Records transfer
Consider the sections below to understand the expected behaviors, depending on DNS record type and proxied status.
For each proxied DNS record in your zone, Cloudflare will transfer out two A and two AAAA records.
These records correspond to the Cloudflare IP addresses ↗ used for proxying traffic.
As explained in DNS record types, Cloudflare uses a process called CNAME flattening to return the final IP address instead of the CNAME target. CNAME flattening improves performance and is also what allows you to set a CNAME record on the zone apex.
Depending on the settings you have, when you use DNS-only CNAME records with outgoing zone transfers, you can expect the following:
- For DNS-only CNAME records on the zone apex, Cloudflare will always transfer out the flattened IP addresses.
- For DNS-only CNAME records on subdomains, Cloudflare will only transfer out flattened IP addresses if the setting CNAME flattening for all CNAME records is enabled.
The following records are not transferred out when you use Cloudflare as primary:
- CAA records
- TXT records used for TLS certificate validation
- DNS-only Load Balancing records
Was this helpful?
- Resources
- API
- New to Cloudflare?
- Directory
- Sponsorships
- Open Source
- Support
- Help Center
- System Status
- Compliance
- GDPR
- Company
- cloudflare.com
- Our team
- Careers
- © 2025 Cloudflare, Inc.
- Privacy Policy
- Terms of Use
- Report Security Issues
- Trademark
-