Application-layer floods that look like real traffic
A Layer 7 DDoS attack does not try to fill your network link. It sends ordinary-looking HTTP requests, often from thousands of addresses at once, to the pages that cost your server the most: search, checkout, login, product filters and API endpoints. Each request is cheap for the attacker and expensive for your application, so a few thousand requests per second can take down a website that a network-level filter would see as normal traffic.
Shieldify is built for exactly this layer. It sees every request before your server does and decides, per request, whether it goes through.
- HTTP GET and POST floods, single-source or spread across large botnets and proxy networks.
- Floods that imitate browsers with real user agents, cookies and headers.
- Targeted floods against expensive paths such as
/search,/checkoutor/wp-login.php. - Cache-busting requests with random query strings that try to force every hit through to your server.
It learns each website on its own
There is no global threshold that has to fit every website. With automatic learning on, Shieldify learns the normal request pressure of each website separately: a busy shop and a small blog get different baselines. New websites start with conservative limits, and the baseline adapts as trustworthy history builds up.
When the current pressure moves well beyond what the website normally sees, Shieldify switches the website into mitigation by itself. Nobody has to notice the attack, log in or press a button. When traffic returns to normal for long enough, mitigation steps back on its own.
Prefer to set the limit yourself? Turn automatic learning off and enter a mitigation threshold in requests per second. During a known campaign you can also keep mitigation on permanently until you switch it off.
Several gates, each cheaper than the next request
Every request passes the same gates at the edge. The earlier a flood is stopped, the less it costs, so the cheapest checks come first.
Per-client rate limits
A single address can only send so many requests per second. Sources above the limit are throttled before anything else runs.
Network-edge quarantine
Addresses that keep flooding are dropped in the kernel firewall for a short period, so they stop consuming web server resources at all.
Browser verification
During mitigation, new visitors pass a quick, invisible browser check. Real browsers continue; scripts and most headless tools do not.
Private CAPTCHA
Traffic that still looks suspicious gets a self-hosted, privacy-friendly CAPTCHA instead of a hard block. No third-party captcha vendor is involved.
Firewall rules
The web application firewall blocks exploit attempts that often ride along with a flood.
Verified crawlers pass
Googlebot, Bingbot and Applebot are checked against their published address ranges and let through, so an attack does not cost you search visibility.
What happens, minute by minute
- Pressure rises. Shieldify sees request pressure on the website move far beyond its learned baseline.
- Mitigation switches on. The website enters mitigation and you get an "attack wave started" alert by email and Discord.
- Visitors are sorted. Visitors who are already verified keep browsing. New sessions pass the browser check; suspicious ones meet the CAPTCHA.
- Repeat sources are cut off. Addresses that keep flooding are rate-limited and then quarantined at the network edge.
- The attack ends. Once traffic is back to normal, mitigation steps back and you get an "attack wave ended" alert with the duration, peak blocking rate and total blocked requests.
Every attack, on a timeline
The panel shows each attack as an attack wave: when it started and ended, what triggered mitigation, the peak blocking rate and how many requests were stopped. The traffic dashboard shows allowed and mitigated requests live and over the last 24 hours, 7, 30, 90 or 180 days, and the security events list shows individual blocked requests with the reason.
Protected in a few minutes
- Add your website in the panel and enter the address of your server.
- Point your DNS to Shieldify with one record. A free certificate is issued automatically.
- Lock down your server so it only accepts traffic from Shieldify. Attackers who know your server's own address could otherwise go around the protection.
The setup guide walks through each step, including real visitor IPs and API endpoints.