# How to set up Cloudflare Enterprise

> Serve your whole site from Cloudflare's network with the Cloudflare Enterprise Add-on. Everything happens in the xSpeed Cache plugin: get both licenses, run the checks, add the DNS records, then manage purging and edge settings.

- Category: Network
- Updated: 2026-10-07
- Canonical: https://xspeedcache.com/docs/cloudflare-enterprise/

---

Cloudflare Enterprise serves your whole pages from Cloudflare's network, so most visitors never reach your server. You set it up in the xSpeed Cache plugin on your site, and xSpeed keeps it in step with your site after that. You don't need a Cloudflare account.

> **Where to find it**
>
> 1. In your WordPress admin, click **xSpeed Cache** in the left menu.
> 2. In the xSpeed Cache sidebar, open the **Network** group.
> 3. Click **Cloudflare Enterprise**.
>
> *Shortcut: open `wp-admin/admin.php?page=xspeed#/network/cloudflare-enterprise` directly.*
>
> ⭐ This panel needs **xSpeed Cache Pro** and the **Cloudflare Enterprise Add-on**.

## What you get, and what you need

What it adds to your site:

- Whole pages served from Cloudflare's network
- Managed firewall and rate limiting
- Image optimization on Cloudflare
- Cloudflare cleared every time you publish

You need two things, both on the same WordPress site:

1. **xSpeed Cache Pro**, installed and with its license active.
2. **The Cloudflare Enterprise Add-on**, a separate license key. It is a license, not a second plugin. It runs inside xSpeed Cache Pro.

The add-on costs **$5 per domain, per month**, on top of xSpeed Cache Pro. See [Pricing](https://xspeedcache.com/pricing/#cloudflare-enterprise).

If your hosting is xCloud and you bought Cloudflare Enterprise from xCloud, you don't need the add-on. See [Sites whose Cloudflare Enterprise comes from xCloud](#sites-whose-cloudflare-enterprise-comes-from-xcloud).

## Step 1: Open Cloudflare Enterprise in WordPress

Open **xSpeed Cache › Network › Cloudflare Enterprise**. Until both licenses are active, the panel opens on **You need two things**.

![The Cloudflare Enterprise panel before the add-on key: You need two things](https://xspeedcache.com/_astro/04-plugin-cfe-purchase-path.VscVUJ9w.png)

- **1 · Plugin: xSpeed Cache Pro.** The add-on runs inside it.
- **2 · Add-on: Cloudflare Enterprise Add-on.** Sold separately, with its own license key.
- **The offer card** on the right shows the price, what the add-on adds, and a **Get the add-on** button.

The pill beside the title and the two steps follow what your site has:

| What your site has | Pill | Step 1 shows | Step 2 shows |
| --- | --- | --- | --- |
| Free plugin only | Pro and add-on needed | Not installed, **Get Pro** | No license key |
| Pro installed, license not active | Pro license and add-on needed | License not active, **Activate License** | No license key |
| Pro licensed, no add-on key | Add-on needed | Active on this site, Done | No license key |

If your xSpeed Cache Pro is too old for the add-on, step 1 says **Update needed** instead, with an **Update Pro** button that opens your Plugins screen. Update Pro, then come back.

With both licenses active, the panel skips this screen and opens on **Checks before setup** ([Step 4](#step-4-run-the-checks-and-enable)).

Bought already? Click the link under the steps. It reads **Already bought both? Enter your license keys**, or **Already have the add-on? Enter its license key** when Pro is already active. It opens the License page. **Activate License** goes to the same page.

Until you enter the add-on key, the xSpeed Cache sidebar also shows a **Cloudflare Enterprise** offer with the price. **Get it** opens this panel. The offer gets smaller when the window is short: a full card, then a compact card with a **Get it** button, then a one-line link. In a collapsed sidebar it is an icon, and the offer opens when you point at it. You can dismiss it.

## Step 2: Get what is missing

1. **Pro.** **Get Pro** opens the [pricing page](https://xspeedcache.com/pricing/). After you buy, download the Pro plugin from your [WPDeveloper account](https://store.wpdeveloper.com/account/) and install it beside the free plugin. [How to install xSpeed Cache Pro](https://xspeedcache.com/docs/installing-pro/) walks through it.
2. **The add-on.** **Get the add-on** opens the store's checkout. There is nothing to download. You get a license key.

## Step 3: Enter both license keys

Both keys go on one page: **xSpeed Cache › Settings › License**. Find your keys in your [WPDeveloper account](https://store.wpdeveloper.com/account/).

