Security edge and WAF

Imperva

Imperva, Inc. · Security edge and WAF. How DNSTrace.dev identifies it from public evidence.

Updated Sep 2026

What Imperva is

Imperva, previously sold as Incapsula, is a security-first reverse proxy offering DDoS mitigation, bot management and a web application firewall alongside caching. Traffic is redirected to Imperva by pointing the hostname at its network, which then filters and forwards to the origin.

How DNSTrace.dev detects it

Detection correlates independent public signals. A single match is reported as strong evidence; agreement between a response header and the announcing network is reported as confirmed.

  • x-iinfo — The Imperva request information header. DNSTrace.dev treats this as both a delivery and a firewall signal.
  • incap_ses and visid_incap cookies — Session and visitor cookies set by the Imperva edge.
  • CNAME targets under incapdns.net — The standard Imperva mapping.

What a detection proves

Requests are being filtered by an Imperva proxy before reaching the origin.

What it does not prove

The origin address, which the proxy exists to conceal. It also does not indicate which rules are enabled or whether the request was challenged.

Common questions

Is Incapsula the same as Imperva?

Yes. Incapsula was the earlier product name, and the incapdns.net and incap_ses identifiers remain in use.

Compare with

Website firewall and CDNSucuri

Sucuri, a GoDaddy brand

CDN, reverse proxy and WAFCloudflare

Cloudflare, Inc.

CDN and edge platformAkamai

Akamai Technologies, Inc.

CDNAmazon CloudFront

Amazon Web Services, Inc.

Check a domain

Run a full lookup to see the delivery layer, the detected application stack, live TLS and the announcing network side by side.

Run a lookup →Platforms →Evidence model →