Securing Your Site Made Easy: How to Enable Cloudflare SSL/HTTPS on Your Website
Let’s be honest: seeing that unsettling "Not Secure" warning in the browser address bar is enough to make any website owner panic. Not only does it scare away potential visitors, but it also tanks your Google rankings and destroys user trust in a matter of seconds.
If you are running a blog, an ecommerce store, or a business portfolio, moving from HTTP to HTTPS isn't optional anymore—it is an absolute must.
The good news? You don't need to be a coding wizard or break the bank to secure your site. In this comprehensive guide, we will walk you through exactly how to set up a free SSL certificate using Cloudflare. Let's dive in!
Why You Absolutely Need an SSL Certificate Today
Before jumping into the setup process, let's address the elephant in the room: Why all the fuss about SSL?
- Trust and Credibility: Browsers like Google Chrome aggressively flag non-HTTPS sites. If visitors see a warning sign, they will likely bounce back to search results—often straight to your competitor.
- SEO Boost: Search engines favor secure websites. HTTPS is a confirmed ranking signal, meaning secure sites get a subtle edge in search visibility.
- Data Protection: SSL encrypts data traveling between your visitor's browser and your web server, protecting sensitive information like login credentials and contact forms from hackers.
Step 1: Create Your Free Cloudflare Account
Cloudflare makes enterprise-grade security accessible to everyone, and their free tier is more than enough for most standard websites and blogs.
- Head over to
and click on Sign Up.Cloudflare's official website - Enter your email address and create a strong password.
- Once logged in, click on the Add a Site button on your dashboard.
- Enter your domain name (e.g.,
yourwebsite.co.ke) and click Continue.
Step 2: Choose Your Plan
Cloudflare will present you with several pricing tiers ranging from Free to Enterprise.
- Scroll down and select the Free Plan (it offers robust SSL/HTTPS features, basic DDoS protection, and global CDN benefits).
- Click Continue to proceed to the DNS scanning phase.
Step 3: Review Your DNS Records
Cloudflare will automatically scan your domain and pull your existing DNS records (A records, CNAME, TXT, etc.) to ensure your site doesn't experience downtime during the switch.
- Check carefully: Make sure all your essential records (especially your root domain and www CNAME records) are listed correctly.
- The Orange Cloud vs. Grey Cloud:
Proxied (Orange Cloud): Traffic routes through Cloudflare, activating security, speed optimization, and free SSL. (Keep this on).
DNS Only (Grey Cloud): Bypasses Cloudflare.
Click Continue once you've verified everything looks good.
Step 4: Update Your Nameservers at Your Registrar
To let Cloudflare manage your traffic and issue your free SSL certificate, you need to point your domain to Cloudflare's nameservers.
- Cloudflare will provide you with two specific nameservers (for example, ns1.cloudflare.com and ns2.cloudflare.com).
Log into the domain registrar where you bought your domain (such as Truehost, Kenya Web Experts, Namecheap, or GoDaddy).
Navigate to the DNS / Nameservers section for your domain.
Replace your current nameservers with the two provided by Cloudflare.
Save your changes.
Pro Tip: Nameserver propagation can take anywhere from a few minutes to a couple of hours. Grab a cup of coffee while Cloudflare checks your setup automatically!
Step 5: Configure Your SSL/HTTPS Settings in Cloudflare
Once your domain is active on Cloudflare (you’ll see an active green badge on your dashboard), it is time to turn on encryption.
Click on your domain in the Cloudflare dashboard.
Navigate to the left sidebar and click on SSL/TLS.
You will see a few encryption modes to choose from:
Understanding Cloudflare SSL Modes
Off: No encryption. Visitors see HTTP. (Avoid this!)
Flexible: Encrypts traffic between the browser and Cloudflare, but traffic between Cloudflare and your web host remains unencrypted. Great if your host doesn't have an SSL installed yet.
Full: Encrypts end-to-end, but uses a self-signed certificate on your web server.
Full (Strict): (Recommended) End-to-end encryption using a trusted SSL certificate on your origin server.
Expert Recommendation: If your web hosting control panel (like cPanel or DirectAdmin) already offers a free AutoSSL (such as Let's Encrypt), set your Cloudflare mode to Full (Strict) for maximum security.
Step 6: Enable "Always Use HTTPS"
You don't want visitors landing on the insecure HTTP version of your site if they type the URL manually. Let's fix that instantly.
Under the SSL/TLS tab on the left menu, click on Edge Certificates.
Scroll down until you find the toggle for Always Use HTTPS.
Switch it to On.
This handy feature automatically redirects all incoming HTTP requests to secure HTTPS versions across your entire website.
Step 7: Fix Mixed Content Errors on Your CMS (WordPress)
Sometimes, after activating SSL, your browser might still show an insecure warning or broken padlock. This is usually caused by Mixed Content—meaning your site is loading secure HTTPS pages, but some images, scripts, or stylesheets are still hardcoded with http://.
If you are using WordPress, fixing this takes less than two minutes:
Log in to your WordPress dashboard.
Go to Plugins > Add New and search for Really Simple SSL.
Install and activate the plugin.
Click Go ahead, activate SSL!
The plugin will automatically handle all internal URL rewrites, forcing everything over to secure connections.
Wrapping Up
Securing your website with Cloudflare SSL/HTTPS is one of the smartest, most cost-effective moves you can make for your online presence. Not only does it take away those scary browser warnings, but it also gives your SEO a helpful nudge and keeps your users' data safe from prying eyes.
Take action today: log into your Cloudflare account, update your nameservers, and give your website the modern security upgrade it truly deserves!
Check HostPinnacle vs Hostinger: Which Web Hosting Is Better ?
