Cloudflare's account-level `enforce_dns_only` setting makes direct-to-origin failover fast, but it also removes proxy-based protection across the account. The real work is proving your DNS, certificates, firewall rules, and origin capacity can survive that mode before you ever need it.