
In this lesson, I walk you through what the course covers and how it's laid out. You'll see what you need to follow along, and why everything here is built around the free plan.
In this lesson, we'll break down what a CDN, or Content Delivery Network, actually is. We'll see how this network of servers speeds up your website for visitors everywhere, saves you money, and makes everything run smoother.
In this lesson, we'll look at what Cloudflare actually is. It's a CDN and quite a bit more. You'll see where it sits between your visitors and your server, and why every request passes through it first.
In this lesson, I explain how Cloudflare does what it does. We'll cover Anycast IP addresses, how they hide your real server, and how traffic gets filtered and sped up before it ever reaches you.
In this lesson, we'll look at two ways to connect your site to Cloudflare. Your web host offers one, but we'll go straight to cloudflare.com instead, and I'll explain why that gives you more control.
In this lesson, we'll add your domain to Cloudflare step by step. You'll see the scan that pulls in your DNS records, and how to change your name servers at your registrar to finish the connection.
In this lesson, I go through what the free plan actually gives you. Free SSL, security rules, bot tools, caching, and speed features. You'll also learn the difference between the account level and the domain level.
In this lesson, we'll take a walk around the Cloudflare dashboard so it stops feeling overwhelming. You'll learn where everything lives, the two levels of your account, and the Quick Search trick for finding anything fast.
In this lesson, we'll look at the Overview page for a single site. You'll see the traffic snapshot and three handy quick actions, purge cache, Under Attack Mode, and Development Mode, plus where your account IDs live.
In this lesson, we'll make DNS simple. Think of it as the address book for your domain. You'll learn A, CNAME, MX, and TXT records, how to add and edit them, and what the orange cloud does.
In this lesson, we'll sort out that long list of DNS records Cloudflare copied in when you added your domain. You'll learn where they came from, which ones are safe to delete, and the bare minimum to keep.
In this lesson, we'll look at the official Cloudflare plugin for WordPress. It's optional, but, if you are running a WordPress site, it clears your cache automatically the moment you update a page. I'll show you how to install it and connect it safely.
While this is not technically part of the Cloudflare Dashboard, it does kind of 'mimic' a few of the functions of the dashboard that prevent you from having to run to the Cloudflare dashboard to do things. Instead, you can do them right from your WordPress site.
In this lesson, we'll add two-factor authentication to your Cloudflare login. It's the first security step I want you to take. I'll walk you through the authenticator app setup and saving your backup codes somewhere safe.
In this lesson, we'll set up your SSL and TLS page the right way. You'll learn what the padlock really means, which encryption mode to pick, and the other toggles worth turning on for a secure site.
In this lesson, I introduce Security Rules, where you decide who gets in and who gets stopped. You'll learn the simple when this, then that shape every rule follows, and what Cloudflare already blocks for you free.
In this lesson, we'll put your own IP address on the guest list before we build any blocking rules. I'll show you two ways to do it, a single address and a reusable account level list.
In this lecture, we’ll create a special Cloudflare rule to protect your WordPress login page. Instead of just blocking suspicious login attempts, we’ll set up a “challenge.” This means potential bad guys get an extra security check, while legitimate users can still easily log in.
Are you getting unwanted traffic from certain countries that aren’t relevant to your website? Cloudflare lets you easily block entire countries! In this lecture, we’ll learn how to block traffic from specific countries. This can be useful for security or compliance/GDPR reasons.
Not all bots are bad! Search engines like Google use “good bots” to explore and rank websites. In this lecture, we’ll make sure these good bots are always welcome on your site. We’ll configure Cloudflare to “allow” good bots, ensuring search engines can properly index your website, which is important for people finding you online.
In this lecture, you will learn where Cloudflare reveals bot activity across the Traffic tab, Events tab, and AI Crawl Control. You’ll also learn the Free plan’s reporting limits and why regularly saving this information can help you build and maintain accurate allow, challenge, and block lists.
Explore the Traffic tab to see what is actually reaching your website. In this lecture, you’ll learn how to spot suspicious traffic spikes, unusually active IP addresses, unknown operating systems, and questionable HTTP activity, then use Cloudflare’s built-in tools to filter traffic or begin creating security rules.
