Stop the floods a CDN can't cache away. Hide your origin behind our edge. Let real visitors through, drop the bots. Web traffic filtered before it hits you.

EdgeShield sits in front of your origin and sheds request floods, bots and connection storms in real time — the dynamic attacks a cache can't absorb. Real visitors pass hands-free. No CAPTCHAs.

Free plan, no card required — live in under five minutes.

<50mslatency across Europe <1msfilter decision 2 nameserversto go live
// everything in one place

Layer-7 DDoS protection, DNS and edge — one platform

Your own authoritative DNS and nameservers, HTTP/HTTPS DDoS & bot protection, per-record proxy, edge caching, real-time analytics and auto under-attack mode — the whole stack for the dynamic traffic a CDN can't cache away. Point your nameservers once and it's all live.

Sheds the flood at the edge

Hundreds of thousands of requests per second dropped before they complete a handshake. IP-rotating botnets that stay under per-IP limits are caught by their shared TLS stack.

1.5M rpspeak shed, per node
JA4TLS fingerprinting

No CAPTCHAs, ever

Real visitors verify hands-free in the background. Under attack, one silent check — then they're remembered and pass.

Auto under-attack mode

Detects a spike and tightens itself, then relaxes when it clears. No pager, no manual toggle.

Repeat offenders, banned & reported

An IP that keeps reoffending after each block escalates to a 7-day ban, and gets reported to AbuseIPDB automatically.

Real-time analytics on every plan

A live request feed, top talkers, per-domain traffic and country breakdowns from real proxied hits — not gated behind a paid tier.

Your own DNS & nameservers

EdgeShield is your authoritative DNS — you get a dedicated pair of nameservers, manage every record in the dashboard, and flip proxy protection on per record. Traffic is answered from the nearest edge (GeoDNS), so DNS itself is fast and DDoS-resistant.

// why edgeshield

A cache can't protect what it can't cache

Static files hide behind any CDN. But logins, APIs, checkouts and game servers must reach your origin on every request — and that's exactly where the flood lands.

The gapCache-only protection
  • Dynamic requests can't be cached, so they pass straight to your origin
  • L7 floods that look like real traffic slip through untouched
  • Bots rotate IPs to stay under per-address limits
  • Under attack, real users get thrown a CAPTCHA
EdgeShieldOrigin-side mitigation
  • Inspects and sheds every request before it reaches your origin
  • Catches distributed floods by their shared JA4 TLS fingerprint
  • Auto "under attack" mode that tightens and relaxes on its own
  • Real visitors verified hands-free — never a CAPTCHA
// setup

Live in three steps

No code changes, no origin re-architecting. Your DNS moves to EdgeShield and everything else stays put.

01

Add your domain

We scan your existing DNS and import it, so nothing breaks when you switch. SSL is issued and renewed for you.

domain → your-app.example
02

Point your nameservers

Set the two nameservers we give you at your registrar. That's the only change — no per-record edits.

NS lily.ns.edgeshield.one · max.ns.edgeshield.one
03

Flip on protection

Toggle the proxy on any record from the dashboard — your origin IP goes dark and traffic filters through the edge.

status proxied · shedding
// pricing

Plans that scale with your domains

Every plan runs the same edge and the same protection. Pay for the domains you cover.

Starter
$20/mo
  • 3 domains
  • 10 whitelisted IPs / domain
  • Real-time analytics
Choose Starter
Most popular
Pro
$50/mo
  • 10 domains
  • 25 whitelisted IPs / domain
  • Everything in Starter
Choose Pro
Business
$100/mo
  • 30 domains
  • 100 whitelisted IPs / domain
  • Everything in Pro
Choose Business
// faq

Questions, answered

Isn't a CDN enough?

A CDN protects what it can cache — static files. Anything dynamic (logins, APIs, checkouts, game servers) reaches your origin on every request, and that's where L7 floods hit. EdgeShield inspects and sheds those requests at the edge before they land, so the dynamic traffic a cache can't touch is still covered.

What attacks does it actually stop?

Layer-7 request floods, IP-rotating botnets, connection storms, credential-stuffing and scraping bots — the dynamic traffic a CDN can't cache away. Attacks are shed at the edge before they reach your origin.

Do I need to switch DNS providers?

EdgeShield becomes your DNS. You point your domain's nameservers at us once — we automatically import your existing records first, so mail and everything else keeps working. From then on you manage DNS (and flip protection on per record) right in the dashboard.

Will it slow down or annoy real visitors?

No. Verification happens automatically in the background with no puzzle to solve, and filtering decisions are made in well under a millisecond.

Who builds EdgeShield, and where does traffic get scrubbed?

EdgeShield is built and operated from Germany. The filtering itself runs on our own edge, so traffic is scrubbed at the location nearest to it rather than hauled back to one country.

Protection your users never notice.

Point your nameservers at EdgeShield and watch the floods stop reaching your origin.

Get started