
Hard to believe I know but tech companies change and add things to their application or user interface all the time and Cloudflare is no different. </sarcasm>
So to help keep you informed, this space will be where I drop some updates from time to time. Mostly the small stuff like a feature was moved or for example, they just changed the name from Turnstile Sites to Turnstile Widgets. I mean why? There are more letters and well anyway.
Seriously though, keep an eye out for these updates.
In this lesson, I want to touch on some current changes to the dashboard in our free-level Cloudflare account and, more importantly, some search tips to help you locate features and tools that may have moved or been removed.
In this quick lecture, I go over the little warning icon in your Cloudflare DNS txt records, and how to fix and remove it. Amount a minute from now yours can be fixed as well.
Cloudflare has again made a few changes and this lesson covers a few of the big changes that affect a majority of site owners that manage domains within Cloudflare. Mainly some of the AI Bot related stuff that deals with crawling your domains.
Among other things, this quick lecture shows the update to the domain-level Security security settings, including the WAF settings. I'm showing two of my accounts side-by-side with one having the update and the other not yet having the update.
In this lecture, I cover what Cloudflare is all about. We’ll look into the important features you get in the free level with Cloudflare, focusing on security and speed. You’ll learn how Cloudflare works in simple terms and see how easy it is to create your own account.
In this lecture, we’ll break down what a CDN, or Content Delivery Network, actually is. We’ll see how this network of servers speeds up your website for visitors everywhere, saves you money, and makes everything run smoother.
Cloudflare is a company that, among other things that we'll touch on later in this course, provides a fantastic CDN service. In this lecture, I'll cover what Cloudflare is and how it helps websites go faster and get there more securely. We’ll learn about the different plans Cloudflare offers, but we’ll focus on the amazing free option.
In this lecture, we’ll finish up the overview stuff and see the simple steps Cloudflare takes to protect and speed up your website. I’ll talk about how it filters traffic, blocks bad bots, and uses a global network (that CDN I talked about earlier) to deliver your website content super quickly.
The goal: you’ll have a clear picture of how Cloudflare makes the internet safer and faster for your website visitors.
Hopefully I've buttered you up enough to want to use Cloudflare, so I now want to let you know there is a 'Best' way and a 'not-so-best' way to access Cloudflare. I cover the differences so you can make a more informed decision.
This lecture covers the steps involved in adding your site or domain to your Cloudflare account. I'm using the free plan in this lecture, but the steps are the same for the Pro plan. If you are using the Enterprise plan, you are probably not reading this.
If you use WordPress, this lesson is a must watch (pretty please)! Cloudflare has a special plugin that makes managing your Cloudflare settings even easier, right from your WordPress dashboard. In this lecture, we’ll install and set up this handy plugin.
In this lecture, I’ll cover Cloudflare’s SSL settings. I’ll go over the different options in simple terms and show you the best settings to make sure your website is secure and gives your visitors peace of mind. Getting SSL right is important so let's not skip this step.
In this lecture, I’ll introduce Cloudflare’s Web Application Firewall, or WAF. WAF is like a smart shield that sits in front of your website, constantly watching for and blocking the bad guys. I’ll cover what a WAF does in simple terms and how Cloudflare’s free WAF helps protect your website from common attacks, keeping it safe and sound.
Now that I've used 'WAF' in this Lecture description several times, I need to mention that a few of the Cloudflare features that were once called WAF have changed to Security rules. So depending on when you are reading this, it will either make sense or you are now wondering what the heck is Steve talking about.
But the lecture has been updated (2025-09-05) to show the new Security rules where WAF once was.
Sometimes, security can be a little too good, and you might accidentally block yourself! In this lecture, we’ll learn about “whitelisting” IP addresses in Cloudflare. We’ll show you how to find your IP address and add it to Cloudflare’s whitelist, ensuring you never get locked out of your own site.
In a previous lecture, we covered how to whitelist our home IP address using a single entry in our 'value' box when setting up the custom rule. This lecture shows that process but first we are creating a list to contain all the IP addresses we want to whitelist. Then we will create that custom rule and use our newly create IP Allow list.
In this lecture, we’ll create a special Cloudflare rule to protect your WordPress login page. Instead of just blocking suspicious login attempts, we’ll set up a “challenge.” This means potential bad guys get an extra security check, while legitimate users can still easily log in.
Imagine your website suddenly gets flooded with too many requests, maybe from bad bots or someone trying to overload it. That’s where rate limiting comes to the rescue! In this lecture, we’ll check out Cloudflare’s rate limiting feature.
