Cloudflare tutor

A morning desk for Kotha · Gold Coast

How this desk works

One Cloudflare feature each morning, dated in Australia/Brisbane. You get a plain-English account of what it is, why it matters when you host a site, an app, or an agent harness, a concrete example on kosan.xyz or drkotha.com, and one or two dashboard exercises. The newest lesson is below. Earlier days stay in the archive and keep their own links. Adding a day is a new entry in the lesson list, then a redeploy. This desk never edits your zones.

· Australia/Brisbane · Lesson

Proxied or DNS-only: what the cloud on a record does

DNS records, the orange cloud, and DNS-only

What it is

A DNS record is one row in a zone. You have two zones, kosan.xyz and drkotha.com, and each zone has its own list of rows. A row does not exist in the other zone just because the names look related.

Every row has a name (the hostname), a type, and a content value. The types you will actually use are: A (an IPv4 address), AAAA (an IPv6 address), CNAME (follow this other hostname), TXT (a note machines read, such as a proof you own the name), and MX (where email for that name is delivered).

On an A, AAAA, or CNAME, Cloudflare draws a cloud. Orange, labelled Proxied, means visitors are sent to Cloudflare first. Grey, labelled DNS only, means Cloudflare only publishes the address you typed, and the visitor’s computer connects straight there.

Proxied is for web traffic: HTTPS, caching, and Workers. DNS only is for anything that must see the real address and must not pass through the web proxy. MX (mail) records cannot be proxied. Leave them grey.

Why it matters

A site, an app, or an agent harness on a Worker only receives a request when that hostname is proxied, or when the hostname is attached as a Worker custom domain (Cloudflare proxies those for you). A grey-cloud record never reaches a Worker, even if a route pattern looks correct in the dashboard.

The cloud is per record, not per zone. kosan.xyz can have one name proxied and another DNS-only. Flipping the cloud on a live name takes that name off Cloudflare immediately: no Worker, no HTTPS certificate from Cloudflare, no cache. Looking is safe. Toggling a name that already serves something is not an experiment.

A redirect rule is a different feature. It runs only after a request has already arrived at Cloudflare, which means the name was proxied. The cloud icon does not create a redirect, and a redirect does not create a DNS row. This lesson is only the DNS row.

On your account

This page is the Worker named cloudflare-tutor, on the hostname cloudflare.kosan.xyz, in the kosan.xyz zone. The Worker custom domain publishes a proxied record for that exact name and sends every path to this Worker. There is no separate server behind it.

The same zone already fronts other Workers you run, each on its own hostname. Those names work because each one is proxied or is itself a Worker custom domain, and the script is bound only to that name. A route such as cloudflare.kosan.xyz/* matches this hostname and nothing else in the zone. It does not match the apex, and it does not match a different subdomain.

drkotha.com is the other list. A name like app.drkotha.com does not exist until a row is added in that zone. For a future site or harness there, either attach the hostname as a Worker custom domain or add a proxied record and a route. Mail rows on drkotha.com stay DNS-only. Editing kosan.xyz never changes drkotha.com, and the reverse is also true.

If cloudflare.kosan.xyz were switched to DNS only and pointed at an ordinary address, the browser would skip Cloudflare and this Worker would see nothing. workers.dev hostnames are separate: they are Cloudflare’s own names for a script, and they do not need a row in either of your zones.

Do this yourself

These stay in the dashboard, on your side. This site does not change DNS, routes, or other Workers.

  1. Open the Cloudflare dashboard, choose the kosan.xyz zone, then DNS, then Records. Search for cloudflare. Find the row cloudflare.kosan.xyz and confirm the proxy status says Proxied (orange cloud). Note the type Cloudflare chose. Do not edit the row, and do not change any other name.
  2. Open the drkotha.com zone, DNS, Records. Without saving anything, find one web hostname and read whether it is Proxied or DNS only, then find an MX row and confirm it is DNS only. Close the page. Do not toggle a cloud. If you want a hands-on trial, add a new record only: name dns-lesson.kosan.xyz, type AAAA, content 100::, proxy status Proxied. Save it, confirm it appears, then delete that same record. Do not modify any row that was already there.

Earlier days

No earlier lessons yet. This is day one. Tomorrow’s feature will be listed here, and this page will keep today’s lesson.