Cloudflare Setup & Optimisation

Cloudflare setup for ExpressionEngine and Craft CMS sites: DNS migration with no downtime, edge caching that leaves forms and logins alone, and automatic cache purging when content changes.

Core Service

Cloudflare sits between your visitors and your website. It answers requests from a location near each visitor, serves pages from its own cache without troubling your server, turns away a large amount of malicious traffic before it arrives, and keeps the site up when your own server is briefly unavailable. For a business-critical site that means faster pages, a lighter load on your hosting, and a layer of protection that was not there before.

The risk with Cloudflare is on sites run through a CMS. ExpressionEngine and Craft decide, on every page, whether that page is safe to cache or has to be built fresh for the person viewing it. Get the setup wrong and Cloudflare either caches almost nothing, so you gain very little, or it caches a page meant for one person and shows it to the next visitor. Contact forms stop going through. Logged-in users see a page meant for someone else. None of it is obvious from looking at the site.

Expression 37 sets up and tunes Cloudflare for ExpressionEngine and Craft sites, and for the custom PHP and Laravel applications that often sit alongside them. That covers moving your domain across, the caching setup, the security settings, and a link between the CMS and Cloudflare that keeps the cache current. Most sites move onto a support retainer afterwards so the setup is maintained as the site changes.

What This Work Covers

  • Moving your domain to Cloudflare with no interruption to the site or your email, including a full check of your DNS records so nothing that depends on them breaks
  • The switch itself timed so the site keeps serving throughout and moves across cleanly once everything is confirmed
  • A caching setup that serves your content pages fast from Cloudflare while making sure forms, logins, baskets and any personalised page are always built fresh
  • Fixing the reason ExpressionEngine and Craft often stop Cloudflare caching anything at all, which needs a change at the server rather than in the Cloudflare dashboard
  • A link between ExpressionEngine or Craft and Cloudflare that clears the cache automatically whenever an editor publishes or updates a page, so changes appear straight away
  • The security settings a business-critical site should have: forced HTTPS, current encryption standards, and protection against bad bots and common attacks
  • Keeping any page that carries private or sensitive information out of the cache entirely, checked against the actual templates rather than guessed from the address

Why the CMS makes this harder

A plain brochure site can be handed to Cloudflare with the caching turned up and left alone. A site run through ExpressionEngine or Craft has logic behind most pages, and some of those pages must never be stored or shown to more than one person. The job is telling Cloudflare which pages are which, and undoing a few default behaviours in ExpressionEngine and Craft that otherwise stop caching working at all. That part is done by someone who works in the CMS every day, not set up from the Cloudflare dashboard alone.

A Recent Example

A UK mental health charity came to Expression 37 with a form-heavy ExpressionEngine site that needed to be faster without putting any of its enquiry or assessment forms at risk. The work involved moving the domain across from the previous provider with no interruption to the site or email, clearing out years of old DNS records, setting up caching that served the content pages quickly while leaving every form and every page that collected personal details to build fresh, and building a link between ExpressionEngine and Cloudflare that clears the cache whenever an editor publishes a change. While going through the templates, one page that mixed personal information into an otherwise cacheable layout was spotted and kept out of the cache before launch.

Common questions:

Will moving to Cloudflare cause downtime?

No. The site keeps serving from your current server the whole time. Cloudflare takes a copy of your existing DNS records, you point your domain at Cloudflare once those records are confirmed, and traffic moves across gradually. Email and any subdomains are checked before the switch so nothing that relies on them stops working.

We think we already have Cloudflare, but no one has looked at it in a while. Can you check it?

Yes, and it is a common starting point. Cloudflare is often switched on by a previous agency, left on its default settings, and then forgotten. We review what is actually configured: the DNS records, the caching rules, the security settings, and whether the CMS is working with Cloudflare or against it. You get a plain summary of what is set up sensibly, what is causing problems, and what is worth changing.

Why does ExpressionEngine or Craft stop Cloudflare caching?

Out of the box, ExpressionEngine sends a "no-cache" instruction in the page headers and an expiry date set in the past, and PHP adds a session cookie. Cloudflare reads any one of those as a reason not to store the page, so nothing gets cached even when the caching rules look correct. The fix is to change how Cloudflare decides what is cacheable and to correct those headers at the server before Cloudflare sees them. Craft and Laravel have their own versions of the same issue.

How do editors clear the cache when they publish something?

They do not have to. The link between the CMS and Cloudflare clears the affected pages automatically when an editor publishes or deletes something, so changes show on the live site straight away rather than waiting for the cache to expire on its own.

Can you make sure forms and logged-in pages are never cached?

Yes. Those pages are found in the templates and set to always come straight from the server. That covers contact and enquiry forms, checkout and basket pages, account areas, and anything that shows content specific to the person viewing it. Pages carrying sensitive information are checked one by one rather than assumed safe from the address.

What protection does Cloudflare actually add?

It sits in front of the site and filters traffic before it reaches your server. That means fewer automated attacks and scrapers getting through, some protection against attempts to overwhelm the site with traffic, and the site staying up during a sudden spike because Cloudflare absorbs much of the load. It does not replace keeping the CMS and plugins patched, but it lowers the day-to-day noise hitting the site.

Does this work on the free Cloudflare plan?

For most sites, yes. The free plan covers DNS, the global cache, HTTPS, and basic protection against bots and attacks, which is enough for a typical business-critical site. Advanced firewall rules, image handling and load balancing are on the paid plans, and a short look at what your site needs will tell you whether that applies.

Who should own the Cloudflare account?

You should. The account is set up in your name, with your billing, and Expression 37 works in it with the access you give. Control of your domain and DNS stays with you, which matters if the working relationship ever changes.

Can we help?

Most clients come to us when their site has started to feel like a risk rather than an asset. Whether the agency relationship has ended, an upgrade has been delayed, or the site has simply grown beyond what it can handle, a conversation costs nothing.

Get in touch with Karl

Related Services

ExpressionEngine Maintenance, Upgrade & Support Craft CMS Maintenance, Upgrade & Support Custom PHP & Laravel Development Ongoing Maintenance & Support

Related Case Studies

Related Blog Posts

Craft CMS and Core Web Vitals: What Slows Sites Down and What It Costs You in Search

Trusted by established businesses and growing brands across the UK

Expression 37 works with a small number of clients at any one time. These are some of them.

About Karl

Karl Bowers ~ ExpressionEngine & Craft CMS Specialist

Karl founded Expression 37 in 2007 and has worked exclusively with ExpressionEngine and Craft CMS ever since. He does not take on work in other platforms and does not hand work to other developers. Expression 37 is deliberately small, because the kind of support that matters to clients with business-critical sites is specific to their site, not something that scales in the conventional sense. If you work with Expression 37, you work with Karl.

Find out how we work

Client feedback:

Our ExpressionEngine website had been running on an outdated version for some time and we knew it needed attention, but finding someone with the right expertise to handle it properly was a concern. Expression 37 assessed the site thoroughly, explained exactly what was involved, and carried out the upgrade with no disruption to our business. The site has been noticeably more reliable since, and having ongoing support in place means we know any issues will be dealt with quickly. Straightforward to work with and clearly know what they are doing.

James Dawber - Managing Director
Dawber Williamson

» Get in touch