Cloudflare Security & compliance Releases

SSL mode off/flexible (unencrypted origin hop)

Part of the Edge TLS posture check · fix arrives as a guide

What it is

The zone's SSL mode is set to Off or Flexible.

Why it matters

Flexible terminates TLS at Cloudflare and speaks plain HTTP to your origin, so visitors see a padlock over a connection that is unencrypted for its final hop. Anything between Cloudflare and your server can read and modify the traffic, including session cookies.

How to fix it

Move to Full (strict), which requires a valid certificate on the origin. If the origin has no certificate, install one — Cloudflare issues free origin certificates for exactly this.

Run them all on your app

Connect your repo and your live services with read-only scopes. The first scan is free, and nothing changes without your approval.