📋 Cloudflare DNS setup guide
This guide shows you exactly how to add DMARC records in Cloudflare for your ARMD Managed DMARC Protection service. It shows you where to log in, where to enter each DNS record and usually takes about 10 minutes.
You’ll use the DNS values in your ARMD.digital onboarding email, and the steps below show you where to enter them.
Not with Cloudflare? Choose your DNS provider from our DMARC DNS setup guides.
🧾 Before you start
You’ll need two things:
- Your ARMD onboarding email containing your DNS records (record type, host name and value for each).
- A Cloudflare login with access to your domain. If your website was set up by an agency or IT provider, the domain may sit under their Cloudflare account rather than yours.
Don’t have the login? No problem. This is usually handled by whoever set up your website or email. Simply forward your ARMD onboarding email to your IT provider or web developer. They’ll have everything they need.
👥 Steps to Add DMARC Records in Cloudflare
Step 1: Log in to the Cloudflare dashboard
Go to dash.cloudflare.com and log in.
Step 2: Find your domain
From the account home screen, select your domain.
Step 3: Open DNS Records
Select DNS from the left menu, then Records. This shows all the current DNS records for your domain. Don’t change or delete anything here — you’re only adding new records.
Step 4: Add your records
Click Add record, then for each record in your ARMD onboarding email:
- Select the record Type from the dropdown (TXT or CNAME, as shown in your email).
- Copy the Host / name value from your email into the Name field.
- Copy the Value / destination from your email into the Content (or Target) field.
- For CNAME records, set Proxy status to DNS only (the cloud icon turns grey). Cloudflare switches this on (orange) by default, and a proxied record will stop the service working.
- Leave the TTL on Auto.
- Click Save.
Check that your new record appears in the list, then repeat for the next record.
Copy and paste — don’t retype. A single missing character will stop the record from working. Watch for your browser or email client adding spaces when copying.
Step 5: You’re done — we take it from here
There’s nothing further to submit. We check your domain automatically and will confirm by email as soon as your records are live. Cloudflare publishes new records almost immediately, so confirmation is usually quick.
Adding these records is the first step of your Managed DMARC Protection service — once they’re live, we handle the monitoring and protection phases from here, and we’ll be in touch if any of your email services need a setting switched on.
📋 Cloudflare-specific notes
The orange cloud, explained. Cloudflare’s proxy (the orange cloud icon) routes website traffic through Cloudflare’s network. That’s useful for websites, but email authentication records aren’t website traffic — a proxied CNAME returns Cloudflare’s addresses instead of the real destination, so verification and reporting fail. Set the records from your ARMD onboarding email to DNS only and leave them that way. Don’t change the proxy setting on any of your existing records.
Domain under someone else’s account? Agencies and IT providers often manage client domains inside their own Cloudflare account. If you log in and don’t see your domain, you may need to be added as a member with DNS permissions, or simply forward your ARMD onboarding email to whoever manages it.
📚 Frequently asked questions
No. You are adding new records, not changing existing ones. Your mail flow and website continue to operate as normal while the records are added.
Cloudflare publishes new records almost immediately — usually within minutes.
You don’t need to check yourself — we monitor your domain and confirm by email once the records are live.
Your login may not have DNS permissions for this domain, or the domain may sit under a different Cloudflare account — often an agency or IT provider’s. Ask whoever set up your website to either make the changes or add you as a member with DNS editing rights, or forward this guide to them.
What matters is where your DNS is hosted, not where your domain was registered or your website lives. If you’re not sure, we confirm this for you during onboarding — your onboarding email names your DNS provider.
For most domains, the DNS records are the main task. Once they’re live, your first DMARC reports show us which services send email on your behalf — some of these, like Microsoft 365 or newsletter platforms, may also need DKIM signing switched on in their own settings.
We’ll contact you in the first few weeks about any that need attention and tell you exactly what to do; it’s usually one setting per service.
✅ Need a hand?
If you get stuck at any step, reply to your onboarding email — it contains everything about your domain, so you’ll reach us with the full picture. If an IT provider manages your domain, forwarding them that email and this guide is usually the fastest route.