Azure App Service is a service used to create and deploy scalable, mission-critical web apps.
How to use cloudflare to hosta newly registered Azure domain names
My question is the same from this link. https://learn.microsoft.com/en-us/answers/questions/1621920/how-to-use-cloudflare-to-host-azure-domain-names
It looks like the solution there stopped working in 2024. I have a newly registered domain. I normally register my domains at GoDaddy, but decided to try Azure this time. I was migrating an existing app to a new domain.
I'm in a bad state right now. I can't get the emails to verify because the DNS has keys that Azure DNS doesn't accept. I can't get Cloudflare to work because I delete the nameservers. Not being able to get the domain verified is causing all my emails to be rejected.
Azure App Service
-
Anonymous
2025-10-06T20:51:42.4833333+00:00 Hello @Jeffery McMullen,
Welcome to Microsoft Q&A Platform. Thank you for reaching out & hope you are doing well.
I understand your question about how to use Cloudflare to host newly registered Azure domain names, especially with email verification failing and potential rejections.
Causes of This Error:
- When you register a domain with Azure App Service Domains, Azure assigns its own nameservers by default.
- If you remove these nameservers and switch to Cloudflare, Azure DNS stops managing the zone, which can disrupt domain verification for email protocols like SPF, DKIM, and DMARC.
- Cloudflare needs certain DNS records for Microsoft 365 email verification, but if these are added incorrectly, Azure DNS might not accept some of the required formats.
You can fix the Issue via two ways,
Option 1 – It is recommended to use Cloudflare as your DNS provider if you would like to benefit from Cloudflare protection.
- Keep your domain registered with Azure.
- In the Azure Portal, navigate to App Service Domain → Nameservers and update the nameservers to the Cloudflare nameservers provided in your Cloudflare account.
- Allow up to 24–48 hours for DNS changes to propagate.
- Add all Microsoft 365 email records in Cloudflare DNS:
- TXT (SPF): v=spf1 include:spf.protection.outlook.com -all
- CNAME (DKIM): Obtain from the Microsoft 365 Admin Center
- TXT (DMARC): _dmarc.yourdomain.com with v=DMARC1; p=none; rua=mailto:******@yourdomain.com
- Verify your domain in Microsoft 365 via Admin Center → Settings → Domains.
- CNAME (DKIM): Obtain from the Microsoft 365 Admin Center
- TXT (SPF): v=spf1 include:spf.protection.outlook.com -all
Option 2 – Manage using Azure DNS:
- Switch back to the Azure-assigned nameservers, which can be found on the domain’s Overview page.
- Enter all necessary Microsoft 365 verification and email records into the Azure DNS zone.
- Verify the domain again in Microsoft 365.
Note: Do not use both Azure DNS and Cloudflare for the same domain at the same time, unless you are delegating a subdomain and select one authoritative DNS provider for your root domain.
How to setup Cloudflare dns: Full setup · Cloudflare DNS docs
Kindly let us know if the above helps or you need further assistance on this issue.
-
Jeffery McMullen • 0 Reputation points
2025-10-06T20:58:08.1433333+00:00 Option 1 does not work because Azure doesn't allow the nameservers to be deleted. In the past I have used Cloudflare for my websites hosted in App Services, but this is the first time where I registered a custom domain within Azure and not GoDaddy directly.
-
Anonymous
2025-10-07T19:12:40.4733333+00:00 Hello @Jeffery McMullen,
Thank you for clarifying, and you are correct. When a domain is registered via Azure App Service Domains, Azure acts as the registrar and assigns its own Azure DNS nameservers. These nameservers cannot be removed or replaced with Cloudflare’s, since Azure DNS remains the authoritative zone for the domain. This is intentional and is different from registrars like GoDaddy or Cloudflare, where changing nameservers is allowed.
Alternative Actions You Can Take:
Option 1 – Set Azure DNS as the primary service and delegate DNS management to Cloudflare: You can retain Azure as your main DNS provider and delegate certain subdomains (such as ) to Cloudflare. To achieve this, create NS records in Azure DNS that point to Cloudflare’s nameservers for the chosen subdomain. This setup allows Cloudflare to manage web traffic for the delegated subdomain, while Azure remains responsible for the root domain.
Option 2 – Domain Registration Transfer: To have Cloudflare manage your entire domain, you’ll need to transfer your registration from Azure to Cloudflare or GoDaddy. After the transfer, you’ll gain complete control over your nameservers and can use Cloudflare for all DNS management.
Option 3 - Please continue to use Azure DNS: If you need to resolve email verification quickly, continue using Azure DNS and add all required Microsoft 365 verification and email records (SPF, DKIM, DMARC) directly to the Azure DNS zone. This will enable email verification to complete without needing Cloudflare.
Note: Do not use Azure DNS and Cloudflare together for the same root domain unless you have correctly delegated a subdomain, as this may lead to DNS conflicts and persistent email delivery problems.
For step-by-step guidance:
Tutorial: Host your domain in Azure DNS | Microsoft Learn
Buy and configure an App Service domain - Azure App Service | Microsoft Learn
Kindly let us know if the above helps or you need further assistance on this issue.
-
Anonymous
2025-10-09T23:02:40.28+00:00 I noticed your question in the private message, so I'm responding here.
Hello @Jeffery McMullen
Thank you for your feedback, your concerns make sense.
Currently, Azure App Service Domains do not support changing the default nameservers. Unlike registrars like GoDaddy or Cloudflare, Azure controls DNS for domains registered on its platform. Due to ICANN and Azure registrar policies, you cannot update these nameservers during the initial 60-day transfer lock period. This rule is in place to help prevent domain hijacking or fraud, but it can be inconvenient if you want to use Cloudflare or another DNS/CDN provider immediately.
1. Azure DNS will stay as the authoritative DNS for your domain until the 60-day period is over. During this time, you are unable to change Azure’s default nameservers.
- If you require complete DNS management with Cloudflare, you can transfer the domain from Azure after the 60-day period.
- If Cloudflare is needed only for certain parts, you can delegate specific subdomains by adding NS records in Azure DNS.
- For urgent tasks like email verification (SPF, DKIM, DMARC), it's recommended to add those DNS records directly in Azure DNS to ensure smooth operation.
Kindly let us know if the above helps or you need further assistance on this issue.
-
Praneeth Maddali • 12,670 Reputation points • Microsoft External Staff • Moderator
2025-10-16T10:41:08.8633333+00:00 Hello @Jeffery McMullen
Just following up to see if your issue has been resolved or if you had a chance to review our earlier comments about using Cloudflare with Azure-registered domains.?
I’ve updated helpful Microsoft links below to guide you through fixing domain and email setup problems. They include easy steps for setting up DNS records in Azure DNS and verifying your Microsoft 365 email.
Reference:
https://learn.microsoft.com/en-us/azure/dns/dns-delegate-domain-azure-dns
-
Praneeth Maddali • 12,670 Reputation points • Microsoft External Staff • Moderator
2025-10-21T09:30:36.0133333+00:00 Hello @Jeffery McMullen
I'm just reaching out to see if your issue has been resolved or if you've had a chance to review my previous comment?
Sign in to comment