Web Application Firewall — protect your site, keep your DNS

SucuraGuard WAF is a reverse-proxy web application firewall on our own anycast network — Toronto, Chicago, Frankfurt, and Singapore. Point one A-record at our anycast VIP and we filter Layer-7 attacks, bots, and abuse before clean traffic reaches your origin. You keep your existing DNS provider — nothing to migrate. Unlimited domains on every tier, free to start, from $20/mo.

Quick Answer

SucuraGuard WAF is a reverse-proxy web application firewall running on Sucura's own AS398999 anycast network. You register your hostname and origin server in the Nexus panel, add one A-record at your existing DNS provider pointing at our anycast VIP, and we sit in front of your site — filtering attacks, bots, and abuse — while you keep your DNS and registrar exactly where they are. Free to start, plans from $20/mo.

4 PoPs
Anycast Edge
1 Record
Keep Your DNS
AS398999
Network
$0
Free Tier

A WAF That Doesn't Ask for Your Nameservers

Most web application firewalls come bundled with a DNS takeover: to get protection, you hand your nameservers to the vendor and route every record — mail, subdomains, everything — through their control panel. That's a real switching cost, and it's more than most sites need just to filter bad traffic on one hostname.

SucuraGuard WAF works the other way. It's a reverse proxy on our own AS398999 anycast network — you register the hostname you want protected and the origin server behind it, we pre-issue a certificate, and you add one A-record at whatever DNS provider you already use. Your registrar, your nameservers, your other records — untouched. Traffic to that hostname routes to the nearest of our four PoPs, gets filtered, and clean requests are forwarded to your origin.

It runs on the same anycast network that already scrubs Layer 3/4 DDoS traffic for Sucura customers, so the WAF is a Layer-7 layer added to infrastructure we already operate — not a second vendor and a second dashboard.

How It Works

1

Add Site & Origin

In Nexus, enter the hostname you want protected and your origin server's address (IP:port).

2

Cert Pre-Issued

A TLS certificate is issued automatically, before your DNS even points at us.

3

Point One A-Record

Add a single A-record at your existing DNS provider pointing your host at our anycast VIP. Keep your DNS.

4

Live & Protected

Once the record propagates, your site is proxied through the nearest PoP — usually within minutes.

The 30-day detect window

New sites get roughly 30 days of detect-only behaviour on new rule matches before anything blocks by default, so a brand-new WAF configuration doesn't false-positive and break a live site the day you turn it on. You can still enable blocking immediately on any rule you've already tuned.

What SucuraGuard WAF Actually Does

Every feature below is live in the product today — nothing on this page is roadmap.

M
Managed WAF Rules
Curated ruleset - covers known-CVE exploits, vulnerability scanners, probes, and other bad or malicious request paths
On by default - included on every tier, updated centrally
Not a named framework - a Sucura-managed ruleset, not a third-party rule set you have to license
R
Custom Rule Engine
Version-controlled - full rule history with diff and revert
Rich match conditions - IP, ASN, network owner, geography (country/continent/region/city), TLS fingerprint (JA3/JA4), HTTP/2 fingerprint, bot score, rate-exceeded, request path or header
Rule limits by tier - 5 on Free, 25 on Pro, 250 on Business, unlimited on Enterprise
B
Bot & Abuse Management
Verified-bot allowlisting - so known good crawlers aren't caught by mistake
Scored bot-signal engine - cadence analysis and per-signal tuning on Pro and up
Credential-stuffing defence - watches configured login routes and tracks failures (Pro+); username-level tracking on Business
A
Adaptive Baseline
Anomaly learning - builds a baseline of your site's normal traffic pattern (Pro and up)
Flags deviation - surfaces traffic that departs from that baseline for review or automatic action
L
Layer-7 Rate Limiting
Token-bucket model - set a burst size and a refill rate per rule (Pro and up)
Path or condition scoped - limit a login form or API route without throttling the whole site
C
Challenge Engine + Under Attack Mode
Four levels - off, invisible proof-of-work, automatic managed, or CAPTCHA (CAPTCHA on Pro and up)
Under Attack Mode - one switch to raise the challenge posture site-wide during an active incident
E
Anycast Edge Caching
Cache purge & dev-mode bypass - control what's cached and when
Always Online - serves a stale cached copy of your site if your origin goes down
Not a full CDN - caching and Always Online only; no image optimization, no edge compute
O
Auto-TLS, Origin Security & Observability
Automatic TLS - certificates issued and renewed automatically, pre-issued before DNS points at us; custom certificate upload on Business
Authenticated origin pull - mutual TLS between our edge and your origin (Business)
Ray ID & per-site analytics - per-request trace lookup, event log, and analytics scoped to each host (retention varies by tier)

Why Not Just Use Cloudflare?

