A Cloudflare-zone DNS record points back at Cloudflare IPs — a loop Cloudflare refuses to proxy. Usually a record meant to be gray-cloud (DNS-only) that got proxied.
An A/AAAA/CNAME record set to Cloudflare's edge IPs (or a CNAME to a proxied hostname) with the orange cloud on = infinite proxy loop. Cloudflare blocks it with 1000.
alias.example.com CNAME → example.com (proxied) while alias is also proxied: the loop again, just one hop deeper.
# dashboard → DNS: look for records whose target resolves to Cloudflare IPs (104.x/172.64-71.x) or CNAMEs to proxied hostnames
# toggle proxy OFF for records that must point at Cloudflare-fronted targets (origin-exposed service, verification records, app-platform domains)
# the origin server's public IP, not the proxied/edge address
dig +short <subdomain> ; curl -sI https://<subdomain>/ | head -3
Records for SaaS platforms (Vercel, Base44, etc.) that hand you a CNAME to THEIR proxied hostname must be DNS-only from your side — the platform does its own Cloudflare fronting. Error 1000 is Cloudflare protecting itself from proxy loops — the config, not the platform, is what needs fixing.
Orange = Cloudflare proxies (origin hidden, edge features on). Gray = plain DNS. If the record's TARGET is itself behind Cloudflare, you must use gray — proxying a proxy is what triggers 1000.
Your previous registrar served the record plainly. Once Cloudflare proxies it, the same target becomes a loop. Gray-cloud that record and behavior returns to normal.
Our most-documented failures, packaged as ready-to-ship starter kits: Docker, Kubernetes, and Terraform.
Browse the template store →One-time. Yours to modify. Instant download from the NinjaOps template store.