Dig into Traffic sample logs to examine individual requests, including IP addresses, user agents, AS numbers (ASN), and requested paths. In this lecture, you’ll learn to recognize common bot behavior, use Verified Bot filters, and turn filtered traffic directly into a custom Cloudflare security rule.
Use the Events tab to inspect requests Cloudflare has already acted on. In this lecture, you’ll learn how to customize displayed columns, review useful details such as user agents and paths, and export the full 24-hour event log as JSON for preserving and analyzing your security data.
Explore AI Crawl Control to identify which AI crawlers are accessing your site, review their activity, copy user agents and directives, and evaluate transferred data. In this lecture, you’ll also see how blocking crawlers here can create security rules and consume your limited Free-plan rule slots.
Put the information gathered from Traffic, Events, and AI Crawl Control to work by building a consolidated bad bot security rule. In this lecture, you’ll add confirmed bad user agents or IP addresses, block them, position the rule below your allow rule, and keep the list updated.
Do you have a test or staging version of your website that you don’t want the whole world to see? In this lecture, we’ll create a powerful Cloudflare rule to block everyone except specific people you choose. This is ideal for development or staging sites where you only want to allow access for yourself and your team.
Want to make your website load incredibly fast for returning visitors? Let’s learn about caching! In this lecture, we’ll explore Cloudflare’s caching rules and how to configure them properly. Caching basically means storing copies of your website files closer to your visitors, so they load almost instantly.
Imagine your website suddenly gets flooded with too many requests, maybe from bad bots or someone trying to overload it. That’s where rate limiting comes to the rescue! In this lecture, we’ll check out Cloudflare’s rate limiting feature.
Making your website files smaller without messing them up will help make your website faster! In this lecture, we’ll check out Cloudflare’s compression rules. Compression makes your website files, like images, smaller so they load quicker. However, if this power-tool is not setup correctly, your files may look wonky,
We’ve covered a lot of Cloudflare features, so let’s take a moment to review the most important settings for speed and caching. In this lecture, we’ll quickly run through the essential Cloudflare dashboard settings that directly impact your website’s performance. We’ll look at things like optimization, caching levels, and network settings.
Cloudflare is loaded with powerful features, and these “Rules” are where things can get really customizable! In this lecture, we’ll introduce you to Cloudflare’s “Rules” section. I’ll explain the difference between security rules and these broader “functionality” rules.
Let’s put Cloudflare Rules into action! In this lecture, we’ll focus on “Configuration Rules”. We’ll learn how to use these rules to apply specific settings to just certain pages of your website, not your entire site.
By the way, you may have noticed that many of these rules and configurations have similar steps to configure them. Using what you learn in these lectures, you can put together your own Rules to protect and/or optimize pieces of your web site or application that are not explicitly covered in these lectures.
Need to move a page on your website or send visitors to a completely different site?
Sure, there are plenty of plugins you can install on your website that requires updating and a bit of a performance ding because of an additional plugin.
OR...
Cloudflare Redirect Rules are the answer! In this lecture, I'll cover how to create simple redirect rules in Cloudflare.
Remember those plugins, for those to work, your site traffic has to hit your server first and all that goes into your webhost serving up your website files. But with the Cloudflare Redirect rule, that traffic is redirected BEFORE it hits your server because Cloudflare sits between your webhost and the web-traffic.
Want to fine-tune how your website communicates with browsers to boost security and speed? This is what I'll cover with Response Header Transform Rules in Cloudflare. In this lecture, we’ll learn how to add special instructions called “response headers” to your website’s traffic. These headers tell web browsers how to handle your website content securely and efficiently.
Are you working with a team, or do you need to give someone else access to your Cloudflare settings? In this lecture, I’ll show you how to invite team members or developers to access your Cloudflare account, but with control over what they can see and do.
In this lecture, we will cover an additional Custom Rule you could use in your Security Rules settings. This rule protects a specific endpoint of our API.