1. In **xSpeed Cache Pro license**, paste the Pro key and click **Activate**.
2. Enter the 6-digit code the store emails you and click **Verify**. Click **Resend** if it does not arrive.
3. In **Cloudflare Enterprise Add-on license**, paste the add-on key and click **Activate**. Confirm it with the emailed code the same way.

When the add-on key is active, the card says **License active — one step left**. Your domain is not on Cloudflare yet. Go on to the Cloudflare Enterprise page; the card links to it.

If the add-on key is refused, the card says why:

| The card says | What to do |
| --- | --- |
| That license has expired | Renew it. Nothing on the site has to change. |
| That license has been disabled | Contact support to find out why. |
| That license is not active for this site | It may already be used on all the sites it allows. |
| That key is for a different product | The add-on has its own key, separate from xSpeed Cache Pro. |
| That key was not recognized | Check it against your receipt, or paste it again. |

The Pro license has a 7-day grace window after it expires. The add-on license has none: when it lapses, Cloudflare Enterprise stops.

On a multisite network, only a network admin can change the add-on key. The whole network shares it.

## Step 4: Run the checks and enable

Go back to **xSpeed Cache › Network › Cloudflare Enterprise**. With both keys active, the panel shows **Put \<your domain> on Cloudflare Enterprise** and **Checks before setup**. It starts with three facts:

- **You need two things.** xSpeed Cache Pro, active and licensed, and the Cloudflare Enterprise Add-on, active on this site.
- **There is no second plugin to install.**
- **You will add records at your DNS provider twice, with a short wait in between.** Have that login ready. If the plugin can tell who runs your DNS, it names them and offers **Open DNS page**.

![Checks before setup, all passing](https://xspeedcache.com/_astro/06-plugin-checks-before-setup.UFv_ofIu.png)

The checks run on their own. They only look; they do not change anything.

| Check | Passes when | If it fails |
| --- | --- | --- |
| Your domain is online | The domain points somewhere | Point it at your server first. |
| Not using Cloudflare already | The domain does not go through a Cloudflare account | In that account, set the record to DNS only (the gray cloud). If your host runs that account, ask them. |
| Your site works over HTTPS | Your server answers securely | Ask your host to add a valid certificate. If your server answers with an error, the check warns but setup can continue. |
| This is your site's address | The domain matches the site | A warning only: the bare domain and www are the same site, and setting up one covers both. |

If the domain is already on Cloudflare Enterprise somewhere else, for example from a hosting dashboard, the second row reads **Not on Cloudflare Enterprise already** and fails. Remove it there first.

Fix anything that fails, then click **Run the checks again**. If only the first or third check fails and you know why, **Enable anyway** lets you go on. It is never offered for the Cloudflare check.

When the checks pass:

1. Leave **Cache pages at Cloudflare's edge** on if the panel offers it. Cloudflare then stores only the pages xSpeed caches, for as long as xSpeed keeps them. You can turn it off later under Performance.
2. Click **Enable Cloudflare Enterprise**. The button reads **Connecting to Cloudflare…**.

The panel then says **Setting up \<your domain> on Cloudflare**. This takes up to a minute. You can leave the page and come back: setup carries on by itself.

## Step 5: Add the DNS records

Once setup has started, the panel shows what to do next in a card at the top:

- A line with your domain and **Your turn**, **Nothing to do** or **Needs attention**.
- A title that names the next move, for example **Add 2 records at Cloudflare** or **Point example.com at Cloudflare**.
- **Open your DNS settings at \<provider>**, when the plugin knows who runs your DNS.
- **Check again**, to look for your records right away, and **Cancel setup**.

The page also checks on its own while it is open, and says when it last checked. Beside the records, **Connection checks** shows the four steps Cloudflare has to pass.

![The setup screen: what to do next, the step 1 records and the connection checks](https://xspeedcache.com/_astro/06b-plugin-setup-your-turn.CVxYquQs.png)

The records are listed in two groups. Each record has **Copy host** and **Copy value** buttons. Copy them from your own panel: the values are different for every domain.

### 1. Prove you own the domain

Safe to add now. Your visitors are not affected.

| Record | Host | What it is for |
| --- | --- | --- |
| TXT | `_cf-custom-hostname.<your domain>` | Proves to Cloudflare that you own the domain. |
| CNAME | `_acme-challenge.<your domain>` | Lets Cloudflare issue and renew the security certificate. |

Keep both records after setup. The certificate renews through them. If you delete them, the site keeps working until the certificate fails to renew.

