DNStracrBack to DNStracr
← All help topics

Connect and sync Cloudflare

Link matching domains and review provider configuration without changing DNS.

Connecting is optional and read-only

Ordinary DNS monitoring works without Cloudflare. In Integrations, connect Cloudflare with a zone-scoped token granting Zone:Read and DNS:Read. DNStracr reads saved configuration and compares it with DNS answers; it does not write DNS records or roll back changes at Cloudflare.

  1. Sync to read accessible Cloudflare zones and their records.
  2. Use Link for a matching domain already in DNStracr, or Add to create and link just the selected domain.
  3. Use Unlink to remove the connection for that domain. The DNStracr domain, monitors and history remain, and later syncs respect the opt-out.

What Sync does

Sync refreshes the accessible zone list and record snapshots. Linking requires the same domain name in both systems. It does not add every Cloudflare zone, enable monitors or approve changed configurations.

A failed record read does not prove that Cloudflare deleted a record. DNStracr preserves the last successful snapshot and reports that fresh evidence is unavailable. Check the last-read time before drawing conclusions.

Accepted, latest and served

On a linked monitor, review Cloudflare comparison and explicitly enable it. Accepted configuration is what you approved for this monitored name and record type. Latest Cloudflare configuration is the last successful provider read. Currently served by DNS is the live DNS evidence.

For an intended change, review the new configuration and choose Accept as expected. For an unintended change, correct it at Cloudflare. Sync alone never accepts a new baseline. Acceptance schedules another check; recovery still needs the configured successful confirmations.

Troubleshooting

No matching zone: verify the domain is in the connected Cloudflare account and included in the token's scope. Different-domain mappings are not supported.

Provider API refresh failed: check token validity, Zone:Read and DNS:Read permissions, zone access and connectivity, then sync again. DNS may still be working while provider access fails. Do not accept a new configuration merely to suppress an API error.

Documentation reviewed: 8 October 2026. Results describe configured checks and available evidence, not a complete security or service-availability guarantee.

Troubleshooting and contacting Support