OCTOBER UPDATE: FASTER WEBSITES, SMOOTHER VERIFICATION AND PASSKEY SIGN-IN.Read the update Sign in

Layer 7 DDoS Protection That Switches Itself On.

Shieldify sits in front of your website, learns what normal traffic looks like and blocks HTTP floods at the edge within seconds. Your server keeps serving real visitors while the attack is absorbed.

1 DNS changeto put a website behind Shieldify. No agent, no code change.
Automaticdetection and mitigation for every website, around the clock.
Email + Discordalerts when an attack starts and when it ends.
€19.90per website per month, with every protection included.
What it stops

Application-layer floods that look like real traffic

A Layer 7 DDoS attack does not try to fill your network link. It sends ordinary-looking HTTP requests, often from thousands of addresses at once, to the pages that cost your server the most: search, checkout, login, product filters and API endpoints. Each request is cheap for the attacker and expensive for your application, so a few thousand requests per second can take down a website that a network-level filter would see as normal traffic.

Shieldify is built for exactly this layer. It sees every request before your server does and decides, per request, whether it goes through.

  • HTTP GET and POST floods, single-source or spread across large botnets and proxy networks.
  • Floods that imitate browsers with real user agents, cookies and headers.
  • Targeted floods against expensive paths such as /search, /checkout or /wp-login.php.
  • Cache-busting requests with random query strings that try to force every hit through to your server.
How detection works

It learns each website on its own

There is no global threshold that has to fit every website. With automatic learning on, Shieldify learns the normal request pressure of each website separately: a busy shop and a small blog get different baselines. New websites start with conservative limits, and the baseline adapts as trustworthy history builds up.

When the current pressure moves well beyond what the website normally sees, Shieldify switches the website into mitigation by itself. Nobody has to notice the attack, log in or press a button. When traffic returns to normal for long enough, mitigation steps back on its own.

Prefer to set the limit yourself? Turn automatic learning off and enter a mitigation threshold in requests per second. During a known campaign you can also keep mitigation on permanently until you switch it off.

Layers of defense

Several gates, each cheaper than the next request

Every request passes the same gates at the edge. The earlier a flood is stopped, the less it costs, so the cheapest checks come first.

Per-client rate limits

A single address can only send so many requests per second. Sources above the limit are throttled before anything else runs.

Network-edge quarantine

Addresses that keep flooding are dropped in the kernel firewall for a short period, so they stop consuming web server resources at all.

Browser verification

During mitigation, new visitors pass a quick, invisible browser check. Real browsers continue; scripts and most headless tools do not.

Private CAPTCHA

Traffic that still looks suspicious gets a self-hosted, privacy-friendly CAPTCHA instead of a hard block. No third-party captcha vendor is involved.

Firewall rules

The web application firewall blocks exploit attempts that often ride along with a flood.

Verified crawlers pass

Googlebot, Bingbot and Applebot are checked against their published address ranges and let through, so an attack does not cost you search visibility.

During an attack

What happens, minute by minute

  1. Pressure rises. Shieldify sees request pressure on the website move far beyond its learned baseline.
  2. Mitigation switches on. The website enters mitigation and you get an "attack wave started" alert by email and Discord.
  3. Visitors are sorted. Visitors who are already verified keep browsing. New sessions pass the browser check; suspicious ones meet the CAPTCHA.
  4. Repeat sources are cut off. Addresses that keep flooding are rate-limited and then quarantined at the network edge.
  5. The attack ends. Once traffic is back to normal, mitigation steps back and you get an "attack wave ended" alert with the duration, peak blocking rate and total blocked requests.
What you see

Every attack, on a timeline

The panel shows each attack as an attack wave: when it started and ended, what triggered mitigation, the peak blocking rate and how many requests were stopped. The traffic dashboard shows allowed and mitigated requests live and over the last 24 hours, 7, 30, 90 or 180 days, and the security events list shows individual blocked requests with the reason.

Setup

Protected in a few minutes

  1. Add your website in the panel and enter the address of your server.
  2. Point your DNS to Shieldify with one record. A free certificate is issued automatically.
  3. Lock down your server so it only accepts traffic from Shieldify. Attackers who know your server's own address could otherwise go around the protection.

The setup guide walks through each step, including real visitor IPs and API endpoints.

FAQ

Questions, Answered.

Something else on your mind? Write to contact@shieldify.ee and a person will answer.

Do I need to change my server or code?

No. Shieldify works as a reverse proxy in front of any host and any stack. You add the website in the panel and point one DNS record to Shieldify.

Will real visitors see a CAPTCHA during an attack?

Most will not. Real browsers pass the invisible browser check once and keep browsing. The CAPTCHA is only shown to traffic that still looks suspicious after that check.

Does Shieldify stop network-layer (L3/L4) floods?

Shieldify itself works at the application layer. Its edge sits behind upstream network-level DDoS filtering, so volumetric floods aimed at the protected address are filtered before they reach it. Your own server's address should not be public, which the setup guide explains.

What about APIs, webhooks and mobile apps?

Machine clients cannot run a browser check. Add their paths, such as payment callbacks or health checks, or their fixed addresses as trusted rules under Access rules, and keep those rules narrow.

What if attackers find my server's IP address?

Then they can bypass any proxy. Allow only Shieldify to reach your web ports in your server firewall or hosting panel, and if your old address was public, consider moving to a new one after switching.

How much does it cost?

€19.90 per website per month, tax included, with every protection in the plan. You can start with a 1-day trial. See pricing.

Stay OnlineWhen It Matters Most.

Put your website behind Shieldify in minutes and let mitigation run on its own.