Do you have a test or staging version of your website that you don’t want the whole world to see? In this lecture, we’ll create a powerful Cloudflare rule to block everyone except specific people you choose. This is ideal for development or staging sites where you only want to allow access for yourself and your team.
Are you getting unwanted traffic from certain countries that aren’t relevant to your website? Cloudflare lets you easily block entire countries! In this lecture, we’ll learn how to block traffic from specific countries. This can be useful for security or compliance/GDPR reasons.
Not all bots are bad! Search engines like Google use “good bots” to explore and rank websites. In this lecture, we’ll make sure these good bots are always welcome on your site. We’ll configure Cloudflare to “allow” good bots, ensuring search engines can properly index your website, which is important for people finding you online.
We’ve talked about blocking bad bots in general, but how do you find out which bots are actually causing trouble on your website? In this lecture, we’ll explore how to find lists of bad bots that might be visiting your site. Then we'll know which to block or challenge.
Want to make your website load incredibly fast for returning visitors? Let’s learn about caching! In this lecture, we’ll explore Cloudflare’s caching rules and how to configure them properly. Caching basically means storing copies of your website files closer to your visitors, so they load almost instantly.
Making your website files smaller without messing them up will help make your website faster! In this lecture, we’ll check out Cloudflare’s compression rules. Compression makes your website files, like images, smaller so they load quicker. However, if this power-tool is not setup correctly, your files may look wonky,
We’ve covered a lot of Cloudflare features, so let’s take a moment to review the most important settings for speed and caching. In this lecture, we’ll quickly run through the essential Cloudflare dashboard settings that directly impact your website’s performance. We’ll look at things like optimization, caching levels, and network settings.
Cloudflare is loaded with powerful features, and these “Rules” are where things can get really customizable! In this lecture, we’ll introduce you to Cloudflare’s “Rules” section. I’ll explain the difference between security rules and these broader “functionality” rules.
Let’s put Cloudflare Rules into action! In this lecture, we’ll focus on “Configuration Rules”. We’ll learn how to use these rules to apply specific settings to just certain pages of your website, not your entire site.
By the way, you may have noticed that many of these rules and configurations have similar steps to configure them. Using what you learn in these lectures, you can put together your own Rules to protect and/or optimize pieces of your web site or application that are not explicitly covered in these lectures.
Need to move a page on your website or send visitors to a completely different site?
Sure, there are plenty of plugins you can install on your website that requires updating and a bit of a performance ding because of an additional plugin.
OR...
Cloudflare Redirect Rules are the answer! In this lecture, I'll cover how to create simple redirect rules in Cloudflare.
Remember those plugins, for those to work, your site traffic has to hit your server first and all that goes into your webhost serving up your website files. But with the Cloudflare Redirect rule, that traffic is redirected BEFORE it hits your server because Cloudflare sits between your webhost and the web-traffic.
Want to fine-tune how your website communicates with browsers to boost security and speed? This is what I'll cover with Response Header Transform Rules in Cloudflare. In this lecture, we’ll learn how to add special instructions called “response headers” to your website’s traffic. These headers tell web browsers how to handle your website content securely and efficiently.
Let’s boost your Cloudflare account security! In this lecture, we’ll set up Two-Factor Authentication, or 2FA. 2FA adds an extra layer of security to your Cloudflare login. This means that even if someone knows your password, they still can’t get in without a code from your phone.
Are you working with a team, or do you need to give someone else access to your Cloudflare settings? In this lecture, I’ll show you how to invite team members or developers to access your Cloudflare account, but with control over what they can see and do.
Cloudflare has a lot of features, and the dashboard can seem a bit overwhelming at first.
This lecture (Dashboard Part One) covers the dashboard’s high-level features accessible before selecting a specific domain.
Key Topics:
Using the Quick Search box to find tools and features.
Managing multiple accounts via the top-left dropdown.
Viewing account history in the Recent tab.
Overview of Compute (Workers and Pages), Storage (R2), and domain registration.
Manage Account settings, including billing, adding members, and assigning limited access.
This lecture (Dashboard Tour Part Two) begins the deep dive into domain-specific settings, focusing on initial navigation and connectivity.
Key Topics:
Navigating the Overview page and using the sidebar for specific domains.
AI Crawl Control to monitor and manage bot activity.
Reviewing Analytics and Logs for traffic insights.
DNS Settings, including the importance of avoiding “yellow triangles” and an explanation of DNSSEC security.
