Site
- Log in to the Cloudflare dashboard and select your account.
- In Account Home, select Website.
- click Add a Site.
- Enter the new domain name and click Add site.
- Chose the free plan and click Continue.
- Import the exisiting zone records and add new if needed.
- Click Continue.
- Log in to the administrator account for your domain registrar and change the name servers as described.
- Wait until the domain servers are active.
- Click Done, check nameservers.
- Click Get started.
- Active all and click finish
- Click Check nameservers and wait until the new nameservers are confirmed.
- Log in to the Cloudflare dashboard and select your account.
- In Account Home, select Website.
- Select the specific website.
- In the left navigation chose DNS and click Settings.
- Click Enable DNSSEC.
- Copy DS Record and Public Key to the registrar and login to this portal.
- Click confirm in the cloudflare portal.
- DNSSEC is now pending while is is waited for the DS to be added to the registrar. This usually takes ten minutes, but can take up to an hour.
- Validate the success.
To configure TLS und Secure HTTP Headers follow theses steps
- Log in to the Cloudflare dashboard and select your account.
- In Account Home, select Website.
- Select the specific website.
- In the left navigation chose SSL/TLS and click Edge Certificates.
- Keep Total TLS deactivated.
- Activate Always Use HTTPS.
- Activate HSTS.
- Confirm that I understand.
- Click Next.
- Enable HSTS (Strict-Transport-Security).
- Max Age Header: 12 month.
- Enable Apply HSTS policy to subdomains.
- Enable Preload.
- Enable No-Sniff Header.
- Click Save.
- Chose TLS 1.3 as Minimum TLS Version.
- Enable Opportunistic Encryption.
- Enable TLS 1.3.
- Enable Certificate Transparency Monitoring. These configuration will provide the following HTTP Headers zone wide:
- strict-transport-security: max-age=31536000; includeSubDomains; preload
- x-content-type-options: nosniff