SSL/TLS

CF Dash lets you manage SSL/TLS for each of your Cloudflare zones.

Open SSL/TLS

  1. Go to the Domains tab and tap your domain.
  2. Tap SSL/TLS.

SSL Mode

Choose the SSL mode that fits your setup:

  • Off — no encryption
  • Flexible — encryption between visitor and Cloudflare only
  • Full — encryption between visitor and Cloudflare, and Cloudflare to your origin (origin must have a valid certificate)
  • Full (strict) — like Full, but the origin certificate must be valid for the hostname

Most setups use Full (strict) or Full.

Universal SSL

Cloudflare automatically issues a free Universal SSL certificate for your zone. You can:

  • Order Universal SSL — request a new Universal SSL certificate (covers the apex and common subdomains).
  • Wildcard cover — check whether the certificate covers *.yourdomain.com.

Custom Certificates

If you bring your own certificate (for example an Extended Validation certificate), you can:

  • Upload Custom — provide the certificate and private key. CF Dash uploads it to Cloudflare for the zone.
  • Remove — delete a previously uploaded custom certificate.

Note: Universal SSL and custom certificate management are Pro features.

Certificate Status

The SSL page shows your current certificate status so you can confirm your zone is properly secured and spot expiring certificates before they cause downtime.