A brief mention of free Email features.
This lecture (Dashboard Tour Part Three) focuses on the critical security features that protect your website from attacks and ensure encrypted connections.
Key Topics:
SSL/TLS settings, highlighting “Full (strict)” as the gold standard for security.
Managing Edge Certificates and HSTS configurations.
The Security Dashboard, including a tour of security rules and rate-limiting.
Detailed Security Settings such as Bot Fight Mode, Browser Integrity Checks, and Hotlink Protection.
This lecture (Dashboard Tour Part Four) covers performance improvements, content delivery settings, and general account maintenance.
Key Topics:
Speed Settings, including content optimization and why some features (like Rocket Loader) might be left off initially.
Caching Configuration, including how to purge the cache and use Development Mode.
Network Settings like IPv6 compatibility, WebSockets, and Onion Routing.
Once you’ve added your website to Cloudflare, the Site Overview page becomes your central hub. In this lecture, we’ll focus on the Cloudflare Site Overview page, which you see after you click on your website domain. I’ll point out the key information and quick actions available on this page, like analytics, purging cache, and security modes.
DNS might sound technical, but it’s essential for how your website works. In this lecture, we’ll explore the Cloudflare DNS Overview page. We’ll explain what DNS records are and how Cloudflare helps you manage them.
Cloudflare can also be where you register your domain name, just like GoDaddy or Namecheap? In this lecture, I'll cover Cloudflare as a Domain Registrar. We’ll discuss the benefits of moving your domain registration to Cloudflare, including cost savings and speed advantages.
In this lecture, we will cover an additional Custom Rule you could use in your Security Rules settings. This rule protects a specific endpoint of our API.
*This is an update to a previous lesson on protecting API Endpoints. This lesson show/explains why this Custom Rule is NO LONGER needed and to delete it.
In this lecture we will cover an additional Custom Rule you could use in your Security rule settings. This rule will protect your site from getting hit with urls that contain certain file type or extension that could cause leaks from your sites database.
Remember you are limited to the number of rules available in your Free or Pro plans, so keep those in mind as you decide which rules to include. That and the order matters -
the most restrictive rules should go at the top, and the least restrictive rules should go at the bottom.
In this lecture we will cover an additional Custom Rule you could use in your Security Rule settings. This rule will protect your site from hackers or bots trying to access passwords or other sensitive data.
Remember you are limited to the number of rules available in your Free or Pro plans, so keep those in mind as you decide which rules to include. That and the order matters -
the most restrictive rules should go at the top, and the least restrictive rules should go at the bottom.
In this lecture we will cover an additional Custom Rule you could use in your Security rules settings. This rule will protect your site from getting hit with SQL Injection Attempts that could allow hackers to access the database of your site. And that is not a good thing.
Remember you are limited to the number of rules available in your Free or Pro plans, so keep those in mind as you decide which rules to include. That and the order matters -
the most restrictive rules should go at the top, and the least restrictive rules should go at the bottom.
In this lecture we will cover an additional Custom Rule you could use in your Security rules settings. This rule will protect your site from getting hit with URLs that try uploading php files that could allow hackers to take over your site or other equally bad things.
Remember you are limited to the number of rules available in your Free or Pro plans, so keep those in mind as you decide which rules to include. That and the order matters -
the most restrictive rules should go at the top, and the least restrictive rules should go at the bottom.
In this lecture we will cover an additional Custom Rule you could use in your Security rules settings. This rule will Blocks attempts to access parent directories they shouldn't see.
Remember you are limited to the number of rules available in your Free or Pro plans, so keep those in mind as you decide which rules to include. That and the order matters -
the most restrictive rules should go at the top, and the least restrictive rules should go at the bottom.
In this lecture we will cover an additional Custom Rule you could use in your Security rules settings. This rule prevents users from uploading executable files that could contain malware, trojans, or other malicious code. It's a fundamental security measure that protects against one of the most direct forms of malware delivery.
Remember you are limited to the number of rules available in your Free or Pro plans, so keep those in mind as you decide which rules to include. That and the order matters -
the most restrictive rules should go at the top, and the least restrictive rules should go at the bottom.
In this lecture we will cover an additional Custom Rule you could use in your Security rule settings. This rule will challenge attempts to access your website using an old browser. This is a security issue because old browsers lack security updates, AND Older browsers often have known vulnerabilities that attackers can exploit. This rule does not block.., it challenges, meaning if it is a human, they simply pass the challenge and move on. The hackers and bots that do not.
