hello@wpfoss.com

Make your DNS impossible to hijack.

We move your domains onto Cloudflare with zero downtime, switch on DNSSEC in the order that keeps you online, and tune your firewall to your real traffic instead of a default template. Your visitors reach you, and only you.

What is wrong now

Moving a domain to Cloudflare is easy, which is exactly why most domains sit there half configured. The parts that need judgement, and that break things if done in the wrong order, are the parts that get skipped.

  • DNSSEC is switched off, so your DNS answers are unsigned and can be forged in transit.
  • DNSSEC was enabled at Cloudflare before the registrar published the DS record, or the reverse, and the domain went dark.
  • No CAA record, so any certificate authority in the world can issue for your domain.
  • The firewall runs a default ruleset never checked against your traffic, so it blocks nothing useful and occasionally blocks customers.
  • No rate limiting on login or contact endpoints, which are the first things bots hammer.
  • Multiple Cloudflare accounts hold different domains, so nobody can say what is configured where.

What you get

  • Migration onto Cloudflare with no downtime and no lost records.
  • DNSSEC enabled in the correct sequence, registry side confirmed before the Cloudflare side is switched on.
  • CAA records restricting certificate issuance to the authorities you actually use.
  • Firewall rules, rate limiting and bot controls tuned to your real traffic, run in log-only mode first.
  • Scattered domains consolidated into one account, so the estate is auditable.
  • Written handover documentation. You are never locked to us.

How the engagement runs

  1. 1

    Map the estate

    Every domain, registrar, DNS zone and account, which usually corrects a few assumptions about who controls what.

  2. 2

    Migrate without downtime

    Records replicated and verified before nameservers change, with TTLs lowered ahead of cutover for a fast rollback.

  3. 3

    Enable DNSSEC, registry first

    The DS record is published and confirmed before anything is switched on at Cloudflare. Doing it the other way is how domains go offline.

  4. 4

    Lock down issuance and traffic

    CAA to control certificate authorities, plus firewall and rate-limit rules tuned to your traffic and monitored before they are enforced.

  5. 5

    Document and hand over

    A written record of every setting and why it is set, so a future administrator does not undo it by accident.

What changes afterwards

Your DNS answers are signed and can be validated, so they cannot be silently forged. Only the certificate authorities you nominated can issue for you. Your firewall blocks traffic that matters and lets your customers through. And you have one account, one inventory, and documentation that says what was done and why.

The free domain security checker tells you in about twenty seconds whether DNSSEC is on and whether you have a CAA record. Both are free to fix and both are missing on most domains we look at.

For the background, what DNSSEC is and why it matters explains the signing chain in plain English, and the CAA record explained covers the one-line record that stops any certificate authority on earth issuing for you.

Frequently asked questions

Why is the DNSSEC order such a big deal?

Because getting it wrong takes your whole domain offline, website and email, and the failure is not obvious. The registry DS record must be published and confirmed first, then the DNS side.

Do we need a paid Cloudflare plan?

Often not. DNSSEC, CAA and the basic firewall are free. We tell you honestly when the free tier is enough. We earn nothing from your Cloudflare bill.

Will the firewall block our own customers?

Not if it is tuned. New rules run in log-only mode first so we can see what they would have blocked before enforcing them.

Our promise, on every engagement

  • Fixed scope, fixed fee, agreed before we start.
  • Every change staged, so your site and email never go offline.
  • Full documentation handed over. No lock-in, ever.
  • If your free check comes back clean, we will tell you, and we will not invent work.

Find out where you stand first.

Run the free check against your own domain, or one whose answer you already know. Then, if you want it fixed properly, we scope the work and quote a fixed fee.