EdgeShield sits in front of your origin and sheds request floods, bots and connection storms in real time — the dynamic attacks a cache can't absorb. Real visitors pass hands-free. No CAPTCHAs.
Free plan, no card required — live in under five minutes.
Your own authoritative DNS and nameservers, HTTP/HTTPS DDoS & bot protection, per-record proxy, edge caching, real-time analytics and auto under-attack mode — the whole stack for the dynamic traffic a CDN can't cache away. Point your nameservers once and it's all live.
Hundreds of thousands of requests per second dropped before they complete a handshake. IP-rotating botnets that stay under per-IP limits are caught by their shared TLS stack.
Real visitors verify hands-free in the background. Under attack, one silent check — then they're remembered and pass.
Detects a spike and tightens itself, then relaxes when it clears. No pager, no manual toggle.
An IP that keeps reoffending after each block escalates to a 7-day ban, and gets reported to AbuseIPDB automatically.
A live request feed, top talkers, per-domain traffic and country breakdowns from real proxied hits — not gated behind a paid tier.
EdgeShield is your authoritative DNS — you get a dedicated pair of nameservers, manage every record in the dashboard, and flip proxy protection on per record. Traffic is answered from the nearest edge (GeoDNS), so DNS itself is fast and DDoS-resistant.
Static files hide behind any CDN. But logins, APIs, checkouts and game servers must reach your origin on every request — and that's exactly where the flood lands.
No code changes, no origin re-architecting. Your DNS moves to EdgeShield and everything else stays put.
We scan your existing DNS and import it, so nothing breaks when you switch. SSL is issued and renewed for you.
Set the two nameservers we give you at your registrar. That's the only change — no per-record edits.
Toggle the proxy on any record from the dashboard — your origin IP goes dark and traffic filters through the edge.
Every plan runs the same edge and the same protection. Pay for the domains you cover.
A CDN protects what it can cache — static files. Anything dynamic (logins, APIs, checkouts, game servers) reaches your origin on every request, and that's where L7 floods hit. EdgeShield inspects and sheds those requests at the edge before they land, so the dynamic traffic a cache can't touch is still covered.
Layer-7 request floods, IP-rotating botnets, connection storms, credential-stuffing and scraping bots — the dynamic traffic a CDN can't cache away. Attacks are shed at the edge before they reach your origin.
EdgeShield becomes your DNS. You point your domain's nameservers at us once — we automatically import your existing records first, so mail and everything else keeps working. From then on you manage DNS (and flip protection on per record) right in the dashboard.
No. Verification happens automatically in the background with no puzzle to solve, and filtering decisions are made in well under a millisecond.
EdgeShield is built and operated from Germany. The filtering itself runs on our own edge, so traffic is scrubbed at the location nearest to it rather than hauled back to one country.
Point your nameservers at EdgeShield and watch the floods stop reaching your origin.
Get started