- Account-wide token with per-project override for domains in another Cloudflare account
- Adding a domain creates or updates its A record, proxied or not
- Records follow a service when it moves servers, keeping their proxy setting
- Flexible-SSL zones switch the domain to HTTP-only so nothing redirect-loops
- DNS check compares every custom domain with the server it runs on and fixes them with one click
- Wildcard records for free subdomains are created per server automatically
Tokens
Add one Cloudflare API token under Settings → DNS and every project uses it. A project can hold its own token when its domains live in another Cloudflare account; the project token wins. Tokens are checked before they are saved and stored encrypted.
Records that follow
Adding a custom domain offers to create or update its A record, proxied or not. The Domains tab shows where each domain currently points, with Point here when it is not this server. When a service moves to another server, records that pointed at the old server follow it and keep their proxy setting; records pointing anywhere else are never touched.
DNS check
Settings → DNS check reads every custom domain in the account from Cloudflare and compares it with the server its service runs on. Wrong IPs, missing records and Flexible-SSL redirect loops are listed with their own fix (point the record here, create it, switch the domain to HTTP-only), plus Fix all after a confirmation. CNAMEs, domains outside the token’s zones and services without a server are listed as not managed. Nothing changes until you click.