DNS lives at the registrar, or at the old web host
Single-region nameservers, no redundancy, no monitoring, and a control panel someone's former web designer owns.
DNS is the one dependency every other system has. Your website, your email routing, your VPN endpoint, your line-of-business portal — all of it resolves through DNS first. AllTech moves that record set onto Cloudflare's anycast network, signs it, and puts always-on DDoS mitigation in front of everything you publish.
In most networks we take over, DNS is a footnote. It was configured once, by somebody who has since left, at a registrar nobody has the login for. It works until it doesn't, and then every system fails at the same time. The recurring findings:
Single-region nameservers, no redundancy, no monitoring, and a control panel someone's former web designer owns.
Nothing cryptographically proves your answers are yours, which leaves room for cache poisoning and resolver spoofing.
Stale A records pointing at decommissioned servers, duplicate SPF records breaking mail authentication, TXT entries from a vendor trial in 2019.
Even behind a proxy, an exposed IP in an old DNS record or mail header lets an attacker bypass every protection you paid for and hit the server directly.
A volumetric attack saturates the circuit before the firewall gets a vote, and the ISP's answer is usually to null-route you — which is indistinguishable from the outage you were trying to prevent.
In an incident, a 24-hour TTL means a 24-hour recovery.
We move authoritative DNS to Cloudflare's anycast network, publish it from every edge location simultaneously, and enable mitigation in front of the records that face the public internet. Configuration is documented and version-controlled alongside the rest of your Cloudflare tenant — so the next engineer can read it.
Your zone served from Cloudflare's global anycast network. Every nameserver answers from the nearest edge, so resolution stays fast and no single site failure takes the zone offline.
Zone signing enabled and the DS record published at your registrar, so resolvers can verify answers came from you and were not altered in transit.
Volumetric floods — SYN, UDP amplification, DNS reflection — absorbed and dropped at the edge, automatically, with no need for anyone to notice and flip a switch first.
HTTP floods, bot traffic, and application-targeted requests filtered with managed rulesets, rate limiting, and challenge actions rather than blanket blocks.
Cloudflare's managed rulesets in front of any public web application, tuned per site instead of enabled and forgotten.
Record audit and cleanup, SPF/DKIM/DMARC verified before cutover, sane TTLs, proxied vs. DNS-only decisions made record by record, and origin IP concealed where the record is proxied.
For TCP/UDP services that aren't HTTP, or for protecting your own IP space and circuit rather than just your published records. Scoped separately — see limitations.
Queries and requests are answered at the edge nearest the user, not backhauled to one data center you rent.
An attack aimed at your domain is spread across the entire network rather than concentrated on one circuit. Absorption replaces heroics.
No single nameserver, region, or link is the thing that takes your zone down.
Zone audit, record inventory, mail authentication check, DNSSEC status, and origin-exposure check. Written findings and a migration plan. Often the right first step, and it stands alone.
Staged zone build, verified cutover, DNSSEC enabled, mitigation and WAF configured, documentation handed over. Fixed scope.
Record changes, rule tuning, attack response, certificate and TTL management, monthly review. When something breaks at 2 a.m., the people who built it answer.
Export the existing zone, inventory every record, identify what's live and what's dead, confirm registrar access. Risk: None — read-only.
Build the zone in Cloudflare, match records exactly, decide proxied vs. DNS-only per record, lower TTLs at the current provider. Risk: None — not yet authoritative.
Compare staged zone against production record by record. Mail authentication (MX, SPF, DKIM, DMARC) checked explicitly, because this is where migrations break. Risk: This is the step that prevents the outage.
Update nameservers at the registrar, watch propagation, then enable DNSSEC and mitigation once resolution is confirmed clean. Risk: Reversible — old zone stays in place.
Mail is the failure mode. A web record that's wrong is visible in seconds; an SPF record that's wrong is silent for a week and then your invoices are in a spam folder. We verify mail before we touch nameservers.
Mitigation is on before the attack, not configured during it. L3/L4 floods are dropped automatically at the edge.
For application-layer attacks we tighten rate limits, raise challenge posture, and — if warranted — enable Under Attack Mode for the affected hostnames.
You get told what's happening, what we changed, and what the user impact is. In plain language, while it's happening.
Written summary: vector, duration, what was blocked, what rules we're keeping, and what we're recommending you change.
If we run your Managed SOC, this is already in scope. If we don't, it's still covered under managed DNS — the OPERATE tier above.
E-commerce, scheduling, client logins, payment pages.
One zone, one set of records, one place the truth lives — instead of DNS split across three vendors and two former employees.
If you've just been null-routed by your ISP, this is the conversation.
DNS integrity and DDoS mitigation show up on renewal forms now.
Genuinely common. We fix ownership as part of the engagement.
Cloudflare protects what's published through it. A flood aimed at your ISP-assigned IP range still saturates your own pipe. That's what Magic Transit exists for, and it's a separate, larger scope.
If an attacker learns your origin address from an old DNS record, a mail header, or a certificate log, they can bypass the edge entirely. We lock the origin firewall to Cloudflare ranges — but this only works if we're allowed to.
Proxying protects HTTP/HTTPS. SSH, RDP, SMTP, game and VoIP protocols need Spectrum or Magic Transit, on higher tiers.
Rate limiting depth, WAF ruleset control, and certificate options vary by Cloudflare tier. We tell you which tier your requirements need before you buy one.
Recursive resolvers honor cached TTLs. We lower TTLs in advance to shrink it, but we can't eliminate it.
Managed rules block known patterns. Business logic abuse, credential stuffing, and API abuse need tuning and review, not just an enabled toggle.
Mitigation stops attack traffic. It doesn't make an undersized origin fast.
Related: Secure Web Gateway · Managed SOC · Network & Infrastructure
Not if it's done properly. MX, SPF, DKIM, and DMARC records are migrated and verified before nameservers change. Mail records are the most common cause of a bad DNS migration, which is why verification is its own step.
No. Cloudflare becomes your authoritative DNS while your registrar stays where it is. You update two nameserver entries. We can also consolidate registration later if you want to.
There isn't one, when it's staged correctly. The Cloudflare zone is built and verified before it becomes authoritative, and the old zone stays in place as a fallback.
For a small business, far less than you'd think. Attacks well under the headline-grabbing sizes are more than enough to take a single office circuit or an unprotected web server offline.
L3/L4 mitigation is always on. Application-layer response has an escalation path we manage, including Under Attack Mode when the situation warrants it.
No. Your firewall controls traffic at your edge. This protects what you publish to the public internet. Different jobs; you want both.
Yes. Internal resolution stays where it is. This is about your public authoritative zone. For internal hostname routing for remote users, see our Secure Web Gateway page.
It lets resolvers verify that the answer for your domain genuinely came from your zone and wasn't tampered with in transit. It's a signature, not a filter — cheap to enable and increasingly expected on security questionnaires.
The full Cloudflare One platform this sits inside.
Outbound filtering — this page is the inbound half.
Publish internal apps without exposing them to the internet at all.
Humans reviewing what the edge flags.
The circuit, firewall, and multi-WAN failover underneath.
For when the problem is the origin, not the traffic.
Send us your domain and a short note about your environment. We'll run a zone and exposure review, tell you what needs fixing, and be straight with you if what you have is already fine.
Trusted by dozens of businesses