WAF without changing your nameservers

Most web application firewalls ask you to hand over your DNS to get protected. SucuraGuard WAF doesn't. Add your site in the Nexus panel, point one A-record at our anycast VIP from whatever DNS provider you already use, and your registrar, MX records, and every other DNS record stay exactly where they are. Unlike Cloudflare's default nameserver takeover. Free to start, from $20/mo.

Quick Answer

Yes, you can get a web application firewall without changing your nameservers. SucuraGuard WAF is a reverse-proxy WAF on Sucura's AS398999 anycast network: you register your hostname and origin in the Nexus panel, we pre-issue a certificate, and you add one A-record at your existing DNS provider pointing at our anycast VIP. Your registrar, MX records, and every other record in your zone are untouched. This is unlike Cloudflare's default onboarding, which takes over your authoritative DNS — though Cloudflare's Business-plan CNAME setup, and comparable options from Sucuri and Imperva, also avoid a full nameserver migration.

1 Record
Keep Your DNS
0
Nameservers Changed
AS398999
Network
$0
Free Tier

Why You Shouldn't Have to Hand Over Your DNS

Your DNS zone is more than the one hostname you want protected. It's your registrar relationship, your MX records routing email, your SPF and DKIM entries keeping that mail deliverable, your subdomains pointing at other apps, and any TXT records verifying domain ownership with Google Workspace, Microsoft 365, or a dozen other services. A WAF that requires a nameserver migration to get set up is asking you to move all of that to a new vendor's control panel — just to filter traffic on one hostname.

Your registrar stays yours. Nothing about adding a reverse-proxy WAF should touch who you registered your domain through or which company you pay for it.

Your email keeps working, untouched. MX records, SPF, and DKIM are exactly the kind of record that breaks mail delivery when a DNS migration goes wrong — a missed record, a TTL that takes hours to expire, a typo in a re-entered zone file. If the WAF only needs one A-record, your mail configuration is never even in scope.

Every other record stays under your control. Subdomains for staging environments, internal tools, third-party service verification, CNAME records for other vendors — none of it has to be re-entered into a new nameserver's dashboard, and none of it is at risk of a copy-paste error during the move.

It's easy to revert. If a WAF setup doesn't work out, undoing a full nameserver migration means moving your entire zone back, hoping you documented every record correctly, and waiting out propagation on all of it. Undoing a single A-record is exactly that: repoint one record back to your origin's IP, and traffic goes straight to your server again.

No single-vendor lock-in of your zone. When one company holds your authoritative DNS, they hold every record in it, not just the one you wanted proxied. Keeping your zone at your existing provider means the WAF vendor's relationship with you is scoped to exactly the traffic you asked them to filter — nothing more.

How It Works — One A-Record

1

Add Site & Origin

In Nexus, enter the hostname you want protected and your origin server's address (IP:port). Nothing in your DNS zone changes yet.

2

Cert Pre-Issued

A TLS certificate is issued automatically, before your DNS even points at us — no downtime waiting on certificate issuance.

3

Point One A-Record

Add a single A-record at your existing DNS provider pointing your host at our anycast VIP. Your registrar and every other record stay put.

4

Live & Protected

Once the record propagates, your site is proxied through the nearest PoP — usually within minutes. Everything else in your zone is unchanged.

The 30-day detect window

New sites get roughly 30 days of detect-only behaviour on new rule matches before anything blocks by default, so a brand-new WAF configuration doesn't false-positive and break a live site the day you turn it on. You can still enable blocking immediately on any rule you've already tuned.

Vs. Cloudflare's Default Onboarding

This is a keep-your-DNS comparison, not a claim that Sucura is the only WAF that avoids a nameserver migration — Sucuri and Imperva offer comparable A-record or CNAME proxy setups. The honest difference here is specifically versus Cloudflare's default path.

Cloudflare's standard signup takes over your authoritative DNS: you're asked to repoint your domain's nameservers to Cloudflare's, and your entire zone — MX, subdomains, TXT records, all of it — is now managed through their dashboard. Cloudflare does offer a way around this, a CNAME/partial-zone setup that only proxies the one hostname you want, but it's restricted to their Business plan and up.

