Service Hotline
400-637-7717
ICP Filing Specialist
0760-88308377
Site knocked offline by an attack? One CNAME record puts it behind our protection nodes — they absorb the attack and your origin disappears. No traffic or bandwidth limits.

Attack traffic stops at the protection nodes: static assets are served from cache, dynamic requests are rate-limited, single IPs going too fast are blocked, and connections for unknown domains are dropped. CC attacks never reach your origin.
Visitors and attackers only ever see the protection nodes. Your origin IP appears in no DNS record, so it can't be targeted directly.
Plans can include several protection nodes with DNS round-robin. If one node fails, drop it from DNS and traffic carries on uninterrupted.
You pay by the number of protected sites — no traffic packages, no bandwidth caps, no overage charges. No surprise bills, no service cut off mid-attack.
Paste your own certificate or use a free one issued here. Nodes terminate SSL and forward securely to the origin, with SNI support for multiple sites.
The origin doesn't have to be ours — cloud server, bare metal, shared hosting, even a machine at another provider. Just enter the IP.
Pick a tier by how many sites you need protected and pay from your balance — provisioned instantly.
Enter the domain and origin IP in your account, add a certificate if you need HTTPS, and saving pushes it to every node.
at your DNS provider, and CNAME the domain to the endpoint we assign.
Once DNS propagates, traffic routes through the protection nodes and your origin disappears from view.
Unlimited. Plans differ only by how many sites you can protect — no traffic packages, no bandwidth caps, no overage fees, and your service is never cut off for exceeding a quota.
Keep it on all the time. That way an attack is absorbed with no action from you, and your origin stays hidden day to day. If you only switch it on once you're under attack, your origin IP is already exposed and protection is less effective.
The DNS standard doesn't allow a CNAME on a root domain. Point a subdomain such as www at us and 301-redirect the root to it; some providers (DNSPod, for example) support CNAME flattening on the root and can be used directly.
Your site is pushed to the protection nodes within seconds of saving. When it actually takes effect depends on your DNS TTL — usually under ten minutes.
No. Any server with a public IP can be the origin, including machines at other providers.
Paste your certificate and private key (PEM format) when adding the site, and the nodes will terminate SSL for your domain before forwarding to the origin. No certificate? Request a free one here first.
Connections reaching your origin come from node IPs; the real visitor IP is in the X-Forwarded-For / X-Real-IP headers for your application to read.