How to mirror your DNS zones to Cloudflare as a secondary
Create a narrowly scoped Cloudflare token, choose zones one by one, and understand what gets rejected or removed.
The panel's own DNS is always the source of truth; Cloudflare is only a copy, and changes made at Cloudflare are overwritten by the next sync.
Steps
- In Cloudflare create an API token limited to the zones and permissions needed. The panel cannot verify a token's scope, so give it the narrowest you can.
- Open DNS, Cloudflare (admin only; one Cloudflare account per node) and paste the token once. It is stored encrypted and never shown or logged.
- Choose zone by zone which to mirror. There is no "mirror everything" switch.
- Use Sync now: it queues the zone, processing about one zone per minute.
Rules
- Only zones that already resolve to this server can be mirrored; this is checked against a recursive resolver and re-checked daily. A zone that stops pointing here is dropped and its records removed from Cloudflare.
- A zone that already exists in your Cloudflare account is rejected, not adopted: the sync would delete any record not present in the panel.
- The panel warns about the account's zone quota before it fills.
- A Cloudflare failure never affects your own DNS.
A customer who wants their own Cloudflare account does not need this: they change the name servers at their registrar and remove the zone from the node.
Last updated: 2026-10-10