Public launch 13 October 2026. Every plan opens that day.

See the plans

Cloudflare

Point Cloudflare DNS at this server and connect an API token, and Dashmox can prove a name through DNS instead of over HTTP. That is what a wildcard certificate needs, and it is what lets a certificate exist before the domain points here.

What it is for

Two things HTTP cannot do.

Dashmox is authoritative on its own nameservers and stays that way, so Cloudflare DNS is an addition rather than a replacement. Nothing here needs Cloudflare, and a website with no connection loses none of what it has. What a token adds is a second way to answer a certificate authority.

Until now every certificate was proved over HTTP: the authority fetches a file from the website. That works, it is the right default, and it cannot do two things.

  • A wildcard. Let’s Encrypt will not issue *.example.com against an HTTP challenge at all. DNS is the only way, so a wildcard needs a connection.
  • A certificate before the domain points here. HTTP needs the authority to reach this server at that name. A website being migrated therefore cannot have a working certificate until after the cutover, which is exactly when somebody wants one already in place. Proved through DNS, the certificate is ready before you move anything, and the switch happens with no gap in HTTPS.

Where a connection covers every name on a website, Dashmox proves them through DNS. Where it does not, nothing changes and the certificate is proved over HTTP as before.

The token

A scoped token, never a Global API Key.

A token is what Dashmox uses to answer a challenge in your Cloudflare DNS. In Cloudflare, under My Profile then API Tokens, create a token with Zone:Read and DNS:Edit on the zones this server should manage. Paste it into Server settings, Cloudflare.

A Global API Key is refused. That credential can do everything on your Cloudflare account, including billing and membership, on every zone you hold. A hosting panel has no business holding it, and Dashmox says so rather than taking it. A scoped token can be revoked on its own and says what it may do when asked, which is why the panel can tell you which of your domains it actually covers.

The token is checked with Cloudflare at the moment you paste it. A token that is wrong is worth saying so about while you are still looking at the form, rather than at the first renewal nobody is watching.

Where it is kept

Not in the panel’s database.

The token goes to the privileged part of the server, which keeps it in a root-only file. The panel keeps what is not secret: which zones the token reaches, when it last worked, and whether it has stopped. So a copy of the panel’s database, a backup of it, or an export of it carries no credential to your DNS.

It is the same arrangement as the secret for an off-site backup destination, for the same reason. It also never appears on a command line, because a command line is readable by every process on the machine.

New websites

Records, without opening Cloudflare.

Create a website whose domain is in a zone your token reaches and its address record and www are published there. No authoritative zone is made on this server for the same name: a domain whose nameservers are at Cloudflare does not resolve through this server whatever is in it, and a second copy of the same records is two answers to one question.

Nothing is overwritten and nothing is deleted. The apex of a domain you are moving usually still points at your old host, and a panel that repointed it while setting the website up would take the live site down at the moment you were not looking. A record that is already there and says something else is reported, left exactly as it is, and you decide.

Mail records go the same way. Dashmox already works out the SPF, DKIM and DMARC a domain needs; with a connection it can publish them for a domain this panel is not authoritative for, which it used to be able only to show you. None of them is proxied, because a mail host behind a proxy resolves to something that does not accept mail.

Your customers

Their account, their zone.

A customer can connect their own Cloudflare account from their own account page. Where both you and a customer could reach the same zone, theirs is used: it is their account and their zone, and you acting on it with your own credential is something nobody can account for afterwards.

The origin

Only Cloudflare, which is normally a support ticket.

A website behind Cloudflare still answers on this server’s own address. Anybody who finds that address reaches the website directly: past the proxy, past the rules it enforces, past its rate limiting. Finding it is not hard, from an old DNS record or a certificate transparency log.

Under Protection, Only Cloudflare closes that, in two layers. The website accepts only Cloudflare’s published address ranges, and it requires the client certificate only Cloudflare holds, so a connection from a spoofed Cloudflare address presents nothing and is refused at the handshake. Cloudflare makes that second layer available on every plan, including Free.

The usual way to get this is to ask your host to add a firewall rule for you. Here it is a switch, and the address ranges are fetched from Cloudflare rather than written down once, because a stale list would take the website off the internet rather than merely be out of date.

It refuses itself when it would be wrong. Turning it on is not allowed unless Cloudflare is in front of every one of the website’s names, and the refusal says which ones are not. Locking a website that is not behind Cloudflare takes it off the internet for everybody, including you. Turning it off is never refused.

What it does not do

It is a credential, not a second control panel.

Dashmox does not mirror your zone in both directions. Which side wins when both changed is not a question with a good answer, and getting it wrong removes records somebody needs.

It does not manage caching, firewall rules or page rules either. Cloudflare’s own dashboard does those better, and chasing them is why Cloudflare withdrew the plugins it used to ship for hosting panels in 2022 rather than keep maintaining them.

Disconnecting forgets the token and changes nothing in Cloudflare. Records this server published stay as they are and your zones go on being served.

All guides