Cloudflare Registrar vs Porkbun

Choose Cloudflare Registrar if your domains already use Cloudflare DNS and you want at-cost renewals with no markup — it's the cheapest way to hold a domain long-term. Choose Porkbun if you want a broad TLD selection, a proper API, email forwarding and the ability to use any nameservers you like.

Editorial judgement last reviewed

Should I register domains with Cloudflare or Porkbun?

Both of these are the answer to "stop paying GoDaddy". They differ in what they're willing to do for you.

Cloudflare Registrar sells domains at cost. Not discounted the first year and marked up afterwards — at wholesale, permanently, with WHOIS privacy included and no upsells. The catch is that it exists to keep you inside Cloudflare: you must use Cloudflare's nameservers, the TLD list is limited to the ones they support, and there is no domain-registration API for the general case. It's a loss leader, and an unusually honest one.

Porkbun is a real registrar with a real product. Wide TLD coverage including the niche ones, honest pricing with free WHOIS privacy, free SSL, email forwarding included, a proper API for programmatic registration and DNS, and support that answers. Renewal prices are slightly above wholesale, which is what it costs to run a business that isn't subsidised by something else.

If you have a portfolio of domains parked long-term and they're all on Cloudflare anyway, transfer them to Cloudflare Registrar and save real money every year.

If you register domains programmatically, want unusual TLDs, or want nameserver freedom, use Porkbun — the price difference is a few dollars a year and you get an actual product for it.

Many people use both: Cloudflare for the domains that matter and never move, Porkbun for everything else. That's a sensible arrangement rather than indecision.

Which one should you pick?

Choose Cloudflare Registrar if…

  • You want the lowest possible renewal price. At-cost means at-cost, and over ten years on a portfolio that's a meaningful amount of money.
  • Your DNS is already on Cloudflare and you have no intention of moving it.
  • You want WHOIS privacy included, no upsells, no dark patterns and no renewal-price surprise in year two.
  • You're holding domains long-term — a portfolio, defensive registrations, brand protection.
  • Your TLDs are mainstream: .com, .net, .org, .io, .dev and the other well-supported ones.
  • You don't need to register domains from code.

Choose Porkbun if…

  • You want an API. Porkbun's covers registration, DNS records and renewals, which Cloudflare Registrar does not offer generally.
  • You need a TLD outside Cloudflare's supported list, including country-code and niche extensions.
  • You want to point the domain at nameservers that aren't Cloudflare's — Route 53, Bunny, your own, or a client's.
  • You want email forwarding, free SSL and URL forwarding included rather than sold separately.
  • You register domains for clients or for a business that isn't otherwise a Cloudflare shop.
  • You want a registrar whose business model is selling domains, not acquiring users for something else.

At-cost pricing: what it means and what it costs you

Cloudflare's registrar charges you exactly what it pays the registry, plus the mandatory ICANN fee. No margin. That is genuinely unusual — most registrars run a low first-year price to win the registration and recover it over years of renewals, which is why a domain you registered for a few dollars renews for several times that.

Over a decade, on a portfolio of twenty domains, at-cost versus a typical retail markup is hundreds of dollars. On a single hobby domain it's a rounding error. Scale your interest in this accordingly.

Porkbun's pricing is not at-cost but it is honest: the renewal price is published next to the registration price, WHOIS privacy is free rather than a $10 upsell, and there's no pattern of quiet increases. That's a low bar in this industry and Porkbun clears it comfortably, which is most of why it's recommended so often.

The pricing to actually avoid is the incumbent model — a cheap first year, an expensive renewal, privacy sold separately, and a checkout flow with four pre-ticked add-ons. Both options on this page are a straightforward improvement on that.

Renewal price is the field that matters, not registration price. Our registrar hub sorts on renewal for exactly that reason, and it's the number we'd tell a friend to check first.

The nameserver constraint, and why it's the real decision

Cloudflare Registrar requires the domain to use Cloudflare's nameservers. This isn't a soft preference; it's the condition of the at-cost pricing, and it makes sense from their side.

