tuqo

Custom domain via Cloudflare DNS: turn off the proxy

In Cloudflare everything happens under DNS → Records, and there is exactly one trap: the orange cloud. Records for Tuqo must be set to DNS only (grey cloud). With proxying on, the site won’t work; the reasons are below.

Step 1. Get the records from the Tuqo panel

Site in the panel → Domains tab → enter the domain → Add. The panel shows cards for the A and TXT records with copy buttons. Every domain gets its own TXT token.

Step 2. Open DNS in Cloudflare

Cloudflare dashboard → pick the domain → DNS section → Records tab → Add record button.

Step 3. An A record with a grey cloud

FieldValue
TypeA
Name@
IPv4 address201.51.6.16
Proxy statusDNS only (grey cloud)
TTLAuto

A new record is created as proxied, so switch the toggle off before you save. Then click Save. If the record already exists with an orange cloud, open it for editing and click the Proxy status toggle: the cloud turns grey and the change is saved right away.

The exact IP is always shown on the domain card in Tuqo; if it ever differs from the one above, go by the panel.

Why the orange cloud doesn’t work

Proxied (orange cloud) means DNS returns Cloudflare’s addresses instead of yours, and all traffic goes through their network. For Tuqo this breaks two things at once:

  • the address check. The panel resolves the domain and sees a Cloudflare IP instead of ours, so the domain card shows “A record points elsewhere”;
  • certificate issuance. Tuqo issues the free SSL certificate itself, on the first request to the domain. Through the proxy the request doesn’t reach us in the form this needs, because Cloudflare terminates TLS. The certificate isn’t issued, and visitors get an error like “SSL handshake failed” or an endless redirect.

DNS only keeps Cloudflare as a plain DNS host: a handy zone editor, fast resolvers, and a direct connection to Tuqo’s serving layer.

Step 4. The TXT record

Add record → type TXT:

FieldValue
TypeTXT
Name_tuqo-verify
Contentthe token from the Tuqo panel

TXT records can’t be proxied, so there is no cloud here.

Step 5. www, if you need it

Add an A record with Name www (also DNS only) or a CNAME www → mysite.com. Proxying must be off on the CNAME too. In Tuqo, www is added as a separate domain with its own TXT record, _tuqo-verify.www.

Step 6. Wait and check

Cloudflare applies changes almost instantly, but resolver caches live by TTL; a few minutes is usually enough:

dig +short mysite.com A
dig +short _tuqo-verify.mysite.com TXT

If you see addresses like 104.x.x.x or 172.67.x.x, the cloud is still orange.

Step 7. Final step in Tuqo

Go back to the Domains tab and click Verify domain. The domain becomes “Verified · on” and the certificate is issued automatically. You can check it separately with the Check HTTPS button on the domain card.

FAQ

What about Cloudflare’s DDoS protection and caching?

In DNS only mode they don’t apply: traffic goes straight to us. For a static site that’s no loss: files are served from our side, and the certificate and HTTP/2 stay in place. If you absolutely need the proxy, you have to accept that certificate issuance on our side won’t succeed.

Can I turn the cloud on later, once the domain is verified?

Better not: the address check will start showing “A record points elsewhere”, and the next certificate renewal may run into problems. Leave it on DNS only.

The domain is in a Cloudflare zone, but I never changed the NS at my registrar

Then nobody queries the Cloudflare zone. Edit the records wherever the domain’s NS point, or delegate the domain to Cloudflare’s name servers first.

General domain guide → · Domain not working → · Pricing →