • MX records (email)
  • TXT records (SPF, DKIM, DMARC, domain verification such as Google or DigitalOcean)
  • CAA records, if any

Take a screenshot or copy them into a text file. You'll compare against this list later, and it's your rollback reference.

If your nameservers are already set to something other than Namecheap BasicDNS, your records live at that other provider. Inventory them there instead.

A day before the switch, lower the TTL on your main records to 5 minutes. A rollback then propagates quickly if anything goes wrong.

Step 3: Note the App Platform domain settings

In DigitalOcean, go to Apps → your app → Settings → Domains and note:

  • Which domains are attached (andrewmercer.net, www.andrewmercer.net)
  • The target hostname DO tells you to point at (the *.ondigitalocean.app name)

Part 2: Add the site to Cloudflare

Step 4: Create a Cloudflare account and add the domain

  1. Sign up at https://dash.cloudflare.com/sign-up.
  2. Click Add a domain (or Add site) and enter andrewmercer.net (the apex, without www).
  3. Choose the Free plan.
  4. Let Cloudflare scan your existing DNS records.

Step 5: Review the imported records

Compare Cloudflare's imported list with your inventory from Step 1. The scan often misses subdomains and sometimes TXT records.

  • Add anything missing.
  • Delete anything stale.
  • Make sure email records (MX, SPF/DKIM/DMARC TXT) are present and correct. Email breaks silently if these are missing.

Step 6: Set up the web records for App Platform

Point both the apex and www at the App Platform hostname:

Type Name Target Proxy status
CNAME @ my-app-xxxxx.ondigitalocean.app DNS only (grey) for now
CNAME www my-app-xxxxx.ondigitalocean.app DNS only (grey) for now

Cloudflare allows a CNAME at the apex through CNAME flattening.

Leave them grey-clouded (DNS only) during the cutover. You'll turn on the proxy in Part 4 once DigitalOcean has verified the domain and issued its certificate.

Mail-related records (MX, mail-server A records) must always stay DNS only.


Part 3: Change the nameservers at Namecheap

Step 7: Get your Cloudflare nameservers

At the end of onboarding, Cloudflare shows two nameservers assigned to your account, something like:

ada.ns.cloudflare.com
bob.ns.cloudflare.com

Use the exact pair shown in your dashboard.

Step 8: Turn off DNSSEC at Namecheap (if enabled)

If DNSSEC is on at Namecheap, disable it before changing nameservers. Otherwise resolvers will reject the new answers and the domain will go dark. You'll re-enable it through Cloudflare in Step 11.

Namecheap: Domain List → Manage → Advanced DNS → DNSSEC → off.

Step 9: Switch to custom DNS

  1. Namecheap: Domain List → Manage.
  2. Under Nameservers, change Namecheap BasicDNS to Custom DNS.
  3. Enter the two Cloudflare nameservers.
  4. Click the green checkmark to save.

Step 10: Wait for activation

Back in Cloudflare, click Check nameservers. Activation usually takes from a few minutes to a couple of hours, and occasionally up to 24 hours. Cloudflare emails you when the zone is active.

Verify from a terminal:

dig NS andrewmercer.net +short
# should return the two *.ns.cloudflare.com servers

dig andrewmercer.net +short
dig www.andrewmercer.net +short

Then load the site in a browser and confirm it still works.

Step 11: Re-enable DNSSEC (optional)

In Cloudflare, go to DNS → Settings → DNSSEC → Enable. Cloudflare will show a DS record. Add it in Namecheap under Advanced DNS → DNSSEC (key tag, algorithm, digest type, digest).


Part 4: Turn on the Cloudflare proxy

Step 12: Confirm DigitalOcean is happy

In Apps → Settings → Domains, both domains should show as active with a valid certificate. Fix anything flagged before continuing.

Step 13: Set SSL/TLS mode to Full (strict)

Cloudflare: SSL/TLS → Overview → set encryption mode to Full (strict).

Do not use Flexible. App Platform redirects HTTP to HTTPS, and Flexible sends HTTP to the origin, which causes an infinite redirect loop.

Also enable these under SSL/TLS → Edge Certificates:

  • Always Use HTTPS: on
  • Minimum TLS Version: 1.2

Step 14: Orange-cloud the web records

In DNS → Records, switch the @ and www CNAMEs from DNS only to Proxied (orange cloud).

Test:

curl -sI https://www.andrewmercer.net | grep -i -E 'server|cf-ray'
# server: cloudflare and a cf-ray header mean traffic is going through Cloudflare

Certificate renewals: App Platform renews its own origin certificate. If DO later reports a domain verification or certificate problem while the records are proxied, set the records to grey cloud temporarily, let DO renew, then switch back to orange.


Next step

Traffic now flows through Cloudflare, so its WAF can filter requests before they reach DigitalOcean. Continue with Setting Up Cloudflare's WAF to Block Abusive Crawlers.


Rollback

If something goes badly wrong:

  1. If you enabled DNSSEC through Cloudflare (Step 11), remove the DS record at Namecheap first.
  2. Namecheap: Domain List → Manage → Nameservers → back to Namecheap BasicDNS.
  3. Recreate the records from your Step 1 inventory in Advanced DNS (Namecheap may have kept them).

With lowered TTLs, the rollback propagates in minutes.


Quick reference

Task Where
Change nameservers Namecheap → Domain List → Manage → Nameservers
DNSSEC (registrar side) Namecheap → Advanced DNS → DNSSEC
DNSSEC (Cloudflare side) Cloudflare → DNS → Settings → DNSSEC
DNS records Cloudflare → DNS → Records
SSL mode Cloudflare → SSL/TLS → Overview → Full (strict)
App domains and certs DigitalOcean → Apps → Settings → Domains