One less target
Most attacks start by reading off where you live. With the proxy switched on that information is no longer public: automated scans don’t find your machine, and hostile traffic has no shortcut around us.
Managed DNS · Proxy · Protection
SecureFlare answers for your domain from the point on our network closest to whoever is browsing, and stands in front of your server. The world sees one of our addresses; your machine’s own address never turns up anywhere.
Nothing to migrate, nothing to reinstall. You change the nameservers at your registrar and you’re live.
Example address. If they can’t find you, they can’t aim at you.
Most attacks start by reading off where you live. With the proxy switched on that information is no longer public: automated scans don’t find your machine, and hostile traffic has no shortcut around us.
Every visit begins with a question to the DNS. Our network answers from the point nearest to whoever asked, so the page starts loading sooner.
Bad requests are stopped on our network. Your server spends no bandwidth and no effort answering someone whose only aim was to bring it down.
How it works
Whoever visits your site speaks to us twice, and never speaks to your server directly.
The browser asks who answers for your name. The question arrives on our network.
The visitor is handed a point on the SecureFlare network, not your server.
Certificate, filters and rules all apply here. Only what gets through reaches your server.
The fourth step is your server, and nobody sees it. The only road that leads there runs through us, and here your rules are the ones that count.
Managed DNS
You delegate the domain to our two nameservers and run the rest from the panel: no files to edit, no waiting around, no syntax to memorise.
The nameservers to set
ns1.secureflare.cloud
ns2.secureflare.cloud
One configuration answers from the whole network: whoever looks you up gets the reply from the point close to them, wherever they are.
Want the bare name of your domain to lead to the name of a service rather than to a fixed address? Plain DNS won’t allow it. Here it will: we resolve the name for you at the moment we answer.
Mail, ownership checks, certificates, third-party services, the newest types: whatever a provider asks you to add, you’ll find it in the panel.
Turn on DNSSEC, copy the code we show you and paste it at your registrar. From that moment the answers for your domain can be verified and can’t be forged.
We keep an eye on your servers. If one stops answering you hear it from us, without taking out a separate monitoring subscription.
Spread visits across more than one machine. If one goes down the traffic moves to the others, and nobody browsing notices.
Proxy
Protection isn’t all or nothing. You decide entry by entry what travels through our network and what stays as it is: the site behind the proxy, the mail straight to its own server.
Whatever you switch on answers with an address of ours. Whatever you leave off keeps working exactly as it did before.
The padlock turns itself on and renews itself. No expiry date to keep in the diary.
Images, stylesheets and static files leave from our network, close to the visitor, without troubling your server.
New machine, new provider, new address: you update it here and, seen from outside, nothing has moved.
Switch it off and the traffic goes straight back to your server, with no configuration to redo.
Protection
Every defence runs on our network, not inside your server. What we throw away costs you nothing.
The waves of traffic built to knock you offline are soaked up by the network, before they ever touch your bandwidth.
Rules kept up to date against the common ways of breaking into a site or emptying its database.
We separate the automation you want, search engines among it, from the kind that lifts your content or tries passwords.
Thresholds per address, per user or per single page: anyone pushing too hard is slowed down or stopped.
Block or allow whole networks, VPNs, anonymising nodes or single countries, depending on who is meant to reach you.
Whatever your users upload is examined before it ever reaches the disk of your server.
If you run an application, malformed or unauthorised requests stop with us and never reach your code.
Platform
The panel is made for someone with a site to keep running, not for someone who administers systems for a living.
Domains, entries and subdomains in a list that makes sense at a glance, with the state of each one always in view. Every change is clear before you confirm it.
Everything the panel does, our programming interface does as well, with separate keys for those who only have to read and those who may also write.
A service of its own, for anyone building applications: the values your app reads at start-up you change from here, with a draft, versions and a way back, without shipping a new release.
Setup
The domain stays where it is and the server stays where it is. All that changes is who answers for you.
You type it into the panel and its configuration appears right away, ready to fill in.
In the panel at your registrar, in place of the current ones, put our two.
ns1.secureflare.cloud
ns2.secureflare.cloud
As soon as the delegation shows up the domain turns active. From there you switch protection on wherever you want it.
Plans aren’t public yet. In the meantime the panel is open: add a domain, see how it’s put together and take your time deciding.