How to mirror your DNS zones to Cloudflare as a secondary

How-to Integrations and business cloudflarednssecondarymirror

Create a narrowly scoped Cloudflare token, choose zones one by one, and understand what gets rejected or removed.

The panel's own DNS is always the source of truth; Cloudflare is only a copy, and changes made at Cloudflare are overwritten by the next sync.

Steps

  1. In Cloudflare create an API token limited to the zones and permissions needed. The panel cannot verify a token's scope, so give it the narrowest you can.
  2. Open DNS, Cloudflare (admin only; one Cloudflare account per node) and paste the token once. It is stored encrypted and never shown or logged.
  3. Choose zone by zone which to mirror. There is no "mirror everything" switch.
  4. Use Sync now: it queues the zone, processing about one zone per minute.

Rules

  • Only zones that already resolve to this server can be mirrored; this is checked against a recursive resolver and re-checked daily. A zone that stops pointing here is dropped and its records removed from Cloudflare.
  • A zone that already exists in your Cloudflare account is rejected, not adopted: the sync would delete any record not present in the panel.
  • The panel warns about the account's zone quota before it fills.
  • A Cloudflare failure never affects your own DNS.

A customer who wants their own Cloudflare account does not need this: they change the name servers at their registrar and remove the zone from the node.

Last updated: 2026-10-10