*This is an update to a previous lesson on protecting API Endpoints. This lesson show/explains why this Custom Rule is NO LONGER needed and to delete it.
In this lecture we will cover an additional Custom Rule you could use in your Security rule settings. This rule will protect your site from getting hit with urls that contain certain file type or extension that could cause leaks from your sites database.
Remember you are limited to the number of rules available in your Free or Pro plans, so keep those in mind as you decide which rules to include. That and the order matters -
the most restrictive rules should go at the top, and the least restrictive rules should go at the bottom.
In this lecture we will cover an additional Custom Rule you could use in your Security Rule settings. This rule will protect your site from hackers or bots trying to access passwords or other sensitive data.
Remember you are limited to the number of rules available in your Free or Pro plans, so keep those in mind as you decide which rules to include. That and the order matters -
the most restrictive rules should go at the top, and the least restrictive rules should go at the bottom.
In this lecture we will cover an additional Custom Rule you could use in your Security rules settings. This rule will protect your site from getting hit with SQL Injection Attempts that could allow hackers to access the database of your site. And that is not a good thing.
Remember you are limited to the number of rules available in your Free or Pro plans, so keep those in mind as you decide which rules to include. That and the order matters -
the most restrictive rules should go at the top, and the least restrictive rules should go at the bottom.
In this lecture we will cover an additional Custom Rule you could use in your Security rules settings. This rule will protect your site from getting hit with URLs that try uploading php files that could allow hackers to take over your site or other equally bad things.
Remember you are limited to the number of rules available in your Free or Pro plans, so keep those in mind as you decide which rules to include. That and the order matters -
the most restrictive rules should go at the top, and the least restrictive rules should go at the bottom.
In this lecture we will cover an additional Custom Rule you could use in your Security rules settings. This rule will Blocks attempts to access parent directories they shouldn't see.
Remember you are limited to the number of rules available in your Free or Pro plans, so keep those in mind as you decide which rules to include. That and the order matters -
the most restrictive rules should go at the top, and the least restrictive rules should go at the bottom.
In this lecture we will cover an additional Custom Rule you could use in your Security rules settings. This rule prevents users from uploading executable files that could contain malware, trojans, or other malicious code. It's a fundamental security measure that protects against one of the most direct forms of malware delivery.
Remember you are limited to the number of rules available in your Free or Pro plans, so keep those in mind as you decide which rules to include. That and the order matters -
the most restrictive rules should go at the top, and the least restrictive rules should go at the bottom.
In this lecture we will cover an additional Custom Rule you could use in your Security rule settings. This rule will challenge attempts to access your website using an old browser. This is a security issue because old browsers lack security updates, AND Older browsers often have known vulnerabilities that attackers can exploit. This rule does not block.., it challenges, meaning if it is a human, they simply pass the challenge and move on. The hackers and bots that do not.
Remember you are limited to the number of rules available in your Free or Pro plans, so keep those in mind as you decide which rules to include. That and the order matters -
the most restrictive rules should go at the top, and the least restrictive rules should go at the bottom.
In this lecture we will cover an additional Custom Rule you could use in your Security rule settings. This rule prevents unauthorized access attempts through spoofed social media authentication. It verifies that login requests actually originate from legitimate social media platforms, preventing credential theft.
Remember you are limited to the number of rules available in your Free or Pro plans, so keep those in mind as you decide which rules to include. That and the order matters -
the most restrictive rules should go at the top, and the least restrictive rules should go at the bottom.
In this lecture we will cover an additional Custom Rule you could use in your Security Rule settings. This rule protects cryptocurrency-related endpoints from unauthorized access and manipulation. This is crucial as crypto endpoints are frequent targets for both theft and cryptojacking attempts.
Remember you are limited to the number of rules available in your Free or Pro plans, so keep those in mind as you decide which rules to include. That and the order matters -
the most restrictive rules should go at the top, and the least restrictive rules should go at the bottom.
In this lecture we will cover an additional Custom Rule you could use in your Security rules settings. This rule Prevents external websites from using your server's resources by directly linking to your images. This protects bandwidth and server resources while maintaining content control.
