Connect Cloudflare

Verify a Cloudflare site and let SEOFixBot past its firewall, either automatically with a scoped API token or by adding the record and rule yourself.

Updated 8 October 2026View as Markdown

If your site's DNS is on Cloudflare, one setup does two things: a TXT record proves you own the domain, and a WAF skip rule lets SEOFixBot through challenges. Open the site page, choose the Cloudflare method on the ownership card, then pick Connect automatically (with an API token) or Do it myself (no API token). Both add the same record and rule.

Cloudflare setup is in the web app only. There is no /v1 endpoint or MCP tool for it.

Connect automatically (with an API token)

  1. On the site page, open the Cloudflare method and choose Connect Cloudflare.

  2. Choose Open Cloudflare. It opens Cloudflare's Create API token page pre-filled with a template named SEOFix (<your host>) and these permissions:

    Permission Why
    Zone → Zone → Read Find your domain's zone
    Zone → DNS → Edit Add the verification TXT record
    Zone → Zone WAF → Edit Add the firewall skip rule

    Cloudflare's template link cannot pick the zone for you. Set Zone Resources to your site's zone, then create the token.

  3. Back in SEOFix, paste the token under Paste the token and choose Connect.

The dialog then shows three results: Verification record, Firewall rule and Ownership verified (or Waiting for DNS: the record can take a few minutes to appear, and SEOFix re-checks automatically).

What SEOFix creates

SEOFix looks up the zone of your site's registrable domain (blog.example.com → example.com) and adds:

  • One TXT record at the zone apex: seofix-verify=<verification token>, with the comment "SEOFix ownership verification". If you already added the identical record by hand, SEOFix reuses it and never deletes it.
  • One custom rule named SEOFix crawler (auto), placed first in the zone's WAF custom rules (SEOFix creates the custom-rules list if your zone has none):
    • Expression: any(http.request.headers["x-seofix-verify"][*] eq "<crawler secret>")
    • Action: Skip, with All remaining custom rules, All managed rules and All Super Bot Fight Mode rules, plus Browser Integrity Check, Security Level, User Agent Blocking, Hotlink Protection and Zone Lockdown.
    • All Super Bot Fight Mode rules is left out automatically when your Cloudflare plan does not allow it.
    • Rate limiting rules are not skipped. SEOFixBot slows down when it is rate limited.

The rule matches your site's private crawler secret, which SEOFixBot sends in the X-SEOFix-Verify header. It never matches the public verification token, which anyone can read from your DNS.

How the token is stored

As the app states: the token is stored encrypted and used only for that record and rule. SEOFix uses it for the zone lookup, the one TXT record and the one WAF rule, and never returns it in a response. You can revoke it any time in Cloudflare (My Profile → API Tokens), or choose Disconnect in SEOFix to remove both.

Errors when connecting

Message Fix
This token cannot read your zone. Edit the token in Cloudflare: add Zone → Zone → Read, and include this domain in Zone Resources.
This token can read your zone but cannot manage DNS records. Add Zone → DNS → Edit.
This token can read your zone and DNS but cannot manage WAF custom rules. Add Zone → Zone WAF → Edit.
Cloudflare is already connected for this site. Disconnect it first. One connection per site.
Cloudflare could not be reached. Please try again. Retry later.

If any step fails, SEOFix removes what it already created in your zone before reporting the error.

Disconnect

On the site page, the Cloudflare method shows the connected zone and Disconnect. Disconnecting removes the firewall rule and SEOFix's TXT record from Cloudflare, then deletes the token. The site stays verified only if another proof still passes. If Cloudflare refuses a removal (for example because you already revoked the token), the app tells you which item to delete in Cloudflare yourself.

Deleting the site removes the rule and record first. If that fails, the delete is refused with 409 cloudflare_connected, so a skip rule is never left behind unmanaged.

Do it myself (no API token)

Choose Do it myself (no API token) (or Prefer not to share a token? Do it yourself). The app lists the same two changes as steps.

Step 1: Prove you own the domain

In Cloudflare, open your zone → DNS → Records → Add record:

Name Type Value TTL
@ (your registrable domain) TXT seofix-verify=<verification token> Auto

Skip this step if the site is already verified another way. While the record is on screen, the card checks for it every 2 minutes for 60 minutes.

Step 2: Let SEOFixBot through your firewall

  1. Open Security → WAF → Custom rules for your zone and choose Create rule. Open (zone)'s WAF rules links there.

  2. Name it SEOFix crawler, choose Edit expression and paste the expression. Use the copy button: the expression holds your crawler secret, which the page fetches only when you choose Reveal or Copy.

    any(http.request.headers["x-seofix-verify"][*] eq "<crawler secret>")
    
  3. Set the action to Skip and tick every item:

    • All remaining custom rules
    • All managed rules
    • All Super Bot Fight Mode rules (Pro plan and above; leave it out if it isn't offered)
    • Under "More components to skip": Browser Integrity Check, Security Level, User Agent Blocking, Hotlink Protection, Zone Lockdown
  4. Place the rule First, then Deploy.

Leave rate limiting rules alone: SEOFixBot slows down instead.

Step 3: Check that it works

Choose Check my setup. SEOFix looks up the TXT record and loads your start page twice as SEOFixBot, with and without the secret header. Each step shows Passed, Needs attention or Note with a hint. What the firewall results mean: Let SEOFix through your firewall.

Bot Fight Mode on the Free plan

On Cloudflare's Free plan, Bot Fight Mode cannot be skipped by any rule. If audits still show blocked pages after the rule is in place, turn Bot Fight Mode off while audits run.

The crawler secret

  • SEOFixBot sends the crawler secret only after the site is verified, only over HTTPS, and only to your site's host and its www / bare-domain twin.
  • Rotate secret (next to the secret on the site page) issues a new value. With an automatic connection, SEOFix updates the Cloudflare rule in place. With a hand-built rule, paste the new expression right away, or audits (including one already running) may hit challenges.
  • Keep it private: don't publish it or put it in your site's code.

More in Sites & firewalls

Still stuck? Email [email protected] with your site and what you expected to see.