SucuraGuard WAF's onboarding is the CNAME/partial-zone experience by default, on every tier including Free: one A-record at whatever DNS provider you already use, nothing else in your zone touched. It's not a claim that keeping your DNS is impossible elsewhere — it's that you don't have to pay for an enterprise plan to get it.

The WAF Itself — Briefly

Keeping your DNS is the onboarding story. Once you're pointed at us, here's what's actually filtering your traffic.

M
Managed + Custom Rules
Curated ruleset - covers known-CVE exploits, scanners, and bad request paths, on by default
Your own rules - match on IP, ASN, geography, TLS/HTTP fingerprint, bot score, or rate; 5 on Free, up to unlimited on Enterprise
B
Bot & Rate Management
Bot signal engine - verified-bot allowlisting plus scored bot detection (Pro and up)
L7 rate limiting - token-bucket limits scoped to a path or condition, so a login form can be throttled without limiting the whole site
C
Challenge Engine
Four levels - off, invisible proof-of-work, automatic managed, or CAPTCHA
Under Attack Mode - one switch to raise the challenge posture site-wide during an incident
O
Auto-TLS & Edge Caching
Automatic certificates - issued and renewed automatically, pre-issued before your DNS points at us
Anycast edge caching - cache purge, dev-mode bypass, and Always Online for a stale copy if your origin goes down — not a full CDN

Pricing

Per account, unlimited domains on every tier. The keep-your-DNS onboarding is the same at every price point, including Free.

Free
$0
Unlimited domains
5 custom rules
Managed WAF ruleset
Basic challenge
Basic edge caching
1-day analytics
Pro
$20/mo
Unlimited domains
25 custom rules
Bot per-signal tuning
Credential-stuffing defence
Adaptive baseline
L7 rate limiting
Advanced caching
CAPTCHA challenge
API access
7-day analytics
Business
$200/mo
Unlimited domains
250 custom rules
Mutual-TLS origin pull
Custom certificate upload
Username-level credential-stuffing tracking
30-day analytics
Enterprise
Custom
Unlimited domains
Unlimited custom rules
Extended (~13-month) analytics retention
Prices are in USD; CAD billing is available. No per-request or metered charges — pricing is a flat monthly fee per tier.
Start Free in Nexus →

Frequently Asked Questions

Do I have to change my nameservers?
No. You add one A-record at your current DNS provider pointing your hostname at our anycast VIP. There is no nameserver migration — your registrar and nameservers stay exactly as they are.
What happens to my email, MX records, or other DNS records?
They're untouched. You only add or point one A-record for the hostname you want protected. Your MX records, SPF/DKIM entries, subdomains, and every other record in your zone stay exactly where they are and under your control.
Can I undo it easily?
Yes. Repoint that one A-record back to your origin server's IP and traffic goes straight to your server again, no proxy in between. Nothing else in your DNS zone was ever changed, so there's nothing else to unwind.
Does Cloudflare require a nameserver change?
By default, yes — Cloudflare's standard onboarding takes over your authoritative DNS with its own nameservers. Cloudflare does offer a CNAME/partial-zone setup that avoids this, but it's gated to its Business plan. Sucuri and Imperva offer similar A-record or CNAME proxy options too, so keeping your DNS isn't unique to Sucura across the whole market — it's a real difference specifically versus Cloudflare's default path.
Do you host my DNS?
No. Sucura is not a DNS provider. You keep your existing DNS host and registrar; we only ask for one A-record pointing at our anycast VIP.
How long does it take to go live?
Minutes after the A-record propagates. Add your site and origin in Nexus, add the A-record at your existing DNS provider, and once it propagates your site is proxied and protected.
Is Sucura the same as Sucuri?
No. Sucura Networks is an independent Canadian network operator running our own autonomous system, AS398999. We are not affiliated with Sucuri (the website security company owned by GoDaddy) or with GoDaddy — the similar name is a coincidence.
Start Free in Nexus Contact Us

Related SucuraGuard Resources