Remember you are limited to the number of rules available in your Free or Pro plans, so keep those in mind as you decide which rules to include. That and the order matters -
the most restrictive rules should go at the top, and the least restrictive rules should go at the bottom.
In this lecture we will cover an additional Custom Rule you could use in your Security rule settings. This rule prevents unauthorized access attempts through spoofed social media authentication. It verifies that login requests actually originate from legitimate social media platforms, preventing credential theft.
Remember you are limited to the number of rules available in your Free or Pro plans, so keep those in mind as you decide which rules to include. That and the order matters -
the most restrictive rules should go at the top, and the least restrictive rules should go at the bottom.
In this lecture we will cover an additional Custom Rule you could use in your Security Rule settings. This rule protects cryptocurrency-related endpoints from unauthorized access and manipulation. This is crucial as crypto endpoints are frequent targets for both theft and cryptojacking attempts.
Remember you are limited to the number of rules available in your Free or Pro plans, so keep those in mind as you decide which rules to include. That and the order matters -
the most restrictive rules should go at the top, and the least restrictive rules should go at the bottom.
In this lecture we will cover an additional Custom Rule you could use in your Security rules settings. This rule Prevents external websites from using your server's resources by directly linking to your images. This protects bandwidth and server resources while maintaining content control.
Yes, there is a 'built-in' Hotlink Prevention feature under Scrape Shield as I show close to the end of this lesson but as I also show there, that 'built-in' feature dose not always work, at least not for me. So if that works for you then great, job done, but if not, this will take care of things for you.
Remember you are limited to the number of rules available in your Free or Pro plans, so keep those in mind as you decide which rules to include. That and the order matters -
the most restrictive rules should go at the top, and the least restrictive rules should go at the bottom.
NOTE: The Copy & Paste code I use in this lesson is in the PDF in the Resource section for this lesson.
In this lecture, we will cover an additional Custom Rule you could use in your Security rule settings. This rule identifies and challenges automated tools attempting to circumvent CAPTCHA systems, maintaining the integrity of human verification systems that protect forms and login pages.
Remember you are limited to the number of rules available in your Free or Pro plans, so keep those in mind as you decide which rules to include. That and the order matters - the most restrictive rules should go at the top, and the least restrictive rules should go at the bottom.
In this lecture, we will cover an additional Custom Rule you could use in your Security rule settings. This rule prevents attackers from gathering system information through exposed PHP error messages, which could reveal server configurations and vulnerabilities.
Remember you are limited to the number of rules available in your Free or Pro plans, so keep those in mind as you decide which rules to include. That and the order matters - the most restrictive rules should go at the top, and the least restrictive rules should go at the bottom.
In this lecture we will cover an additional Custom Rule you could use in your Security rule settings. This rule protects WordPress installations from brute force attacks and DDoS attempts that exploit the XML-RPC interface, a common attack vector for WordPress sites.
Remember you are limited to the number of rules available in your Free or Pro plans, so keep those in mind as you decide which rules to include. That and the order matters - the most restrictive rules should go at the top, and the least restrictive rules should go at the bottom.
In this lecture, we will cover an additional Custom Rule you could use in your Security rule settings. This rule prevents access to critical server configuration files that control directory permissions and CMS settings and blocks common attack vectors targeting web server configurations.
Remember you are limited to the number of rules available in your Free or Pro plans, so keep those in mind as you decide which rules to include. That and the order matters - the most restrictive rules should go at the top, and the least restrictive rules should go at the bottom.
In this lecture, we will cover an additional Custom Rule you could use in your Security rule settings. This rule blocks common command injection attempts through URL parameters targeting server-side code execution.
Remember you are limited to the number of rules available in your Free or Pro plans, so keep those in mind as you decide which rules to include. That and the order matters - the most restrictive rules should go at the top, and the least restrictive rules should go at the bottom.
In this lecture, we will cover an additional Custom Rule you could use in your Security rule settings. This rule Stops attempts to access critical system files through path traversal.
Remember you are limited to the number of rules available in your Free or Pro plans, so keep those in mind as you decide which rules to include. That and the order matters - the most restrictive rules should go at the top, and the least restrictive rules should go at the bottom.
In this lecture, we will cover an additional Custom Rule you could use in your Security rule settings. This rule prevents command injection attacks targeting query parameters.
Remember you are limited to the number of rules available in your Free or Pro plans, so keep those in mind as you decide which rules to include. That and the order matters - the most restrictive rules should go at the top, and the least restrictive rules should go at the bottom.
