# What the orange cloud actually does — LLM Prompt

> **How to use this file:** Paste the entire contents into Claude, ChatGPT, Gemini, or any LLM as your opening message. It gives the model the whole guide, so it can walk you through it, ask where you have got to, and help when something does not behave.
>
> *Source: [https://documentation.elmspark.com/guides/what-the-orange-cloud-does/](https://documentation.elmspark.com/guides/what-the-orange-cloud-does/)*

---

You are helping me with the following. Use this guide as your reference. Work through it with me, ask what I have already done, and help me troubleshoot. Where a step changes something on a live site, a domain, or a server, tell me what it will do and wait for me to confirm before we go on. If something here contradicts what I am actually seeing, say so rather than guessing.

**What this covers:** Cloudflare's two switches explained plainly: nameservers versus the orange cloud, the SPF record an automatic import will miss, and the one setting that breaks a PageMotor site.

CLOUDFLARE, PLAINLY

# What the orange cloud actually does

Five short lessons on the two switches people confuse, the record an automatic import will miss, and the one setting that breaks a PageMotor site outright.

Five lessons, about seven minutes

1. Two different things are both called "DNS"
2. What moving your nameservers changes
3. The record an import will miss
4. Who provides the certificate
5. The setting that breaks PageMotor

This explains the ideas. For the actual steps, follow [Cloudflare for DNS](https://documentation.elmspark.com/hosting/cloudflare/).

Lesson 1

## Two different things are both called "DNS"

Almost every muddled Cloudflare conversation comes from this, so it goes first.

### Nameservers

**Who answers questions about your domain.**

Someone types your address. Their computer asks "where is that?" Your nameservers answer.

You set these at your registrar.

### The orange cloud

**Whether visitors reach your server directly or go through Cloudflare first.**

Grey: straight to your server. Orange: through Cloudflare, which then fetches from your server.

You set these per record, inside Cloudflare.

They are separate switches and they do separate jobs. You can move your nameservers to Cloudflare and leave every record grey, in which case Cloudflare is answering the address question and nothing else. Plenty of sites run exactly that way on purpose.

**Why does this cause so much confusion?**

Because "I moved my DNS to Cloudflare" and "it is still DNS-only" are both true at the same time, and they sound like a contradiction. The first is about nameservers. The second is about the orange cloud. Once you hold them apart, most of the confusion disappears.

Lesson 2

## What moving your nameservers changes

Less than people expect, which is the good news.

Think of it as changing which office holds your address book. The addresses in the book do not change. Only the office holding it does.

If the records are copied across correctly, visitors notice nothing at all. Your site is served from the same machine, on the same address, by the same software. Your email carries on arriving.

**The changeover is not a moment, it is a window.** For a while, some computers still ask your old provider and some ask Cloudflare. If both hold identical records, everyone gets the same answer either way and nobody sees a problem. That window can last up to 48 hours, because the record naming your nameservers is allowed to be remembered that long.

Which is also why a domain can look like it has not moved when it has. The answer is not wrong, just remembered from earlier.

**How do I see the real answer rather than a remembered one?**

Ask the registry directly, which is the authority for who your nameservers are:

```
dig NS example.com @a.gtld-servers.net +noall +authority
```

Or ask a public resolver rather than whatever your network hands you: `dig NS example.com @1.1.1.1`

Lesson 3

## The record an import will miss

When you add a domain, Cloudflare scans your current DNS and copies what it finds. It is a genuine time-saver and it is explicitly best-effort.

Here is the failure that survives a careful check, because the usual advice does not catch it.

Your SPF record says who is allowed to send email as your domain. Sometimes it does not name your mail provider directly. It points at *another record under your own domain*, and that second record names the provider.

```
example.com                    TXT  "v=spf1 include:dc-a1b2c3d4._spfm.example.com ~all"
                                             |
                                             v
dc-a1b2c3d4._spfm.example.com  TXT  "v=spf1 include:_spf.google.com ~all"
```

The scan finds the first record, because your own domain name is an obvious place to look. It cannot find the second one.