For most people this is fine or actively good. Cloudflare's DNS is fast, free, has a decent API, and the proxying, page rules and WAF are already where you want them.

It's a problem in specific cases: a client's domain that must stay on their DNS provider, a setup with DNSSEC managed elsewhere, an architecture that needs a DNS feature Cloudflare doesn't expose, or a compliance requirement that your DNS not sit behind a reverse proxy. In those cases the constraint is disqualifying and Porkbun is your answer.

There's also a concentration argument. Putting your registrar, DNS, CDN, WAF, object storage and compute with one vendor means one account compromise or one billing dispute affects everything at once. Some teams deliberately keep the registrar separate from the CDN for exactly this reason. Whether that's prudent or paranoid depends on what the domain is worth to you — but if the answer is "the entire company", separating it is cheap insurance.

APIs and programmatic registration

If you register domains from code — a product that provisions customer subdomains on real TLDs, a tool that hunts for available names, a client-onboarding flow — Cloudflare Registrar is not the right tool. It has no general registration API, and the DNS API it does have is for records on domains you already hold.

Porkbun's API handles the full lifecycle: check availability, register, set nameservers, manage DNS records, renew. It's straightforward REST with API-key authentication, the docs are clear, and there is no minimum spend or reseller agreement to get access. For most programmatic use cases it is the pragmatic pick.

Above that tier sit the purpose-built domain APIs — Namecheap's reseller API, Dynadot, and infrastructure-grade providers like Name.com and OpenSRS — which offer bulk operations, reseller pricing and better rate limits. We cover those separately on the domain API providers hub, because the buying criteria there are genuinely different: you care about pricing tiers, TLD coverage at wholesale, sandbox environments and rate limits rather than about a dashboard.

The dividing line is roughly volume. Under a few hundred domains a year, Porkbun's API is fine. Above that, talk to a reseller-oriented provider.

Transfers, and the small print that catches people

Moving a domain between registrars takes about a week and follows a fixed sequence: unlock at the current registrar, get the authorisation code, initiate at the new one, approve the confirmation email. Both platforms handle it competently.

Four things to know before you start. First, ICANN blocks transfers within sixty days of registration or of a previous transfer — plan around it. Second, a transfer adds a year to the registration and you pay for that year, so you're not losing time, but you are paying up front. Third, WHOIS privacy sometimes hides the administrative contact address that the confirmation email goes to; check it's reachable before you begin. Fourth, DNS records do not travel with the domain — export your zone file first, recreate it at the destination, and only then flip the nameservers.

That last one is the classic outage. Someone transfers a domain, the nameservers change, and every record disappears because nobody exported the zone. Do it in the right order and the transfer is invisible to users.

For inbound transfers to Cloudflare specifically, the domain needs to be on a Cloudflare account with its DNS already active, which effectively means you do the DNS move first and the registrar move second. That ordering is the safe one anyway.

Frequently asked questions

Is Cloudflare Registrar really at cost?

Yes — you pay the registry fee plus the ICANN fee, with no markup, and WHOIS privacy is included. The trade is that the domain must use Cloudflare nameservers and the supported TLD list is narrower than a full-service registrar's.

Can I use Cloudflare Registrar with external DNS?

No. Cloudflare nameservers are a requirement of the at-cost pricing. If you need Route 53, Bunny, a client's provider or your own nameservers, use Porkbun or another registrar.

Does Porkbun have an API for registering domains?

Yes — availability checks, registration, renewal, nameserver changes and DNS record management, with API-key authentication and no reseller agreement required. It's the more practical choice for programmatic registration.

Which is better for a domain portfolio?

Cloudflare, on price, if the TLDs are supported and you're happy on their nameservers. At-cost renewals compound across dozens of domains and many years. Keep anything needing custom DNS or an unusual TLD at Porkbun.

What about GoDaddy, Namecheap or Google Domains?

Google Domains was sold to Squarespace, which is why a wave of people moved. Namecheap is a reasonable middle option with a solid reseller API. GoDaddy is consistently the most expensive at renewal with the most aggressive upsells; both options here are a straight improvement.