In this lecture, we will cover an additional Custom Rule you could use in your Security rule settings. This rule blocks direct access to server-side executables through web requests.
Remember you are limited to the number of rules available in your Free or Pro plans, so keep those in mind as you decide which rules to include. That and the order matters - the most restrictive rules should go at the top, and the least restrictive rules should go at the bottom.
In this lecture, we will cover an additional Custom Rule you could use in your Security rule settings. This rule protects accidentally exposed database/zip backups from being downloaded.
Remember you are limited to the number of rules available in your Free or Pro plans, so keep those in mind as you decide which rules to include. That and the order matters - the most restrictive rules should go at the top, and the least restrictive rules should go at the bottom.
In this lecture, we will cover an additional Custom Rule you could use in your Security rule settings. This rule will Block empty User-Agents because legitimate browsers always send User-Agent headers. Empty values often indicate malicious bots.
Remember you are limited to the number of rules available in your Free or Pro plans, so keep those in mind as you decide which rules to include. That and the order matters - the most restrictive rules should go at the top, and the least restrictive rules should go at the bottom.
In this lecture, I will show you how to prepare your WordPress (dynamic) site to be hosted as a static site on your Cloudflare account. I'll be using a free Cloudflare account but I'm sure this will work just as easily on a paid Cloudflare account.
In this lecture, we will cover the steps involved in deploying your site on your free Cloudflare hosting feature. There are a couple of items that show up during the demo that originally concerned me but as I show in the lecture, it is nothing to be worried about.
In this lecture, we will finish up the Free Hosting of WordPress on Cloudflare by replacing the default free URL that comes with the Cloudflare 'Page' with a domain you already have on Cloudflare. This is very simple as you are about to see but I take 6 minutes to show you something that takes about 30 seconds, because there are a few things that should be covered in order to get this part correct.
Are you tired of slow website loading times and worried about constant security threats? Do you manage a WordPress site (or a few!) and want to make it faster and safer without breaking the bank?
Then this course is for you. I'll show you, step-by-step, how to use Cloudflare's powerful (and FREE) features to protect your site from attacks, dramatically improve performance, and even lower your hosting costs.
Forget complicated tech jargon and endless, outdated tutorials. This course is designed for practical, immediate results. I'll guide you through the Cloudflare dashboard with clear, concise "how-to" videos – no fluff, just actionable steps.
Here's what you'll learn (and do):
Fortify Your Website's Defenses:
Set up a basic Web Application Firewall (WAF) to block common attacks like SQL injections and cross-site scripting.
Whitelist your own IP address so you never get accidentally blocked.
Block malicious traffic from specific countries (if needed for your business or compliance).
Enable "good bot" access for search engines while stopping the bad ones.
Implement two-factor authentication (2FA) for rock-solid Cloudflare account security.
Learn about and enable key SSL/TLS settings
Turbocharge Your Site Speed:
Configure Cloudflare's Content Delivery Network (CDN) to serve your content from servers closer to your visitors – globally.
Set up caching rules to reduce server load and bandwidth usage.
Optimize loading with the configuration rules.
Simplify Your Workflow:
Manage key Cloudflare settings directly from your WordPress dashboard (using the free Cloudflare plugin).
Understand how to transfer your domain registration to Cloudflare (optional, but can save you money!).
And More Pro-Level (but Easy & Free) Tips:
Set up "Turnstile" – a user-friendly alternative to those annoying CAPTCHAs.
Create custom rules for specific scenarios (like protecting your login page).
Get a handle on Cloudflare's basic reporting to monitor security events.
Who this course is for:
WordPress site owners, managers, and developers (from bloggers to small businesses).
NOTE: You do NOT Need a WordPress site for this course to help you configure the various 'None-WordPress' settings.
Anyone who wants to improve website security and performance without needing a computer science degree.
IT professionals looking to add Cloudflare skills to their resume.
Entrepreneurs who want to protect their online assets and save on hosting expenses.
Who this course is NOT for:
Advanced Cloudflare users looking for highly specialized, enterprise-level configurations. This is a foundational course focused on practical, everyday use.
My Promise to You:
No Hype, Just Results: I'll cut through the complexity and show you exactly what you need to do.
Direct Access to Me: I'm active in the Q&A section. Ask me anything!
Extra: Downloadable Quiz Book in the last Lecture that covers the entire course. The quiz - both True & False as well as Multiple Choice formats, will help you retain the stuff you learn throughout the course.
Ready to make your website faster, safer, and more efficient? Enroll today!