Yes, there is a 'built-in' Hotlink Prevention feature under Scrape Shield as I show close to the end of this lesson but as I also show there, that 'built-in' feature dose not always work, at least not for me. So if that works for you then great, job done, but if not, this will take care of things for you.
Remember you are limited to the number of rules available in your Free or Pro plans, so keep those in mind as you decide which rules to include. That and the order matters -
the most restrictive rules should go at the top, and the least restrictive rules should go at the bottom.
NOTE: The Copy & Paste code I use in this lesson is in the PDF in the Resource section for this lesson.
In this lecture, we will cover an additional Custom Rule you could use in your Security rule settings. This rule identifies and challenges automated tools attempting to circumvent CAPTCHA systems, maintaining the integrity of human verification systems that protect forms and login pages.
Remember you are limited to the number of rules available in your Free or Pro plans, so keep those in mind as you decide which rules to include. That and the order matters - the most restrictive rules should go at the top, and the least restrictive rules should go at the bottom.
In this lecture, we will cover an additional Custom Rule you could use in your Security rule settings. This rule prevents attackers from gathering system information through exposed PHP error messages, which could reveal server configurations and vulnerabilities.
Remember you are limited to the number of rules available in your Free or Pro plans, so keep those in mind as you decide which rules to include. That and the order matters - the most restrictive rules should go at the top, and the least restrictive rules should go at the bottom.
In this lecture we will cover an additional Custom Rule you could use in your Security rule settings. This rule protects WordPress installations from brute force attacks and DDoS attempts that exploit the XML-RPC interface, a common attack vector for WordPress sites.
Remember you are limited to the number of rules available in your Free or Pro plans, so keep those in mind as you decide which rules to include. That and the order matters - the most restrictive rules should go at the top, and the least restrictive rules should go at the bottom.
In this lecture, we will cover an additional Custom Rule you could use in your Security rule settings. This rule prevents access to critical server configuration files that control directory permissions and CMS settings and blocks common attack vectors targeting web server configurations.
Remember you are limited to the number of rules available in your Free or Pro plans, so keep those in mind as you decide which rules to include. That and the order matters - the most restrictive rules should go at the top, and the least restrictive rules should go at the bottom.
In this lecture, we will cover an additional Custom Rule you could use in your Security rule settings. This rule blocks common command injection attempts through URL parameters targeting server-side code execution.
Remember you are limited to the number of rules available in your Free or Pro plans, so keep those in mind as you decide which rules to include. That and the order matters - the most restrictive rules should go at the top, and the least restrictive rules should go at the bottom.
In this lecture, we will cover an additional Custom Rule you could use in your Security rule settings. This rule Stops attempts to access critical system files through path traversal.
Remember you are limited to the number of rules available in your Free or Pro plans, so keep those in mind as you decide which rules to include. That and the order matters - the most restrictive rules should go at the top, and the least restrictive rules should go at the bottom.
In this lecture, we will cover an additional Custom Rule you could use in your Security rule settings. This rule prevents command injection attacks targeting query parameters.
Remember you are limited to the number of rules available in your Free or Pro plans, so keep those in mind as you decide which rules to include. That and the order matters - the most restrictive rules should go at the top, and the least restrictive rules should go at the bottom.
In this lecture, we will cover an additional Custom Rule you could use in your Security rule settings. This rule blocks direct access to server-side executables through web requests.
Remember you are limited to the number of rules available in your Free or Pro plans, so keep those in mind as you decide which rules to include. That and the order matters - the most restrictive rules should go at the top, and the least restrictive rules should go at the bottom.
In this lecture, we will cover an additional Custom Rule you could use in your Security rule settings. This rule protects accidentally exposed database/zip backups from being downloaded.
Remember you are limited to the number of rules available in your Free or Pro plans, so keep those in mind as you decide which rules to include. That and the order matters - the most restrictive rules should go at the top, and the least restrictive rules should go at the bottom.
In this lecture, we will cover an additional Custom Rule you could use in your Security rule settings. This rule will Block empty User-Agents because legitimate browsers always send User-Agent headers. Empty values often indicate malicious bots.
