Concierge DNS: We Point Your Site at the Managed WAF
Campus web and agency operators often want a managed WAF but will not touch DNS. The zone sits with central IT, a registrar, or an agency NOC. Change tickets take a week. Apex records scare people. Nobody wants a cutover that breaks SSO on Monday morning. Concierge DNS WAF setup is the path for that reality: ProtectMyWebsite coordinates with whoever holds the zone, points the public hostname at the edge, and handles SSL — typically about one business day once the hostname list and access path are clear. Hosting and CMS stay put. Rules still start in count. You still promote after evidence.
Who concierge DNS is for
Concierge is not a different product — same ProtectMyWebsite edge, different who-flips-the-record story:
Central IT owns DNS — web/comms owns the CMS; the zone is locked behind change control.
Registrar or vendor holds the zone — the person who can edit www is not on your Slack.
Apex / root is the hard part — example.edu or agency.gov cannot take a casual CNAME paste. A CNAME cannot sit on the zone apex.
Multiple public names — www, apex, and microsites that must share the shield on day one.
If you already control the zone, self-serve is usually faster. Concierge exists when “one DNS change” is organizational. Companion setup calendar: /guides/managed-waf-setup. See higher education and government.
What "we do DNS" actually means
Managed WAF we do DNS means ProtectMyWebsite works the cutover with the zone owner — not that we take over your registrar forever.
1. You inventory public hostnames that must sit behind the shield (www, apex, named microsites).
2. We confirm the cutover shape — typically a CNAME for www and other subdomains (you keep the current DNS host). Apex is different: a CNAME cannot sit on the root. Options are protect www and redirect the apex at the registrar, a provider alias/ANAME if the zone already supports it, or a nameserver delegate so we can alias the apex.
3. We coordinate the change with whoever can edit the zone (ticket, call, shared checklist).
4. SSL is issued or terminated at the edge. Visitors keep the same URL; no CMS certificate work.
5. Traffic hits the edge in count. Matches log; they do not deny yet.
Origin stays put. Concierge is the handoff, not a hosting migration. Lock origin IPs off the open internet after cutover.
| Cutover shape | Typical use | Operator note |
|---|---|---|
| CNAME (www / subdomains) | Cleanest path for most properties | One record per hostname → ProtectMyWebsite edge. You keep your current DNS provider. |
| Apex / root | example.edu, agency.gov | CNAME cannot sit on the apex. Use www + registrar redirect, a provider alias/ANAME if they have it, or nameserver delegate so we can alias the root. |
| Nameserver delegate | Central DNS policy prefers zone-level handoff, or you want the apex on the shield | Discuss with campus/agency DNS owners. Import MX/TXT first so mail survives. Traffic still lands on the edge. |
Timeline: concierge cutover → count → promote
Separate DNS live from rules in block. Concierge shortens the organizational wait; it does not skip the observe window.
Go live can mean “DNS flipped and SSL green” on the concierge day. Hardened means you promoted junk after the first ~24-hour count window. “One business day” is typical once hostnames and zone access are clear — your tickets and registrar delays still set the clock. That is not a guaranteed clock-hour SLA.
| Window | What happens | What “done” means |
|---|---|---|
| Prep | Hostname list, zone owner contact, cutover shape | Ready to schedule |
| Cutover day | Concierge coordinates DNS; SSL green at the edge | Typically ~one business day once access and hostnames are clear — not a clock-hour SLA |
| Day 0–~24 hours — count | Managed rules for injection, XSS-class noise, known exploit patterns, bad bots, malicious IPs, plus useful rate limits — all start in count | Observing; no day-one deny theater |
| After ~24 hours — promote | Dashboard shows what’s safe. Promote Copilot recommends Promote, Hold, or Needs allowlist | You still click once. Copilot explains; it does not auto-block |
| Ongoing | New noise lands in count until you promote | Observe → explain → human promote |
SSL, forms, and what does not change
Same URLs — bookmarks and users do not change.
SSL at the edge — valid cert on the public name; no CMS re-key.
Forms and callbacks keep working in count — nested bodies, Webforms, FOIA uploads, LMS/IdP redirects.
