How can I use Automated Certificate Management with CloudFlare?


I use CloudFlare, but also want to use ACM. Is it possible to use both of these products together?


It is possible to use CloudFlare with ACM, but you won't be able to take advantage of their more advanced features (e.g., CDN, DoS protection, etc.). To use ACM with CloudFlare, you need to configure your domain using the "DNS only" option and NOT the "DNS and HTTP Proxy (CDN)" option. If you do that, then ACM will work fine for your application.

The reason why this is the case is that part of the ACM provisioning process involves performing a DNS verification step with Let's Encrypt. During that process, we generate a temporary SSL certificate that Let's Encrypt expects and serve it for your app's domain. Let's Encrypt then makes a connection to verify that you own the domain. This relies upon your DNS actually pointing to our routing endpoints. The "DNS only" option does just that. The "DNS and HTTP Proxy" option points your DNS to one of CloudFlare's endpoints which does not have the certificate. This causes the DNS verification to fail.

As such, the "DNS only" option is the only one that will work with Heroku ACM.


  • Use "Full SSL" (rather than "Full SSL (Strict)") with CloudFlare. You can disable ACM and follow the setup described here.
  • Upload a custom certificate with Heroku SSL to fully secure your connection end-to-end.

Ask on Stack Overflow

Engage with a community of passionate experts to get the answers you need

Ask on Stack Overflow

Heroku Support

Create a support ticket and our support experts will get back to you

Contact Heroku Support
Terms of Service Privacy Cookies © 2018