Web Application Firewall

Two-stage DDoS protection

DNSZone.io's WAF uses a two-stage mitigation system — automated sensor-based blocking followed by human challenge verification — to keep your site online during attacks.

Mitigation stages

Our WAF activates automatically when an attack is detected. The two stages work together to filter out malicious traffic while keeping legitimate users online.

01
Stage 1

Sensor Mitigation

The first stage activates the moment our traffic sensor detects an anomaly. DNSZone.io monitors incoming requests in real time. When traffic from a single IP or a group of IPs exceeds normal thresholds, the system automatically engages.

Our firewall reads access logs every second during an attack. The top offending IPs are identified and blocked via dynamically updated firewall rules. IPs that sustain blocked traffic for more than 30 seconds are issued a temporary network-level ban lasting 5 minutes, enforced before your website even sees the traffic.

Sensor mitigation is fully automatic. No manual action is required. Your origin server never sees the flood traffic — it's stopped at the edge.

Real-time IP blocking
Firewall rules update every second based on live log analysis. Top offenders are blocked within moments of the attack starting.
Automatic
Streak-based temp bans
IPs sending blocked requests for 30+ consecutive seconds are automatically banned at network level for 5 minutes, the lowest-latency block possible.
Automatic
Origin protection
Your server's real IP is hidden behind DNSZone.io's reverse proxy. Attackers cannot bypass the WAF to hit your origin directly.
Always on
Discord alerts
You receive an alert when an attack starts and another when it clears — including domain, attack type, peak RPS, and total blocked count.
Automatic
02
Stage 2

Human Challenge

When sensor mitigation isn't enough — for example during sophisticated distributed attacks using many IPs or legitimate-looking bot traffic — you can enable the Human Challenge from your dashboard. It can also be used proactively as a permanent layer of protection on high-risk domains.

The Human Challenge serves a lightweight JavaScript proof-of-work to every visitor before forwarding them to your site. Legitimate browsers complete this in milliseconds and are transparently redirected. Bots that lack JavaScript execution, have the wrong headers, or fail the proof-of-work are blocked at the edge and never reach your server.

A session cookie is issued to verified visitors so they don't see the challenge again for the duration of their session. The challenge page inherits your site's domain and does not redirect to a third-party service.

JavaScript proof-of-work
Visitors must execute a small computation in the browser. Real browsers handle this in under a second. Bots typically can't execute JavaScript at all.
On demand
Transparent for real users
Legitimate visitors see a brief loading screen and are forwarded automatically. No CAPTCHA to solve, no interaction required.
Seamless
Session persistence
Verified visitors receive a signed cookie. They pass the challenge once per session — no repeated friction during normal browsing.
Smart
Per-domain control
Enable or disable the Human Challenge per domain at any time from the WAF tab in your dashboard. Takes effect immediately.
Flexible

Request lifecycle

Every request passes through multiple layers before reaching your origin server.

Visitor
Request arrives from the internet
IP Check
Banned IPs dropped at network level
WAF Rules
Firewall rules checked (IP, country, UA)
Challenge
Human Challenge (if enabled)
Origin
Clean traffic reaches your server

Custom rule types

Beyond automatic mitigation, you can set up custom rules to control exactly who can reach your domain.

IP & CIDR blocks
Block or allow individual IPs or entire subnets. Useful for blocking known bad actors or whitelisting trusted ranges like your office network.
Country rules
Block traffic from specific countries entirely. DNSZone.io resolves the visitor's country from their IP and applies the rule before the request hits nginx.
User-Agent rules
Block requests by User-Agent string. Effective against known bot fingerprints, scrapers, and vulnerability scanners that identify themselves.
URL path rules
Block access to specific paths like admin panels, sensitive endpoints, or attack-targeted routes without touching your application code.

Add your domain in under 2 minutes

DNSZone.io's WAF is included on every plan. No credit card required to get started.