>I can see the advantage of Cloudflare's proxy systems, but I wish they'd be clearer about when they're being used and not pretend that this is some DNS feature or that records have been set to one thing when they've actually been set to something else. If nothing else, it makes debugging DNS issues a lot more confusing, particularly if you're not a DNS expert.
You could say the same about the reverse, ie. people set up their site on cloudflare, thought it was "protected", but really it's dns only and their servers are wide open. It's even worse if they migrated from another provider that was providing ddos protection.
I don't think this particular feature helps there, though. If you set your site up on Cloudflare, you'll probably explicitly want the proxy stuff, and that's very easy to set up. But if you buy a domain on Cloudflare, then you're already not looking specifically at the proxy products, you're looking at something else. And if you start configuring that domain in an admin panel that looks like it's offering you direct DNS configuration, and then you later realise that the DNS configuration has ended up completely different to how you set it up, then that's a bit weird. Like, if I set `CNAME` in DNS, then I expect the DNS CNAME record to be what I set it to.
You could say the same about the reverse, ie. people set up their site on cloudflare, thought it was "protected", but really it's dns only and their servers are wide open. It's even worse if they migrated from another provider that was providing ddos protection.