If your site is on a subdomain, such as `shop.example.com`, add the records in the DNS zone of `example.com`. Most providers add `example.com` to the name for you, so the host you enter is `_cf-custom-hostname.shop` and `_acme-challenge.shop`. The panel shows the exact host to enter.

### 2. Send visitors through Cloudflare

This is the step that moves your visitors. It stays locked until Cloudflare confirms you own the domain and issues the certificate. Switching earlier would show visitors an error until the certificate is ready.

For your main domain, choose one of two options. Use only one. If you add both, some visitors can go to the wrong place.

- **Option 1: one CNAME record.** Use it if your DNS provider lets you add a CNAME for the main domain.
- **Option 2: two A records.** Use it if it does not. When the panel knows your provider does not allow it, option 1 says **Not available at \<provider>**.

If your DNS is at Cloudflare, set each new record to DNS only (the gray cloud). A proxied record puts your own Cloudflare account in front and the setup fails.

The www name has its own CNAME. It is optional: add it so visitors who type the www address also go through Cloudflare. You can add it later.

Before you change these records, the panel saves what they pointed at under **Your records before the switch**. Keep them in case you ever go back to your own server.

If an old record for the same name is still there, the card says **Remove the old record for \<name> at \<provider>**. Delete it, then click **Check again**.

### What the record statuses mean

| Status | Meaning |
| --- | --- |
| Not checked yet | The first check has not run. It runs within a minute. |
| Not found at your DNS provider | The record is not there yet. |
| Added under the wrong name | Your provider adds the domain to the name for you. Enter only the part before it. The card says **Fix the Host name…**. |
| Found, but different | A record exists with another value. Change it to the value shown. |
| Hidden by your DNS provider | Your provider answers the certificate check itself. See [If your DNS is at Cloudflare](#if-your-dns-is-at-cloudflare). |
| Added. Spreading across the internet, usually under an hour. | Nothing to do but wait. |
| Added. DNS changes can take up to an hour. | The same, for the step 2 records. |
| In place | Done. |

Each name in step 2 also has a line of its own:

| Line | Meaning |
| --- | --- |
| Pointing at your server (\<address>) | Still going to your own server. Change it to one of the options. |
| Changed. Spreading across the internet, usually under an hour. | Nothing to do but wait. |
| Pointing at Cloudflare | Done. |
| Optional | The www name, not added yet. |

### How the connection checks read

The panel checks four steps in order.

1. **Cloudflare confirmed you own the domain**
2. **Security certificate ready**
3. **Visitors reach Cloudflare**
4. **Cloudflare serves your pages**

Under each step is one line:

- **Waiting for your records**: it is your turn. Add the records above.
- **Your records are in place, waiting for confirmation**: your part is done. Cloudflare has not confirmed yet.
- **Waiting 12 min · usually within 15 min**: how long so far, and what is normal.
- **Checked after visitors reach Cloudflare**: the last step waits for step 3.
- **Your DNS provider is answering the certificate check itself**: see the next section.
- **Passed 49 min ago**: done.
- **Not passing yet**: the step has never passed.
- **Passed 3 d ago · failing for 2 h**: it worked and has stopped. Something changed, often a deleted record.

If your records are right and Cloudflare has still not confirmed them after an hour, the card says **Your DNS is done, but Cloudflare has not confirmed it**. Contact support.

### If your DNS is at Cloudflare

Set every record you add for this setup to DNS only (the gray cloud), not proxied.

When your domain's DNS is in your own Cloudflare account, Cloudflare's own SSL (Universal SSL) can answer the certificate check, so the record you added cannot be seen. The panel says **Turn off Universal SSL for \<your domain> at Cloudflare** or **Your DNS provider is hiding the certificate record**.

In your Cloudflare account, turn off Universal SSL (SSL/TLS → Edge Certificates) for this domain, then click **Check again**. Leave it off: the certificate renews through the same record, and turning it back on can hide the record again.

### If the certificate takes longer than usual

Some certificates only finish after visitors reach Cloudflare. If the certificate step waits much longer than usual, step 2 shows **Waiting longer than usual** and a **Switch now anyway** link. Use it only if you have waited. Visitors may see a certificate warning for a short time.

When all four steps pass, the panel says **\<your domain> is on Cloudflare** once, and the Domain tab reads **Serving from Cloudflare**.

## Day to day: purging, edge settings and Health

Once the domain is live, most things run on their own. When you publish or update a post, xSpeed clears the changed pages on Cloudflare too. **Purge all** in the plugin's top bar also clears Cloudflare Enterprise.

The panel now has tabs: **Performance**, **Security**, **Advanced**, **Domain**, **DNS** and **Danger zone**. It opens on Performance.

