SucuraGuard WAF is a reverse-proxy web application firewall on our own anycast network — Toronto, Chicago, Frankfurt, and Singapore. Point one A-record at our anycast VIP and we filter Layer-7 attacks, bots, and abuse before clean traffic reaches your origin. You keep your existing DNS provider — nothing to migrate. Unlimited domains on every tier, free to start, from $20/mo.
SucuraGuard WAF is a reverse-proxy web application firewall running on Sucura's own AS398999 anycast network. You register your hostname and origin server in the Nexus panel, add one A-record at your existing DNS provider pointing at our anycast VIP, and we sit in front of your site — filtering attacks, bots, and abuse — while you keep your DNS and registrar exactly where they are. Free to start, plans from $20/mo.
Most web application firewalls come bundled with a DNS takeover: to get protection, you hand your nameservers to the vendor and route every record — mail, subdomains, everything — through their control panel. That's a real switching cost, and it's more than most sites need just to filter bad traffic on one hostname.
SucuraGuard WAF works the other way. It's a reverse proxy on our own AS398999 anycast network — you register the hostname you want protected and the origin server behind it, we pre-issue a certificate, and you add one A-record at whatever DNS provider you already use. Your registrar, your nameservers, your other records — untouched. Traffic to that hostname routes to the nearest of our four PoPs, gets filtered, and clean requests are forwarded to your origin.
It runs on the same anycast network that already scrubs Layer 3/4 DDoS traffic for Sucura customers, so the WAF is a Layer-7 layer added to infrastructure we already operate — not a second vendor and a second dashboard.
In Nexus, enter the hostname you want protected and your origin server's address (IP:port).
A TLS certificate is issued automatically, before your DNS even points at us.
Add a single A-record at your existing DNS provider pointing your host at our anycast VIP. Keep your DNS.
Once the record propagates, your site is proxied through the nearest PoP — usually within minutes.
New sites get roughly 30 days of detect-only behaviour on new rule matches before anything blocks by default, so a brand-new WAF configuration doesn't false-positive and break a live site the day you turn it on. You can still enable blocking immediately on any rule you've already tuned.
Every feature below is live in the product today — nothing on this page is roadmap.
Cloudflare is a fine product used by millions of sites — this isn't a claim that we replace it for everyone. It's the honest case for where SucuraGuard WAF is genuinely a better fit.
Cloudflare's default onboarding takes over your authoritative DNS with its own nameservers. SucuraGuard WAF asks for one A-record at whatever DNS provider you already use — your nameservers never change.
Every tier — including Free — covers unlimited domains on your account. You're not billed per site as your portfolio grows.
Bot-signal tuning, credential-stuffing defence, adaptive baseline, Layer-7 rate limiting, and CAPTCHA challenges are all on Pro at $20/mo — not held back for an enterprise-only plan.
SucuraGuard WAF runs on the same AS398999 anycast network as Sucura's DDoS protection, so Layer-7 filtering and Layer 3/4 scrubbing sit on infrastructure we operate end to end.
Per account, unlimited domains on every tier. Pick one in the Nexus panel — the Free tier costs nothing to try.