not quite accurate
"Cloud security providers alter the DNS settings of a domain name to reroute distributed denial of service attack traffic through their infrastructure"
At least for the Incapsula service you have to make your own DNS changes. And as you can guess, this means all traffic for those DNS names passes through their infrastructure.
One way to find out who Incapsula's clients are is to examine the certificate you get. All of their clients' domains are listed in the subjectAltName field.