### Is it working?

The **Domain** tab shows the verdict, the certificate, this month's usage and the last purge.

| Verdict | Meaning |
| --- | --- |
| Serving from Cloudflare | All good. |
| On Cloudflare. Pages are still being cached. Check again in a minute. | Normal right after setup or a clear. |
| On Cloudflare, but pages are not cached | The line under it names the cause: xSpeed is not caching the page, or Cloudflare page caching is off under Performance. |
| Visitors do not go through Cloudflare yet | Your DNS still points elsewhere. |
| Cloudflare's firewall blocked our check. It may block visitors too. | Look at the Security tab. |
| Your server answered with an error | Fix the error on your server. |
| We could not check your site from outside | The **From your server** row below checks from your own server instead. Click **Check now**. |

The usage line reads **\<used> GB of \<allowance> GB this month · \<percent>%**. It turns amber at 80%. If the allowance runs out before the 1st, Cloudflare Enterprise may be switched off for this site until then.

**License use this period** lists the domains your add-on license has covered. A domain you removed still counts until the license renews.

If the pill reads **Something changed**, a check that used to pass is failing. The panel says which one. **Finish DNS setup** takes you to the records.

### Purging

- **Purge changed pages** (top right, on every tab) clears the pages that changed since the last clear.
- **Clear everything on Cloudflare** (open **More** on the Domain tab) drops every cached page, image, script and style for the domain. Visitors reach your server until the cache refills. It asks first.

The line **Last purge 14:57 · cleared this site's pages · verified** records the last clear. Instead of verified it can say **verifying**, **Cloudflare still served the old page**, **your server served the old page** or **could not verify**.

If you see **Old pages stay after a clear**, Cloudflare was cleared but your host's own server cache still serves old pages for a while. Ask your host to clear it. On nginx servers the panel may say **Each clear empties the whole site until you update your server rules**. Click **Show the nginx block** and give it to your host.

### Edge settings

Switches are on the **Performance** and **Security** tabs.

| Setting | What it does |
| --- | --- |
| Cloudflare page caching | Caches your pages on Cloudflare. xSpeed's own page cache then serves only what Cloudflare asks your server for. |
| Caching | Caches images, CSS and JavaScript. Not needed while Cloudflare page caching is on. |
| Early hints | Lets browsers start loading CSS and images before the page arrives. |
| Scrape shield | Hides email addresses on your site from spam bots. |
| Image optimization | Off, Lossless or Lossy. Makes images smaller. |
| SSL cipher | Modern, Compatible or Legacy. Modern is safest. Legacy works with old browsers. |
| WAF | Blocks known attacks with Cloudflare's managed firewall rules. |
| Rate limiting | Slows any address that sends more than 200 requests a minute, counted at each Cloudflare location. It can also slow your own uptime monitors and cache warmers. |
| Browser integrity check | Blocks requests that look like bad bots. |
| Under attack mode | Every visitor waits on a check page for a few seconds. Turn it on only during an attack. |
| AI crawler blocking | Stops known AI crawlers from collecting your content. |

A change takes about 20 seconds to save. The row then says **Saved. Cloudflare is still applying it, which can take a few minutes.** Nothing else to do.

**Settings in use** shows the **Cloudflare cache lifetime**, which xSpeed sets: Cloudflare keeps a page as long as your Page Cache expiry. **Included, always on** lists what every domain gets with nothing to set up: Always Online, Tiered Cache, HTTP/3, Brotli, faster repeat visits and automatic HTTPS rewrites. On the **Advanced** tab, **Pages Cloudflare never caches** follows your [Page Cache](https://xspeedcache.com/docs/page-cache/) exclusions, so edit them there.

### What Health warns about

**xSpeed Cache › Health & insights** checks how Cloudflare treats pages xSpeed marks as do-not-store. On a healthy site the row reads **Edge cache being told what not to store**.

If it reads **Cloudflare stores pages marked do-not-store**, a test page sent with "do not store" came back from Cloudflare's cache. Cart, account and other per-visitor pages can then reach the wrong visitor. With the add-on you have no Cloudflare account to change, so contact support. If your Cloudflare Enterprise comes from xCloud, ask xCloud.

### Removing the domain

**Danger zone › Remove** takes the domain off Cloudflare.

Clicking it opens **Remove this domain from Cloudflare Enterprise?**, which lists the records to point back at your own server. Do it in this order, and there is no downtime:

1. Change those records at your DNS provider.
2. Wait for the change to take effect.
3. Come back, tick **I understand my DNS must point back to my own server, or the site will be unreachable.** and click **Remove**.

