ddos protection for websites

Neogate takes your site’s traffic, filters out bots and floods, and lets only real visitors through to your server. You connect through DNS in a few minutes, with no changes to your code.

● bots bounce off● people get through
  • from $15 a month
  • 3 days free
  • HTTP and HTTPS
  • servers in Germany
33
attacks stopped
780,157
requests a minute at peak
9.7M
requests filtered out
3,754
addresses in one attack

from our edge since September 5, 2026, 8 customer domains, updated every 10 minutes

what it looks like

attack of September 21, 2026

A real attack on a site behind Neogate. In three minutes 1,099,242 requests hit the edge and 1,437 reached the server, that is 0.13%. Switch to “unprotected” to see what the server would have got. The dashboard has the same chart and a report for every attack.

arrived
1,099,242
reached the server
1,437

how traffic is filtered

The same attack: of 1,099,242 requests, 1,437 reached the server. This is where the rest stopped.

layer 1
network
stopped before the edge, not counted
  • volumetric attacks are absorbed by the upstream carrier before they reach our servers
  • packets from flooding addresses are dropped in the network card driver, before the system’s network stack
layer 2
connection
−843,344dropped
  • hundreds of addresses sharing one TLS fingerprint are cut off by the fingerprint at once, not address by address
  • a bot that holds one HTTP/2 connection and pushes thousands of requests through it loses the whole connection
  • dropped bots get no answer: the connection just goes silent, and the flood tool waits instead of sending its next request
layer 3
request
−254,461dropped
  • attack mode switches on for the site under attack only, its neighbours don’t notice
  • the browser check is a small puzzle a browser solves in a fraction of a second, no captcha
  • during an attack a page’s background requests are only accepted from a browser that has passed the check
  • returning visitors and the Google, Yandex and Bing crawlers go through without a check
layer 4
your server
1,437reached
  • gets only traffic that passed, with the visitor’s real IP in X-Real-IP and X-Forwarded-For
  • if it starts answering with errors, attack mode switches on by itself, even without a visible flood
  • if it stops responding, you get a notification

what a visitor sees

During an attack this page shows up in front of the site for a moment. The browser solves a small puzzle and opens the site by itself. The text only appears after 0.8 seconds, so a visitor usually just sees a slightly longer load.

  • no captcha, no clicks: the browser does it all
  • the puzzle is unique to each address and browser, so a solution can’t be handed out to a botnet
  • the edge checks the answer with one hash, which costs it nothing
  • on the right, this check just ran in your browser, for real
🔒 shop.example.ru
Checking your browser…
One second, attack protection is on.
puzzle…answer…sha256…

also included

behaviour limits

We count more than requests. An address that keeps getting errors, walks through pages that don’t exist or sends huge request bodies is cut off before it hits the limit.

tls certificates

We issue and renew the certificate for your domain. HTTPS works from the first minute.

attack reports

Peak load, sources, response codes and what was filtered out. A report can be shared with a link.

telegram alerts

A message when an attack starts and ends, and when your server stops responding.

who it’s for

websites and shops

Visitors get the invisible check only during an attack; the rest of the time the site works as usual. Google, Yandex and Bing crawlers are let through by their addresses, so search rankings don’t suffer.

Chrome→browser check→your site
  • an invisible browser check, only while an attack is on
  • search crawlers go through without a check
  • a WAF on the OWASP rules: SQL injection, XSS and the rest
  • optional: a per-address limit and scanner filtering

how to connect

01
add the domain

Enter the domain, your server’s address and the mode: website, API or service. The dashboard shows the DNS target and our addresses for your firewall.

02
point DNS

Change the domain’s record to the Neogate address. Once it propagates, traffic flows through us and the TLS certificate is issued automatically.

03
lock the server

Allow incoming connections on 80 and 443 only from Neogate addresses. Otherwise an attack can go straight to your server, around the protection.

# DNS
shop.example.com. CNAME <target from the dashboard>
 
# server: allow 80 and 443 from Neogate only
ufw allow from <Neogate address> to any port 80,443 proto tcp
ufw deny 80,443/tcp

pricing

Start
$15/ month
  • up to 3 domains
  • reports and stats for 7 days
  • full protection, no limits
start with 3 days free
Pro
$39/ month
  • up to 15 domains
  • reports and stats for 30 days
  • full protection, no limits
start with 3 days free
Business
$99/ month
  • up to 50 domains
  • reports and stats for 90 days
  • full protection, no limits
start with 3 days free
on every plan
  • ●browser check and TLS fingerprints
  • ●behaviour limits, scanner filtering
  • ●attack mode per site
  • ●TLS certificates
  • ●shareable attack reports
  • ●Telegram alerts
  • ●server monitoring
  • ●team access to a project
  • ●99.5% SLA

Protection is the same on every plan; plans differ in the number of domains and how long reports are kept. No auto-renewal. Checkout is in Russian rubles at the ruble price of the plan, so a card issued outside Russia may not work yet: write to us and we’ll find a way. If a payment lapses, protection keeps working, and after 3 days only settings changes are locked. Unused days are refunded.

questions

Websites and APIs served over HTTP and HTTPS. We don’t protect game servers or other TCP and UDP services. Volumetric network attacks are absorbed by the upstream carrier before they reach our servers.

No. Change the domain’s DNS record and close your server to direct connections, that’s all.

Yes. Protection starts as soon as the new DNS record propagates, usually within minutes. Close your server to direct connections right away: the address under attack is already known to the attackers.

The real one: we pass it in the X-Real-IP and X-Forwarded-For headers. In nginx, turning on real_ip_header is enough.

Not normally. During an attack the browser passes the check automatically in a fraction of a second. APIs and apps in API mode never get the check; limits and filters protect them.

Nobody can promise that, and neither do we. During a heavy attack some visitors may be refused for a moment; the terms say so. The availability of the service itself is covered by the SLA.

99.5% availability a month. Below that, we extend your paid period by 10–50% of the plan’s monthly price.

In rubles, by card or SBP, for 1, 3, 6 or 12 months with up to 15% off. If you cancel, unused days are refunded.

On servers in Germany. Request logs are kept for 30 days and attack records for 90 days, then deleted automatically.

under attack right now?

We’ll connect you at once; protection starts as soon as the DNS record propagates. Write to admin@neogate.systems, the first 3 days are free.

protect my site