Most web application firewalls ask you to hand over your DNS to get protected. SucuraGuard WAF doesn't. Add your site in the Nexus panel, point one A-record at our anycast VIP from whatever DNS provider you already use, and your registrar, MX records, and every other DNS record stay exactly where they are. Unlike Cloudflare's default nameserver takeover. Free to start, from $20/mo.
Yes, you can get a web application firewall without changing your nameservers. SucuraGuard WAF is a reverse-proxy WAF on Sucura's AS398999 anycast network: you register your hostname and origin in the Nexus panel, we pre-issue a certificate, and you add one A-record at your existing DNS provider pointing at our anycast VIP. Your registrar, MX records, and every other record in your zone are untouched. This is unlike Cloudflare's default onboarding, which takes over your authoritative DNS — though Cloudflare's Business-plan CNAME setup, and comparable options from Sucuri and Imperva, also avoid a full nameserver migration.
Your DNS zone is more than the one hostname you want protected. It's your registrar relationship, your MX records routing email, your SPF and DKIM entries keeping that mail deliverable, your subdomains pointing at other apps, and any TXT records verifying domain ownership with Google Workspace, Microsoft 365, or a dozen other services. A WAF that requires a nameserver migration to get set up is asking you to move all of that to a new vendor's control panel — just to filter traffic on one hostname.
Your registrar stays yours. Nothing about adding a reverse-proxy WAF should touch who you registered your domain through or which company you pay for it.
Your email keeps working, untouched. MX records, SPF, and DKIM are exactly the kind of record that breaks mail delivery when a DNS migration goes wrong — a missed record, a TTL that takes hours to expire, a typo in a re-entered zone file. If the WAF only needs one A-record, your mail configuration is never even in scope.
Every other record stays under your control. Subdomains for staging environments, internal tools, third-party service verification, CNAME records for other vendors — none of it has to be re-entered into a new nameserver's dashboard, and none of it is at risk of a copy-paste error during the move.
It's easy to revert. If a WAF setup doesn't work out, undoing a full nameserver migration means moving your entire zone back, hoping you documented every record correctly, and waiting out propagation on all of it. Undoing a single A-record is exactly that: repoint one record back to your origin's IP, and traffic goes straight to your server again.
No single-vendor lock-in of your zone. When one company holds your authoritative DNS, they hold every record in it, not just the one you wanted proxied. Keeping your zone at your existing provider means the WAF vendor's relationship with you is scoped to exactly the traffic you asked them to filter — nothing more.
In Nexus, enter the hostname you want protected and your origin server's address (IP:port). Nothing in your DNS zone changes yet.
A TLS certificate is issued automatically, before your DNS even points at us — no downtime waiting on certificate issuance.
Add a single A-record at your existing DNS provider pointing your host at our anycast VIP. Your registrar and every other record stay put.
Once the record propagates, your site is proxied through the nearest PoP — usually within minutes. Everything else in your zone is unchanged.
New sites get roughly 30 days of detect-only behaviour on new rule matches before anything blocks by default, so a brand-new WAF configuration doesn't false-positive and break a live site the day you turn it on. You can still enable blocking immediately on any rule you've already tuned.
This is a keep-your-DNS comparison, not a claim that Sucura is the only WAF that avoids a nameserver migration — Sucuri and Imperva offer comparable A-record or CNAME proxy setups. The honest difference here is specifically versus Cloudflare's default path.
Cloudflare's standard signup takes over your authoritative DNS: you're asked to repoint your domain's nameservers to Cloudflare's, and your entire zone — MX, subdomains, TXT records, all of it — is now managed through their dashboard. Cloudflare does offer a way around this, a CNAME/partial-zone setup that only proxies the one hostname you want, but it's restricted to their Business plan and up.
SucuraGuard WAF's onboarding is the CNAME/partial-zone experience by default, on every tier including Free: one A-record at whatever DNS provider you already use, nothing else in your zone touched. It's not a claim that keeping your DNS is impossible elsewhere — it's that you don't have to pay for an enterprise plan to get it.
Keeping your DNS is the onboarding story. Once you're pointed at us, here's what's actually filtering your traffic.
Per account, unlimited domains on every tier. The keep-your-DNS onboarding is the same at every price point, including Free.