SecureFlare

Managed DNS · Proxy · Protection

Your site, fast everywhere.
Your server, nowhere to be found.

SecureFlare answers for your domain from the point on our network closest to whoever is browsing, and stands in front of your server. The world sees one of our addresses; your machine’s own address never turns up anywhere.

Nothing to migrate, nothing to reinstall. You change the nameservers at your registrar and you’re live.

What the world sees of your domain
your domain 198.51.100.24 SecureFlare network
your server never published

Example address. If they can’t find you, they can’t aim at you.

What changes for you

One less target

Most attacks start by reading off where you live. With the proxy switched on that information is no longer public: automated scans don’t find your machine, and hostile traffic has no shortcut around us.

Answers from closer by

Every visit begins with a question to the DNS. Our network answers from the point nearest to whoever asked, so the page starts loading sooner.

The filter sits in front

Bad requests are stopped on our network. Your server spends no bandwidth and no effort answering someone whose only aim was to bring it down.

How it works

Three steps, and one stays invisible

Whoever visits your site speaks to us twice, and never speaks to your server directly.

1

Someone looks up your domain

The browser asks who answers for your name. The question arrives on our network.

2

We answer with an address of ours

The visitor is handed a point on the SecureFlare network, not your server.

3

We inspect the request, then pass it on

Certificate, filters and rules all apply here. Only what gets through reaches your server.

The fourth step is your server, and nobody sees it. The only road that leads there runs through us, and here your rules are the ones that count.

Managed DNS

DNS that doesn’t make you compromise

You delegate the domain to our two nameservers and run the rest from the panel: no files to edit, no waiting around, no syntax to memorise.

The nameservers to set

ns1.secureflare.cloud

ns2.secureflare.cloud

  • Answers from the nearest point

    One configuration answers from the whole network: whoever looks you up gets the reply from the point close to them, wherever they are.

  • Your domain without www can point anywhere

    Want the bare name of your domain to lead to the name of a service rather than to a fixed address? Plain DNS won’t allow it. Here it will: we resolve the name for you at the moment we answer.

  • Every record you need is there

    Mail, ownership checks, certificates, third-party services, the newest types: whatever a provider asks you to add, you’ll find it in the panel.

  • Sign your domain in two clicks

    Turn on DNSSEC, copy the code we show you and paste it at your registrar. From that moment the answers for your domain can be verified and can’t be forged.

  • Host checks included

    We keep an eye on your servers. If one stops answering you hear it from us, without taking out a separate monitoring subscription.

  • Several servers behind one name

    Spread visits across more than one machine. If one goes down the traffic moves to the others, and nobody browsing notices.

Proxy

A switch on every record

Protection isn’t all or nothing. You decide entry by entry what travels through our network and what stays as it is: the site behind the proxy, the mail straight to its own server.

The site Protected
The customer area Protected
The mail Direct

Whatever you switch on answers with an address of ours. Whatever you leave off keeps working exactly as it did before.

  • Certificates handled for you

    The padlock turns itself on and renews itself. No expiry date to keep in the diary.

  • Content served from the network

    Images, stylesheets and static files leave from our network, close to the visitor, without troubling your server.

  • Change servers whenever you like

    New machine, new provider, new address: you update it here and, seen from outside, nothing has moved.

  • Reversible at any time

    Switch it off and the traffic goes straight back to your server, with no configuration to redo.

Protection

Hostile traffic stops before it gets to you

Every defence runs on our network, not inside your server. What we throw away costs you nothing.

DDoS attacks

The waves of traffic built to knock you offline are soaked up by the network, before they ever touch your bandwidth.

Application firewall

Rules kept up to date against the common ways of breaking into a site or emptying its database.

Bots recognised

We separate the automation you want, search engines among it, from the kind that lifts your content or tries passwords.

Rate limiting

Thresholds per address, per user or per single page: anyone pushing too hard is slowed down or stopped.

Access lists

Block or allow whole networks, VPNs, anonymising nodes or single countries, depending on who is meant to reach you.

Incoming files checked

Whatever your users upload is examined before it ever reaches the disk of your server.

Calls verified

If you run an application, malformed or unauthorised requests stop with us and never reach your code.

Platform

Built to be used, not studied

The panel is made for someone with a site to keep running, not for someone who administers systems for a living.

A panel you can read

Domains, entries and subdomains in a list that makes sense at a glance, with the state of each one always in view. Every change is clear before you confirm it.

Automation, if you need it

Everything the panel does, our programming interface does as well, with separate keys for those who only have to read and those who may also write.

Remote Config

A service of its own, for anyone building applications: the values your app reads at start-up you change from here, with a draft, versions and a way back, without shipping a new release.

Setup

Three steps, one change at the registrar

The domain stays where it is and the server stays where it is. All that changes is who answers for you.

  1. Add the domain

    You type it into the panel and its configuration appears right away, ready to fill in.

  2. Change the nameservers

    In the panel at your registrar, in place of the current ones, put our two.

    ns1.secureflare.cloud
    ns2.secureflare.cloud

  3. It’s live

    As soon as the delegation shows up the domain turns active. From there you switch protection on wherever you want it.

Start from the panel

Plans aren’t public yet. In the meantime the panel is open: add a domain, see how it’s put together and take your time deciding.