DNS and platforms
Protection is a hostname you control pointed at the edge. There is no plugin, app, or module inside WordPress, Drupal, Magento, or Shopify.
Two ways to point DNS
A hostname that is not the zone apex uses a CNAME to the CloudFront target we show. The zone apex cannot be a CNAME at most DNS hosts. For the apex, the product uses managed DNS: import mail and verification records, then set our nameservers at the registrar.
If you protect www, the page can suggest an optional redirect from the apex to www at your registrar. That redirect is yours to add. It is not created for you.
Cloudflare CNAMEs must stay DNS-only (grey cloud) so validation and the traffic record resolve to us. The one-click Cloudflare publish does that.
One-click DNS credentials
Account → DNS providers can store a Cloudflare API token or a GoDaddy key and secret. Those are the only two providers with a saved-credential connection. Everyone else uses the records on the site page.
Connected — credentials on file (hidden). Only the account owner can connect, replace, or remove DNS credentials. We never display the current token or secret. Paste a new one to replace it. Remove deletes our copy. You still revoke the token at the provider.
Cloudflare’s expected scope is the Edit zone DNS template (Zone DNS Edit and Zone Read). GoDaddy’s expected scope is a production key that can write DNS on the domains you protect. We publish the CNAME and TXT records we show you.
Providers we recognize from nameservers
If we can see your nameservers, the DNS instructions name the host. Unknown nameservers get the generic record, with no provider name.
- Cloudflare
- GoDaddy
- Namecheap
- Amazon Route 53 (apex uses an alias, or you switch the site to managed DNS)
- Google Domains, Google, or googlehosted nameserver patterns — the detector still uses that label when the nameserver matches
- IONOS
- Bluehost
- DNSimple
- Hover
Recognizing a nameserver only changes the help text. It does not connect an API, except Cloudflare and GoDaddy when you save credentials.
Platforms
You type a domain and an origin. The edge does not install anything on the origin. Platform guides describe how those sites usually behave in count mode (login paths, forms, checkout). They are not a separate product integration.
Shopify-hosted checkout stays on Shopify. A custom storefront, headless front end, or marketing hostname you control can be added like any other site.
Promote Copilot treats some paths as known-good when they show up in samples: LMS-style paths, registration and webform posts, health checks, WordPress admin-ajax, Drupal JSON:API and other CMS paths, SSO, login, payment, API and GraphQL, and admin. xmlrpc.php is not known-good.