ddos protection for websites
Neogate takes your site’s traffic, filters out bots and floods, and lets only real visitors through to your server. You connect through DNS in a few minutes, with no changes to your code.
- from $15 a month
- 3 days free
- HTTP and HTTPS
- servers in Germany
from our edge since September 5, 2026, 8 customer domains, updated every 10 minutes
what it looks like
A real attack on a site behind Neogate. In three minutes 1,099,242 requests hit the edge and 1,437 reached the server, that is 0.13%. Switch to “unprotected” to see what the server would have got. The dashboard has the same chart and a report for every attack.
how traffic is filtered
The same attack: of 1,099,242 requests, 1,437 reached the server. This is where the rest stopped.
- volumetric attacks are absorbed by the upstream carrier before they reach our servers
- packets from flooding addresses are dropped in the network card driver, before the system’s network stack
- hundreds of addresses sharing one TLS fingerprint are cut off by the fingerprint at once, not address by address
- a bot that holds one HTTP/2 connection and pushes thousands of requests through it loses the whole connection
- dropped bots get no answer: the connection just goes silent, and the flood tool waits instead of sending its next request
- attack mode switches on for the site under attack only, its neighbours don’t notice
- the browser check is a small puzzle a browser solves in a fraction of a second, no captcha
- during an attack a page’s background requests are only accepted from a browser that has passed the check
- returning visitors and the Google, Yandex and Bing crawlers go through without a check
- gets only traffic that passed, with the visitor’s real IP in X-Real-IP and X-Forwarded-For
- if it starts answering with errors, attack mode switches on by itself, even without a visible flood
- if it stops responding, you get a notification
what a visitor sees
During an attack this page shows up in front of the site for a moment. The browser solves a small puzzle and opens the site by itself. The text only appears after 0.8 seconds, so a visitor usually just sees a slightly longer load.
- no captcha, no clicks: the browser does it all
- the puzzle is unique to each address and browser, so a solution can’t be handed out to a botnet
- the edge checks the answer with one hash, which costs it nothing
- on the right, this check just ran in your browser, for real
also included
We count more than requests. An address that keeps getting errors, walks through pages that don’t exist or sends huge request bodies is cut off before it hits the limit.
We issue and renew the certificate for your domain. HTTPS works from the first minute.
Peak load, sources, response codes and what was filtered out. A report can be shared with a link.
A message when an attack starts and ends, and when your server stops responding.
who it’s for
Visitors get the invisible check only during an attack; the rest of the time the site works as usual. Google, Yandex and Bing crawlers are let through by their addresses, so search rankings don’t suffer.
- an invisible browser check, only while an attack is on
- search crawlers go through without a check
- a WAF on the OWASP rules: SQL injection, XSS and the rest
- optional: a per-address limit and scanner filtering
how to connect
Enter the domain, your server’s address and the mode: website, API or service. The dashboard shows the DNS target and our addresses for your firewall.
Change the domain’s record to the Neogate address. Once it propagates, traffic flows through us and the TLS certificate is issued automatically.
Allow incoming connections on 80 and 443 only from Neogate addresses. Otherwise an attack can go straight to your server, around the protection.
# DNSshop.example.com. CNAME <target from the dashboard># server: allow 80 and 443 from Neogate onlyufw allow from <Neogate address> to any port 80,443 proto tcpufw deny 80,443/tcp
pricing
- up to 3 domains
- reports and stats for 7 days
- full protection, no limits
- up to 15 domains
- reports and stats for 30 days
- full protection, no limits
- up to 50 domains
- reports and stats for 90 days
- full protection, no limits
- ●browser check and TLS fingerprints
- ●behaviour limits, scanner filtering
- ●attack mode per site
- ●TLS certificates
- ●shareable attack reports
- ●Telegram alerts
- ●server monitoring
- ●team access to a project
- ●99.5% SLA
Protection is the same on every plan; plans differ in the number of domains and how long reports are kept. No auto-renewal. Checkout is in Russian rubles at the ruble price of the plan, so a card issued outside Russia may not work yet: write to us and we’ll find a way. If a payment lapses, protection keeps working, and after 3 days only settings changes are locked. Unused days are refunded.
questions
Websites and APIs served over HTTP and HTTPS. We don’t protect game servers or other TCP and UDP services. Volumetric network attacks are absorbed by the upstream carrier before they reach our servers.
No. Change the domain’s DNS record and close your server to direct connections, that’s all.
Yes. Protection starts as soon as the new DNS record propagates, usually within minutes. Close your server to direct connections right away: the address under attack is already known to the attackers.
The real one: we pass it in the X-Real-IP and X-Forwarded-For headers. In nginx, turning on real_ip_header is enough.
Not normally. During an attack the browser passes the check automatically in a fraction of a second. APIs and apps in API mode never get the check; limits and filters protect them.
Nobody can promise that, and neither do we. During a heavy attack some visitors may be refused for a moment; the terms say so. The availability of the service itself is covered by the SLA.
99.5% availability a month. Below that, we extend your paid period by 10–50% of the plan’s monthly price.
In rubles, by card or SBP, for 1, 3, 6 or 12 months with up to 15% off. If you cancel, unused days are refunded.
On servers in Germany. Request logs are kept for 30 days and attack records for 90 days, then deleted automatically.
We’ll connect you at once; protection starts as soon as the DNS record propagates. Write to admin@neogate.systems, the first 3 days are free.
protect my site