Remember you are limited to the number of rules available in your Free or Pro plans, so keep those in mind as you decide which rules to include. That and the order matters - the most restrictive rules should go at the top, and the least restrictive rules should go at the bottom.
Cloudflare can also be where you register your domain name, just like GoDaddy or Namecheap? In this lecture, I'll cover Cloudflare as a Domain Registrar. We’ll discuss the benefits of moving your domain registration to Cloudflare, including cost savings and speed advantages.
In this lecture, I will show you how to prepare your WordPress (dynamic) site to be hosted as a static site on your Cloudflare account. I'll be using a free Cloudflare account but I'm sure this will work just as easily on a paid Cloudflare account.
In this lecture, we will cover the steps involved in deploying your site on your free Cloudflare hosting feature. There are a couple of items that show up during the demo that originally concerned me but as I show in the lecture, it is nothing to be worried about.
In this lecture, we will finish up the Free Hosting of WordPress on Cloudflare by replacing the default free URL that comes with the Cloudflare 'Page' with a domain you already have on Cloudflare. This is very simple as you are about to see but I take 6 minutes to show you something that takes about 30 seconds, because there are a few things that should be covered in order to get this part correct.
One AI bot switch became three. Find out what Search, Agent, and Training bots actually do on your site, which ones send people back to you, and how to choose. Works on the free plan.
Are you tired of slow website loading times and worried about constant security threats? Do you manage a WordPress site (or a few!) and want to make it faster and safer without breaking the bank?
Then this course is for you. I'll show you, step-by-step, how to use Cloudflare's powerful (and FREE) features to protect your site from attacks, dramatically improve performance, and even lower your hosting costs.
Forget complicated tech jargon and endless, outdated tutorials. This course is designed for practical, immediate results. I'll guide you through the Cloudflare dashboard with clear, concise "how-to" videos – no fluff, just actionable steps.
Here's what you'll learn (and do):
Fortify Your Website's Defenses:
Set up basic Security Rules (Formerly Known as WAF) to block common attacks such as SQL injection and cross-site scripting.
Whitelist your own IP address so you never get accidentally blocked.
Block malicious traffic from specific countries (if needed for your business or compliance).
Enable "good bot" access for search engines while stopping the bad ones.
Implement two-factor authentication (2FA) for rock-solid Cloudflare account security.
Learn about and enable key SSL/TLS settings
Turbocharge Your Site Speed:
Configure Cloudflare's Content Delivery Network (CDN) to serve your content from servers closer to your visitors – globally.
Set up caching rules to reduce server load and bandwidth usage.
Optimize loading with the configuration rules.
Simplify Your Workflow:
Manage key Cloudflare settings directly from your WordPress dashboard (using the free Cloudflare plugin).
Understand how to transfer your domain registration to Cloudflare (optional, but can save you money!).
And More Advanced-Level (but Easy & on the Free Tier) Tips:
Set up "Turnstile" – a user-friendly alternative to those annoying CAPTCHAs.
Create custom rules for specific scenarios (like protecting your login page).
Get a handle on Cloudflare's basic reporting to monitor security events.
Who this course is for:
WordPress site owners, managers, and developers (from bloggers to small businesses).
NOTE: You do NOT Need a WordPress site for this course to help you configure the various 'None-WordPress' settings.
Anyone who wants to improve website security and performance without needing a computer science degree.
IT professionals looking to add Cloudflare skills to their resume.
Entrepreneurs who want to protect their online assets and save on hosting expenses.
Who this course is NOT for:
Advanced Cloudflare users looking for highly specialized, enterprise-level configurations. This is a foundational course focused on practical, everyday use of the Cloudflare Free tier.
My Promise to You:
No Hype, Just Results: I'll cut through the complexity and show you exactly what you need to do.
Direct Access to Me: I'm active in the Q&A section. Ask me anything!
Extra: Downloadable Quiz Book in the last Lecture that covers the entire course. The quiz - both True & False as well as Multiple Choice formats, will help you retain the stuff you learn throughout the course.
Ready to make your website faster, safer, and more efficient? Enroll today!