Use one already set up
You already hold a domain in your own Cloudflare account
Attach it in one step and wait for DNS to catch up. Nothing is bought or registered; this connects a domain you already have.
Live in minutes
Domains and email
You can put a Q-Code site on your own domain three ways: use one already set up in your own Cloudflare account, delegate one you own elsewhere, or point one you keep exactly where it is.
Each route is one step plus a wait for DNS to catch up. The certificate is issued automatically once DNS resolves, usually within minutes, and the zone sits on a Cloudflare account in your name rather than ours.
| Type | Name | Value |
|---|---|---|
| A | @ | 104.21.x.x |
| CNAME | www | q-code.pages.dev |
| TXT | _dmarc | v=DMARC1; p=quarantine |
Sending as
hello@bike-shop.co.uk
Three routes
Most platforms support one of these properly and make the other two your problem. All three are first-class here, because which one suits you is not something a platform should get to decide.
You already hold a domain in your own Cloudflare account
Attach it in one step and wait for DNS to catch up. Nothing is bought or registered; this connects a domain you already have.
Live in minutes
You have a domain elsewhere and want DNS managed from your own Cloudflare account, without moving the registration itself
Change the nameservers at your current registrar to point to the new zone. DNS is copied over first so nothing goes dark.
No downtime while DNS updates
You would rather not move the registration or the nameservers at all
Leave it where it is and change two records. You get the exact records to paste, and they are verified before it claims to be done.
Live in under an hour
Certificates
The certificate is issued when the domain is verified and rotated before it expires. There is nothing to buy, no renewal date to remember, and no upgrade tier that unlocks it.
HTTP redirects to HTTPS, HSTS is on, and the whole site is served from Cloudflare’s edge network, which means the same certificate and the same latency wherever a visitor is.
Issued on verification, rotated before expiry.
HTTP redirects, HSTS is set, mixed content is caught by the build.
Static files served close to the visitor rather than from one region.
Part of the platform it sits on, not an add-on.
Branded email
A confirmation sent from a shared relay looks like spam because it largely is. Sending from your own authenticated domain is the difference between a receipt and a junk folder.
None of the three authentication records is invented here. They are the published internet standards, and the records written into your zone follow them:SPF, RFC 7208,DKIM, RFC 6376 andDMARC, RFC 7489.
Q&A
You do. It stays registered wherever you registered it, and the DNS zone sits in a Cloudflare account you hold the login to. Removing Q-Code removes the code that reads the zone; it does not touch the zone.
Usually a few minutes after the DNS records resolve. There is nothing to buy, install or renew, because the certificate is issued and rotated automatically.
No. The DNS records are copied to the new zone and verified before the delegation completes, so the name never resolves to nothing.
Yes. shop.your-domain.co.uk or app.your-domain.com are the same one-click setup as the root, and the root can keep pointing anywhere you like.
Yes, and that is the point rather than a hurdle. It is free to create, it is where your domain and DNS live, and holding it yourself is what makes leaving possible without asking anyone’s permission.
Yes, in two ways. A stable address is what makes a page worth citing, because a URL that moves is a citation that breaks. And the last rung of the agent-readiness scan lives in the DNS zone rather than in the site: discovery records need DNSSEC on the zone, and serving a Markdown version of a page to agents is a Cloudflare zone setting on the Pro plan and above. Holding the zone yourself is what makes either of those your decision.
Sending is what the mail module sets up. Receiving is left to whichever provider you prefer, and the DNS records are written to leave room for it rather than to claim it.
Use a domain you already hold, delegate one you own elsewhere, or keep it exactly where it is. All three end with a certificate and a site that is genuinely yours to take away.