1 October 2026Improvements since our 27 September 2026 update.
Faster Websites
- Pages served through Shieldify now load noticeably faster: Shieldify keeps its connections to your server open and reuses them instead of opening a new connection for every request.
- Pages, stylesheets and scripts are now compressed on the way to your visitors, so they download faster.
- Your server now receives far fewer new connections from Shieldify, which lowers its load during busy periods.
- If your server cannot be reached, visitors now see an error page after 15 seconds instead of waiting up to a minute.
Smoother Visitor Verification
- Fixed an issue where a form submitted after a few minutes on a website (for example sign-in, registration, checkout or comments) could be lost, requiring visitors to submit it again.
- Many visitors and browsers sharing one network, such as an office, school or mobile carrier, can now complete verification at the same time.
- Visitors who open many pages quickly are no longer mistakenly blocked for a short time.
- The CAPTCHA now recovers from brief connection problems and returns visitors to the exact page they were on.
- Forms sent to the HTTP address of a website with Force SSL now keep their content when redirected to HTTPS.
- Visitors who reach a website while its setup is still completing can now pass verification instead of seeing the check repeatedly.
Search Engines
- Major search engine crawlers such as Googlebot and Bingbot are now recognized reliably and are not asked to verify, protecting your search visibility. Bots that only pretend to be search engines are still checked.
- The list of official search engine addresses is now refreshed automatically every week.
Stronger Protection During Attacks
- Improved the stability and speed of protection during very large attacks.
- Attacks from very large numbers of addresses are now blocked more completely.
- A single attacker can no longer use up verification capacity and keep real visitors from verifying.
- SSL certificates can now be issued and renewed even while a website is under attack.
- Strengthened network-level DDoS protection in front of Shieldify.
- Added automatic monitoring of the services behind visitor verification, so problems are detected and resolved faster.
Private Pages
- Private page rules now match addresses more reliably, including variations in letter case and trailing slashes.
- Improved the security of the private page access request page shown on your website.
Account and Panel Security
- You can now sign in with a passkey, such as Face ID, Touch ID, Windows Hello or a security key. Add one from your Profile; password sign-in remains available.
- Two-factor authentication codes can now be used only once.
- Limited how many verification emails can be sent to an account, protecting inboxes from email flooding.
- The panel can no longer be embedded in other websites, protecting against click-tricking attacks.
- Website server addresses are now validated more strictly.
Safer Website Settings
- A settings change that cannot be applied is now rolled back automatically, without affecting your other settings or websites.
- Protection settings such as rate limits now have clear allowed ranges.
- Deleting a website now also removes its SSL certificate.
- Panel tools such as log search, DNS checks, cache purge and notification tests now have fair-use limits, keeping the panel fast for everyone.
Payments
- Prices and checkout load more reliably, with a retry option when a connection is slow.
Refreshed Look
- New Shieldify logo and color palette across the website, the panel and the verification pages shown to your visitors.
More Secure HTTPS
- HTTPS connections now follow current security recommendations, and outdated encryption methods are no longer accepted. Very old browsers and devices without modern encryption support may no longer be able to connect.