That is not carelessness on Cloudflare's part. DNS cannot be listed from outside. There is no "show me everything" request. A scanner has to guess names and try them, and `dc-a1b2c3d4._spfm` is not a name anybody guesses.

**So the checklist passes and the chain is broken.** You confirm SPF is present, because it is. What is missing is the record it points at. Your SPF now refers to something that does not exist, mail from your domain starts failing its check and drifting into spam folders, and nothing anywhere tells you. You find out when somebody mentions your email stopped arriving.

Domains that have been through GoDaddy's mail settings often carry a chain like this. So do some Microsoft and hosting-panel setups.

**How do I check mine?**

Read your SPF, and if it contains an `include:` pointing at something under your own domain, resolve that target too:

```
dig +short TXT example.com
dig +short TXT dc-a1b2c3d4._spfm.example.com
```

If the second one returns nothing after your move, that is the fault. Copy the record across by hand, exactly as it was.

The wider habit worth forming: export your zone from the old provider *before* you move, then compare line by line afterwards. An import is a good start, never a guarantee.

Lesson 4

## Who provides the certificate

Back to the second switch. It decides who is responsible for the padlock in the address bar.

### Grey cloud

The visitor reaches your server directly.

**You provide the certificate**, on your own machine, and you renew it.

### Orange cloud

The visitor reaches Cloudflare, and Cloudflare reaches your server.

**Cloudflare provides the certificate** at its edge, free and automatically.

For one site this is a small convenience. For anyone running many sites, or creating new ones regularly, it is the difference between a certificate job per site and no certificate job at all.

**One condition worth knowing.** Cloudflare's free certificate covers your domain and one level below it. `shop.example.com` is one level down and is covered. `eu.shop.example.com` is two levels and is not. Wildcards are not covered on the free tier either. Keep to one level and it stays free.

**If Cloudflare provides the certificate, does my server still need one?**

Yes, and lesson five is why. Cloudflare's certificate covers the visitor's journey to Cloudflare. The second journey, Cloudflare to your server, needs its own encryption, which means a certificate on your machine too. Cloudflare will issue you a free one for that purpose if you want it.

Lesson 5

## The setting that breaks PageMotor

If you ever turn a record orange, one setting has to be right first. Getting it wrong does not weaken your site slightly. It takes it down.

With Cloudflare in front, there are two journeys: visitor to Cloudflare, and Cloudflare to your server. The SSL/TLS encryption mode decides whether that second journey is encrypted.

| Mode | Cloudflare to your server | Verdict |
|---|---|---|
| **Flexible** | Unencrypted, plain HTTP | Breaks PageMotor |
| **Full (strict)** | Encrypted and the certificate checked | Use this |

Why Flexible specifically breaks PageMotor, rather than merely being less secure:

1. The request arriving at your server is plain HTTP.
2. PageMotor looks at it, concludes the site is not running securely, and writes its links as `http://`.
3. Cloudflare sees a plain link and sends the visitor back round to be upgraded.
4. PageMotor writes another plain link. Round again.
5. The browser gives up and shows a redirect loop.

**It is a whole-zone setting.** Changing the mode applies across the domain, not only to the record you had in mind. Set it deliberately before anything goes orange, rather than discovering it during.

**Why does the mode not matter while everything is grey?**

Because no traffic is passing through Cloudflare at all, so there is no second journey for the setting to govern. It becomes load-bearing the moment the first record turns orange, which is exactly when people are least expecting a new failure.

When you actually do it

## The steps, rather than the ideas

This page is the mental model. The procedure lives next door and covers account setup, the record review, changing nameservers at your registrar, DNSSEC, pointing the record at your server, the Mailgun records, and letting an AI assistant manage the zone for you.

[Cloudflare for DNS, step by step](https://documentation.elmspark.com/hosting/cloudflare/)

Two things from this page appear there as warnings at the exact step where they bite: the chained SPF record in the review step, and the encryption mode when you turn the cloud orange.

---

*Generated from the guide above. If something here looks wrong, the guide is the source of truth: https://documentation.elmspark.com/guides/what-the-orange-cloud-does/*
