FAQ
The following provide answers to the most common questions associated with Cloudflare SSL/TLS certificates and settings.
Cloudflare certificates are prioritized by a combination of hostname specificity, zone specificity, and certificate type.
For more details, refer to Certificate and hostname priority.
Yes, Google announced that they use HTTPS as a ranking signal for SEO ↗.
For further SEO tweaks, refer to our article on improving SEO Rankings with Cloudflare.
If Cloudflare is your authoritative DNS provider, Universal SSL certificates typically issue within 15 minutes of domain activation at Cloudflare and do not require further customer action after domain activation.
Alternatively, if you use Cloudflare services via CNAME records set at your authoritative DNS provider, provisioning your Universal SSL certificate requires manual addition of DNS verification records at your authoritative DNS provider. Advanced SSL certificates also typically issue within 15 minutes.
If the Certificate Authority requires a manual review of brand, phishing, or TLD requirements, a Universal SSL certificate can take longer than 24 hours to issue.
Some domains are not eligible for the Universal SSL if they contain words that conflict with trademarked domains.
To resolve this issue, you can:
- Purchase an advanced certificate.
- Upload your own custom certificate.
The double byte / IDN / punycode domains support for Cloudflare edge certificates depends on the certificate authority (CA). Google Trust Services does not support punycode domains as mentioned in the certificate authorities limitations.
Refer to Encrypt all visitor traffic.
A free Universal SSL certificate is available for all new Cloudflare domains added via a hosting partner using both full and partial setups.
For more details, refer to Enable Universal SSL certificates.
No. Cloudflare SSL/TLS certificates are not shared across domains nor across customers.
Cloudflare must decrypt traffic in order to cache and filter malicious traffic. Cloudflare either re-encrypts traffic or sends plain text traffic to the origin web server depending on your domain's encryption mode.
Domains on Business and Enterprise plans can upload a Custom SSL certificate.
No. Since Cloudflare does not proxy connections made directly to paypal.com, enabling Cloudflare for your domain does not affect how TLS connections are made.
However, note that PayPal IPN (Instant Payment Notification) might not support TLS version 1.3 if you have it enabled on your zone.
If you are encountering issues with PayPal IPN when the traffic is proxied by Cloudflare, try setting the Minimum TLS version to 1.2.
Yes. For more details, refer to our documentation on Mutual TLS authentication.
A partial DNS setup requires additional steps to provision and validate an SSL certificate.
For more details, refer to Enable Universal SSL.
No. Multiple industry leaders — including Digicert ↗ and Mozilla ↗ — have discouraged certificate pinning because of security concerns.
For a safer alternative, use Certificate Transparency Monitoring.
Refer to Certificate pinning for more details.
To learn more about SSL, go to the Cloudflare Learning Center ↗.
The Let's Encrypt Certificate Authority and SNI are not currently supported by Redsys.
We recommend one of the following options:
- Change the Universal Certificate Authority to a different CA.
- Add an advanced certificate or custom certificate using a different CA.
Was this helpful?
- Resources
- API
- New to Cloudflare?
- Products
- Sponsorships
- Open Source
- Support
- Help Center
- System Status
- Compliance
- GDPR
- Company
- cloudflare.com
- Our team
- Careers
- 2025 Cloudflare, Inc.
- Privacy Policy
- Terms of Use
- Report Security Issues
- Trademark