知识库

Use your own Cloudflare DNS account to serve your domains' DNS

Create a Cloudflare API token with Zone Read and DNS Edit and connect it, so your domains' DNS is served from your own Cloudflare account.

What connecting it does for you

Connecting your own Cloudflare account lets a domain's DNS be served from your account instead of ours. You keep the zone, the bill and the vendor dashboard; we create and update the records your sites and mailboxes need, so you do not copy them by hand.

Before you start

A Cloudflare account with your domains added as zones, or ready to add them. Cloudflare's free plan is enough. Connect Cloudflare as DNS separately from a Cloudflare CDN account if you want the two on different Cloudflare accounts.

1. Create the key at Cloudflare

In the Cloudflare dashboard open My Profile → API Tokens and choose Create Token, then Create Custom Token. Give it a name, add the permissions below, and under Zone Resources choose the zones you want us to reach — all zones, or only the ones you name. Review it and press Create Token. Cloudflare shows the token once; copy it then.

Add these permissions:

  • Zone → Zone → Read
  • Zone → DNS → Edit

The older alternative. Instead of a token you can connect with your Global API Key and the email address you sign in with (My Profile → API Tokens → API Keys → Global API Key → View). Cloudflare recommends against it: the Global API Key carries every permission your login has, on every zone, and cannot be narrowed. Use a token if you can.

2. Connect it here

Open Integrations in your dashboard and choose Connect an account. Pick Your own DNS as the group and Cloudflare DNS as the account, fill in API token — or, for the older alternative, API key and Account email, and press Connect account.

We test what you paste before anything is saved. A key that does not work is never stored, and the answer says what was wrong with it. A key that works is kept encrypted in our secrets vault — never in our database — and is never shown again, not even to you.

What happens next

  • On any domain, open its DNS tab and choose this account as where the domain's
  • DNS is served from. We create the zone there if it does not exist and write the records the domain's sites and mail need.

  • When something on our side changes what a record must say — you move a site, switch CDN or
  • add a mailbox — we update the record on your account.

  • To finish the move, your domain's nameservers must point at Cloudflare. If the domain is
  • registered with us, or at a registrar you have connected, we set them for you; otherwise the domain's page shows the nameservers to set.

  • When you connect, we check that the key can list your zones, read records and change records.
  • The checklist beside the connection shows which of those we could confirm.

If it does not connect

A zone is missing. The token's Zone Resources does not include it. Edit the token to include that zone, or all zones — the token value does not change.

Cloudflare Registrar domains. A domain registered with Cloudflare Registrar can only use Cloudflare's nameservers, so its DNS always stays on Cloudflare.

It says the key was rejected. Almost always one of three things: a space or a line break copied with it, a key that has expired, or a key that was revoked or regenerated after you copied it. Create a fresh one and paste it again.

It connects, but something later fails. The key authenticates but lacks a permission the action needs. Create a new key with the permissions listed above, then disconnect the old connection and connect the new key.

Disconnecting

Open Integrations, find the account and press Disconnect. That deletes the stored key at once. Anything that was using it stops at its next action, and the screens that depended on it say so rather than failing quietly.

Disconnecting does not undo what was already done — records, deployments or settings we changed on your account stay as they are. If you think the key itself may have leaked, also revoke it at the vendor; disconnecting removes our copy, not theirs.

这篇文章尚未翻译成您的语言,因此您正在阅读英文版本。

博客最新动态

关于托管、搜索引擎优化以及大规模网站运营的最新文章。

从托管层看SEO与外链建设:2026年运营商视角

2026年托管服务如何影响索引与链接权重:保持页面可收录、在建站前审查老域名、无痕迹外链建设,以及关于基础设施对SEO实际能做什么和不能做什么的客观分析。

阅读文章

让WordPress既快速又安全:性能与插件检查清单

一份打造快速、安全 WordPress 的实用清单:服务器级缓存、按站点划分的对象缓存、值得使用的少数插件、保持技术栈更新,以及绝不能缓存的 WooCommerce 页面。

阅读文章

如何选择2026年托管式网络托管:买家指南

真正让优质托管主机区别于带有控制面板的廉价虚拟空间的核心要素——数据迁移、备份、隔离、真正的缓存以及诚实的扩容方案——以及如何在您做出承诺前对其进行评估。

阅读文章

阅读博客

还是没头绪?

每个套餐均包含技术支持,客服团队全天 24 小时在线,您可以用我们支持的任意 58 种语言与我们联系——我们将用您的语言为您解答。

联系客服 所有文章