Cloudflare
Security & compliance
Releases
SSL mode off/flexible (unencrypted origin hop)
Part of the Edge TLS posture check · fix arrives as a guide
What it is
The zone's SSL mode is set to Off or Flexible.
Why it matters
Flexible terminates TLS at Cloudflare and speaks plain HTTP to your origin, so visitors see a padlock over a connection that is unencrypted for its final hop. Anything between Cloudflare and your server can read and modify the traffic, including session cookies.
How to fix it
Move to Full (strict), which requires a valid certificate on the origin. If the origin has no certificate, install one — Cloudflare issues free origin certificates for exactly this.
Run them all on your app
Connect your repo and your live services with read-only scopes. The first scan is free, and nothing changes without your approval.