Start with authoritative DNS

Treat DNS records as production configuration with clear ownership and change control. Proxy only services that are compatible with the expected edge behaviour and keep non-web protocols explicit rather than assuming every hostname belongs behind the same proxy model.

Protect the origin as well as the edge

A WAF is less valuable if attackers can bypass it and reach an unrestricted origin directly. Restrict origin access where practical, manage TLS correctly and ensure administrative interfaces are not accidentally exposed through alternate hostnames or addresses.

Use caching deliberately

Static assets, APIs and authenticated pages have different caching requirements. Define cache keys, bypass rules and purge behaviour from application semantics so performance optimisation does not create stale or cross-user content exposure.

Monitor the whole request path

Edge availability does not prove origin health. Combine Cloudflare visibility with synthetic tests, application monitoring and origin telemetry so teams can distinguish DNS, edge, network and application failures quickly.

Need help applying this?

AL Group can assess, design, implement and operate the underlying technology rather than stopping at advice.

Talk to an engineer