Help4 Net
Delivery modes

Proxy websites. Keep mail and control records direct.

DNS answers tell clients where to connect. Proxy and WAF settings determine whether compatible web traffic passes through Help4 before reaching the origin.

Default rule

Proxy public HTTP/HTTPS website hostnames. Keep MX, DKIM, DMARC, SPF, verification, and non-web protocols DNS-only unless a specific Help4 product supports proxying that protocol.

Mode chooser

Full proxy + WAFBest for public websites and supported APIs that need origin shielding, attack filtering, TLS, and edge delivery.
Proxy with limited cachingUse for dynamic websites where WAF and origin shielding are required but authenticated pages must bypass shared cache.
DNS-onlyUse for MX targets, mail, SSH, verification records, and protocols not explicitly supported by the proxy.
Temporary bypassUse only as a controlled diagnostic state. It can expose the origin and should have an owner, reason, and end time.

Typical choices

Record/hostnameTypical modeReason
Apex website and wwwProxy + WAFPublic web delivery and origin protection.
API over HTTPSProxy + WAF, no-store where privateProtect requests without caching credentials or personalized responses.
MX and mail hostnamesDNS-onlySMTP is not ordinary website traffic.
SPF, DKIM, DMARC, verificationDNS-only recordsThese are DNS policy/ownership data, not proxied destinations.
Admin or origin identityRestricted/direct by designNever expose a private origin name merely to make setup easier.

Cache safety