Move Your DNS to Cloudflare (Free) for Eligible Email Auto-Fixes
Move your domain's DNS to Cloudflare's free plan without breaking email or your website, then optionally auto-apply known-provider MX records and tightening an existing SPF record's terminal qualifier.
Some DNS hosts - including several popular registrars - do not give normal accounts an API to edit DNS records. That is why a tool can read your public DNS and tell you exactly what is wrong, but cannot offer to apply the change for you: it has no safe, authorized way to write to your zone at that host.
Cloudflare is different. Its free plan includes DNS hosting and lets you create a token with Zone DNS Edit and Zone Read for this zone. That can enable eligible automatic changes after you approve each one, but it does not make every finding automatic. For an ordinary mail setup, publishing a first SPF or DMARC record remains manual because it needs sender or monitored-mailbox details the scan cannot prove. Moving DNS is optional.
This guide explains what moving DNS to Cloudflare does (and does not) change, how to do it without breaking your website or email, and how to confirm everything still works before and after the switch.
Check your domain now, then use this guide to understand the result.
Check my domain - freeOn this page
Why moving DNS to Cloudflare can enable eligible changes
Applying a DNS change for you requires writing to the zone where your records actually live. Cloudflare's free plan supports that through a token with Zone DNS Edit and Zone Read for this zone. For ordinary email-setup findings, automatic changes cover only known-provider MX records and tightening an existing SPF record's terminal qualifier.
- Cloudflare DNS hosting is free, with no record limit for normal use.
- You create a token with Zone DNS Edit and Zone Read for this zone yourself and can delete it anytime.
- Domain Email Doctor can apply an eligible exact change after you approve it - no password or unrestricted account access.
- You keep your domain registration wherever it is now; only the DNS nameservers change.
In short: you are not switching companies or paying anything. You are moving where your DNS records are managed to a host that lets you authorize precise, previewed changes.
What changing nameservers does and does not change
Your nameservers decide which DNS host answers for your domain. When you point them at Cloudflare, every record - email and website - is served from Cloudflare from then on.
| What changes | What stays the same |
|---|---|
| Where your DNS records are managed (now Cloudflare) | Who you bought the domain from (your registrar is unchanged) |
| The dashboard you edit MX, SPF, DKIM, and DMARC in | Your email provider and mailboxes (Google, Microsoft, etc.) |
| The nameservers listed at your registrar | Your website host, as long as its A or CNAME records move too |
The one real risk is an incomplete move: if a record does not come across, the service it controls can break until you add it. That is why copying your current records first - the next step - matters.
Before you start: copy your current records
Cloudflare imports most existing records automatically when you add a domain, but it can miss some. Make your own list first so you can confirm nothing is lost.
- Run an email DNS check on your domain and note the MX, SPF (TXT), DKIM, and DMARC records it reports.
- Open your current DNS host and copy any website records too - usually an A record on the root and a CNAME on www.
- Note any other records you rely on, such as verification TXT records for Google or Microsoft.
- Keep this list open while you set up Cloudflare so you can check each record against it.
If your domain receives email, the MX records and the SPF, DKIM, and DMARC TXT records are the ones that must survive the move intact.
Step by step: add your domain to Cloudflare
| Step | What to do |
|---|---|
| 1 | Create a free account at dash.cloudflare.com. |
| 2 | Choose Add a site, enter your domain, and select the Free plan. |
| 3 | Let Cloudflare scan and import your existing DNS records, then review them against the list you made. |
| 4 | Add any record that did not import - especially MX records and the SPF, DKIM, DMARC, and website A or CNAME records. |
| 5 | Cloudflare shows you two nameservers (for example, two names ending in ns.cloudflare.com). Copy both. |
| 6 | At your domain registrar, replace the current nameservers with Cloudflare's two, and save. |
| 7 | Wait for activation. It is usually quick but can take up to 24 hours to fully propagate. |
Until activation finishes, the internet may use either your old or new host, so keep both sets of records matching during the switch.
After the move: re-check, then apply changes
Once Cloudflare shows your domain as Active, confirm everything resolves before relying on it.
- Re-run an email DNS check and confirm MX, SPF, DKIM, and DMARC look the way they did before - or better.
- Open your website to confirm the A or CNAME records moved correctly.
- Send and receive a test email to confirm mail flow is intact.
With DNS on Cloudflare, you can authorize a token with Zone DNS Edit and Zone Read for this zone for known-provider MX records and tightening an existing SPF record's terminal qualifier. For an ordinary mail setup, publishing a first SPF or DMARC record remains manual because it needs sender or monitored-mailbox details the scan cannot prove. Moving to Cloudflare is optional.
Quick checklist
- Copy your current MX, SPF, DKIM, and DMARC records before changing anything.
- Add your domain to Cloudflare's free plan and review every imported record.
- Add any record that did not import, especially MX and the email TXT records.
- Replace your nameservers at your registrar with Cloudflare's two nameservers.
- Wait for Cloudflare to show the domain as Active, then re-check your email DNS.
- Confirm your website and a test email both still work after the switch.