# Cloudflare cPanel DNS Proxy: Real Visitor IPs

Source: https://srvscripts.com/guides/cloudflare-cpanel-dns-proxy-real-ip/
Updated: 2026-10-03
Publisher: srvScripts (https://srvscripts.com/)

## Which records to proxy

When you add a domain to Cloudflare it imports the zone from cPanel and turns the orange cloud on for most A records. Go through them:

In short: When you add a domain to Cloudflare it imports the zone from cPanel and turns the orange cloud on for most A records.

- `@` and `www` (A records to the server IP): **proxied**. This is the point of Cloudflare.

- `mail`, `smtp`, `imap`, `pop`, `webmail`, `cpanel`, `whm`, `ftp`: **DNS only** (grey cloud). Cloudflare’s proxy only carries HTTP(S) on standard ports; a proxied `mail` record silently breaks IMAP and SMTP for every client, and a proxied `cpanel` record breaks port 2083 unless you pay for Spectrum.

- `MX`: points to a hostname, usually `mail.domain.com`. It must resolve to the real IP, so that hostname must be DNS-only. Same for any `autodiscover`/`autoconfig` records.

- `TXT` (SPF, DKIM, DMARC): copy across exactly. Check afterwards with `dig TXT default._domainkey.domain.com +short`.

- The server hostname (`server.hostingcompany.com`) usually lives in a different zone; leave it.

Change the nameservers at the registrar only after the zone in Cloudflare matches `dig ANY` on the cPanel server. Keep the zone in cPanel as well — the cPanel DNS zone is still what AutoSSL and the local resolver read.

## SSL mode: Full (strict), nothing else

Cloudflare → SSL/TLS → **Full (strict)**. “Flexible” serves HTTPS to visitors while fetching your site over plain HTTP, which breaks WordPress redirects (infinite loop) and leaks everything between Cloudflare and your server. Full (strict) needs a valid certificate on the origin, which cPanel’s AutoSSL provides — but AutoSSL’s DCV check has to reach your server through Cloudflare. It does, over HTTP on `/.well-known/`, as long as you have no page rule forcing HTTPS on that path and no WAF rule blocking it.

If AutoSSL fails after the move, temporarily grey-cloud `@`, run AutoSSL, then re-enable the proxy; or install a **Cloudflare Origin Certificate** (SSL/TLS → Origin Server) in cPanel, which is valid for 15 years and never needs DCV.

Turn on Always Use HTTPS and Automatic HTTPS Rewrites in Cloudflare, and remove any `.htaccess` HTTP→HTTPS redirect that checks `%{HTTPS}` — behind the proxy that variable is always `off` and causes a loop. If you need a redirect in `.htaccess`, test `%{HTTP:X-Forwarded-Proto} !https` instead.

## Real visitor IPs

Behind Cloudflare, Apache sees every request coming from a Cloudflare IP. Your logs are useless, CSF/LFD bans Cloudflare instead of the attacker, and WordPress security plugins block everyone. Fix it at the web server so every layer above gets the real address.

**Apache (EasyApache 4):** install `mod_remoteip` and trust Cloudflare’s ranges.

```
dnf -y install ea-apache24-mod_remoteip
cat > /etc/apache2/conf.d/includes/pre_main_global.conf