No in-app plugin/module as the edge — DNS + proxy, not another CMS security pack.
Concierge removes the “who edits the zone” friction. It does not flip deny-on-day-one packs.
Self-serve vs concierge vs Talk to sales
Self-serve DNS is faster when you control the zone and can edit today: sign up, add a site, change DNS, start count. Card at Stripe for the 14-day trial; then $150/site/month — see pricing.
Concierge DNS is for when the zone is owned by central IT, a registrar, or an agency NOC. We coordinate cutover; typically ~one business day once the hostname list and access are clear.
Talk to sales (Campus Estate) is the multi-site story — many departmental properties, uneven ownership. Talk to sales team; no Estate dollar amounts here. Promote Copilot is included on self-serve and estate paths.
Start with a free passive scan before anyone touches DNS. Create the trial at signup when ready to schedule cutover.
| Path | Best when | What you do |
|---|---|---|
| Self-serve DNS | You control the zone and can edit today | Sign up, add site, change DNS, start count. Card at Stripe for the 14-day trial; then $150/site/month |
| Concierge DNS | Zone owned by central IT / registrar / agency NOC | We coordinate cutover; typically ~one business day once hostname list and access are clear |
| Talk to sales (Campus Estate) | Many departmental properties, uneven ownership | Multi-site story. Talk to sales team — no Estate dollar amounts here. Copilot included on both paths |
Concierge go-live checklist
1. List public hostnames that must share the shield (www, apex, named microsites).
2. Name the zone owner — central IT, registrar, or agency NOC.
3. Choose cutover shape — CNAME for www/subdomains; apex via www redirect, provider alias, or nameserver-delegate where policy requires it.
4. Confirm origin reachability and lock down public origin exposure after cutover.
5. Run concierge cutover → SSL green. Site is live in count.
6. Let ~24 hours of real traffic accumulate, then open the dashboard. Promote Copilot surfaces Promote / Hold / Needs allowlist. You still click once. It does not auto-block.
7. Next property — or Talk to sales team for a multi-site estate.
FAQ
What is concierge DNS WAF setup? Concierge DNS means ProtectMyWebsite coordinates pointing your public hostname at the managed edge when your team will not (or cannot) edit the zone. SSL is handled at the edge. Rules start in count; after ~24 hours you promote — Copilot explains, it does not auto-block. Typical turnaround is about one business day once hostnames and zone access are clear.
Do you support apex domain WAF cutover help? Yes. Subdomains usually use a CNAME to the edge. A CNAME cannot sit on the apex/root — we use a www CNAME plus registrar redirect, your provider’s alias-style record if they have one, or a nameserver-delegate path when policy prefers it. Hosting and CMS stay put. Same count → promote story. Setup calendar: /guides/managed-waf-setup.
How long does campus IT DNS help take? Typically ~one business day once the hostname list and zone editor are clear — not a hard clock-hour SLA. Registrar queues on your side still matter. Traffic then runs in count; promote follows evidence after ~24 hours.
Is SSL included when you do DNS? Yes. SSL is issued or terminated at the ProtectMyWebsite edge. Visitors keep the same URL — no CMS certificate re-key as part of go-live.
When should we Talk to sales instead of concierge for one site? When you have many properties, mixed DNS ownership, or need a campus/agency estate roll-out. Start with /solutions/multi-site-managed-waf. Self-serve remains $150/site/month with a 14-day trial — /pricing and /signup. Copilot included on both paths; no Estate dollar amounts here.
Start here
ProtectMyWebsite concierge DNS is we point your site at the managed WAF → count → promote — zone owners stay in their process, SSL is handled, ~24 hours to see what’s safe, you still click once, no auto-block theater.
Related
- All guides
- Managed WAF setup: DNS cutover to count mode
- What is WAF count mode? (and why you start there)
- What's safe to block on a WAF?
- DIY WAF vs managed: console burden or operator?
- Hide your origin IP behind a WAF (and allowlist edge IPs only)
- Managed WAF for multi-site teams
- Managed WAF for university and college websites
- Managed WAF for government and public-sector websites
- Pricing
- Free security scan
- Start a 14-day trial