Cloudflare is a fine product used by millions of sites — this isn't a claim that we replace it for everyone. It's the honest case for where SucuraGuard WAF is genuinely a better fit.

Keep your DNS

Cloudflare's default onboarding takes over your authoritative DNS with its own nameservers. SucuraGuard WAF asks for one A-record at whatever DNS provider you already use — your nameservers never change.

Unlimited domains, flat price

Every tier — including Free — covers unlimited domains on your account. You're not billed per site as your portfolio grows.

Real controls on the $20 tier

Bot-signal tuning, credential-stuffing defence, adaptive baseline, Layer-7 rate limiting, and CAPTCHA challenges are all on Pro at $20/mo — not held back for an enterprise-only plan.

WAF + DDoS, one network

SucuraGuard WAF runs on the same AS398999 anycast network as Sucura's DDoS protection, so Layer-7 filtering and Layer 3/4 scrubbing sit on infrastructure we operate end to end.

Pricing

Per account, unlimited domains on every tier. Pick one in the Nexus panel — the Free tier costs nothing to try.

Free
$0
Unlimited domains
5 custom rules
Managed WAF ruleset
Basic challenge
Basic edge caching
1-day analytics
Pro
$20/mo
Unlimited domains
25 custom rules
Bot per-signal tuning
Credential-stuffing defence
Adaptive baseline
L7 rate limiting
Advanced caching
CAPTCHA challenge
API access
7-day analytics
Business
$200/mo
Unlimited domains
250 custom rules
Mutual-TLS origin pull
Custom certificate upload
Username-level credential-stuffing tracking
30-day analytics
Enterprise
Custom
Unlimited domains
Unlimited custom rules
Extended (~13-month) analytics retention
Prices are in USD; CAD billing is available. No per-request or metered charges — pricing is a flat monthly fee per tier.
Start Free in Nexus →

Frequently Asked Questions

Do I have to change my nameservers or move my DNS?
No. You keep your existing DNS provider and registrar. You add one A-record at your current DNS provider pointing your hostname at our anycast VIP — there is no nameserver migration and nothing to move.
What does SucuraGuard WAF actually do?
It's a reverse-proxy web application firewall: it filters Layer-7 attacks, bots, and abuse before traffic ever reaches your origin server. That includes a managed ruleset, your own custom rules, challenges, Layer-7 rate limiting, anycast edge caching, and automatic TLS, all configured self-service in the Nexus panel.
Is this a CDN?
No. It's an anycast reverse proxy with edge caching and an Always Online mode that can serve a stale cached copy if your origin goes down — but it is not a full CDN. There is no image optimization and no edge compute, so don't expect asset acceleration beyond caching.
How is this different from Cloudflare?
You keep your DNS instead of moving to our nameservers — one A-record at your current provider is all it takes. Every tier covers unlimited domains at one flat price rather than per-site billing, real bot management and rate limiting are available on the $20/mo tier rather than gated to an enterprise plan, and WAF and DDoS protection run on the same AS398999 anycast network instead of separate products.
What attacks does it stop?
A managed ruleset covers known-CVE exploits, vulnerability scanners, probes, and other bad or malicious request paths. On top of that you can write your own custom rules matching on IP, ASN, geography, TLS/HTTP fingerprint, bot score, or rate, and layer in bot management, Layer-7 rate limiting, and challenges for anything the managed rules don't already catch.
Is there a free tier, and how fast can I set it up?
Yes — the Free tier is $0/mo with unlimited domains, the managed ruleset, 5 custom rules, and basic challenge and caching. Add your site and origin in Nexus, add the one A-record at your existing DNS provider, and once it propagates your site is proxied and protected, usually within minutes.
Is Sucura the same as Sucuri?
No. Sucura Networks is an independent Canadian network operator running our own autonomous system, AS398999. We are not affiliated with Sucuri (the website security company owned by GoDaddy) or with GoDaddy — the similar name is a coincidence.
Does it work with the DDoS protection?
Yes. SucuraGuard WAF runs on the same AS398999 anycast network as Sucura's DDoS protection. DDoS scrubbing handles Layer 3/4 volumetric attacks at the network edge, and the WAF adds Layer-7 filtering — managed and custom rules, bot management, and rate limiting — on top, so the two products complement each other on one network instead of stacking two vendors.
Start Free in Nexus Contact Us

Related SucuraGuard Resources