Your add-on license is kept, so you can put the domain back later without buying again. If you set it up again, Cloudflare is pointed at the server your site runs on at that time, so moving to a new server in between is fine.

**Cancel setup**, on the setup screen, removes a domain that is not live yet. If you have not changed the step 2 records, nothing changes for your visitors. You can delete the step 1 records, or leave them.

## If Cloudflare stops serving your site

- **Off Cloudflare.** Cloudflare is not serving the domain right now. Your setup and records are kept. Click **Put it back on Cloudflare**. It checks the records again, which usually takes a few minutes.
- **This domain is no longer on Cloudflare.** If your DNS still points at Cloudflare, your site is unreachable until you change it. The panel shows **Put your DNS back** with the records your domain had before. Add them again at your DNS provider. When the change has spread, **Set up again** starts over. If the panel offers **Reconnect** instead, the domain is still yours: reconnecting gives you new ownership records, and the step 2 records do not change.
- **This domain moved to another site.** Another site proved it controls the domain. If you added DNS records for Cloudflare, change them back.

## Multisite

On a network, the main site sets up Cloudflare Enterprise, and a network admin makes the changes. A subsite that shares the main site's domain shows **The main site of this network sets up Cloudflare Enterprise.** Once the main site is live, the subsite's panel says so, and offers **Purge this site's pages** where it can clear its own pages. See [Multisite](https://xspeedcache.com/docs/multisite/).

## Sites whose Cloudflare Enterprise comes from xCloud

If your site is hosted on xCloud and you bought Cloudflare Enterprise there, xCloud runs it and you don't need the add-on. The panel then says **Cloudflare Enterprise is managed by xCloud**, with an **Open xCloud** button. Change edge settings and DNS in your xCloud dashboard, not in xSpeed. There is nothing to set up in the plugin.

Clearing pages goes through xCloud's own purge plugin. What reaches Cloudflare depends on whether that plugin takes xSpeed's purges yet. The panel tells you which case you are in:

|  | xCloud's plugin takes xSpeed's purges | It does not yet |
| --- | --- | --- |
| Post you edit | Cleared on Cloudflare | Cleared on Cloudflare, by xCloud's plugin |
| Home page, archives, feeds | Cleared on Cloudflare | Stay cached on Cloudflare until they expire |
| Purge All in xSpeed | Reaches Cloudflare | Does not reach Cloudflare |

In the second case, ask xCloud to update its purge plugin.

## Walkthrough video

[Watch the walkthrough (4 min, MP4)](https://res.cloudinary.com/ertbvbhk/video/upload/v1791299326/261006_210841_cfe-walkthrough.mp4). It was recorded before setup moved fully into the plugin, so it opens on xSpeed Hub. You don't need the Hub: start in the plugin, as this guide does. The rest covers the plugin's panel and License page, and a live domain's records, progress steps, purge controls and edge settings.

## FAQ

**Do I need a Cloudflare account?** No. If your domain already goes through your own Cloudflare account, set its record to DNS only (the gray cloud) before setup.

**Do I need xSpeed Hub?** No. Everything is done in the plugin on your site.

**Is the add-on a second plugin?** No. It is a license key for xSpeed Cache Pro. There is nothing else to install.

**What does it cost?** $5 per domain, per month, on top of xSpeed Cache Pro.

**Do I have to keep the page open during setup?** No. Setup carries on by itself. The page only checks more often while it is open.

**I added the records. Why is it still waiting?** DNS changes take time to spread, usually under an hour. Check each record's status and click **Check again**. If a record says Added under the wrong name, your provider added the domain for you: enter only the part before it.

**My DNS provider does not allow a CNAME on the main domain.** Use option 2, the two A records, for the main domain, and the CNAME for www.

**Why is step 2 locked?** Sending visitors to Cloudflare before the certificate is ready shows them an error. Step 2 unlocks once ownership and the certificate pass.

**The certificate step is stuck and my DNS is at Cloudflare.** Turn off Universal SSL for the domain in your Cloudflare account (SSL/TLS → Edge Certificates), then click **Check again**. The panel says so when it sees this.

**Can I delete the ownership records after setup?** No. Keep both. The certificate renews through them.

**My page changed but visitors see the old one.** Wait a moment, then check the last purge line. If it says your server served the old page, or you see Old pages stay after a clear, your host's own cache is the cause. Ask your host to clear it.

**Does removing a domain free up my license?** Not right away. A removed domain still counts toward your license until it renews.

**What happens if the add-on license expires?** Cloudflare Enterprise stops. There is no grace window. Renew the key on the License page.
