ShieldCache is a reverse proxy that sits in front of your existing website. Your website stays with your current host, whether that is us or someone else. You only change the DNS records of your domain. Visitors then reach our proxy servers in Germany first, and only checked requests are passed on to your server, the so-called origin.
The path of a request
Every request to your domain passes through the same stations:
- Proxy servers in Germany: The encrypted connection ends at ShieldCache - via HTTP/1.1, HTTP/2 or HTTP/3, with an automatically issued certificate or your own.
- Global blocklists: The servers drop traffic from known abuse IPs and networks at network level. You do not need to configure anything for this.
- Access rules: IP rules, country and network operator filters, rate limits, access protection and file protection take effect. For soft blocks, a captcha check can appear instead of an error page.
- Web Application Firewall: The OWASP Core Rule Set checks the request for attack patterns such as SQL injection or cross-site scripting.
- HTTP cache: If the response is in the cache, it goes straight back to the visitor. ShieldCache passes all other requests on to your server.
If ShieldCache rejects a request, the visitor sees an error page with an error code and reference. With the reference you can find the request again in the customer area - see Firewall: log and check reference.
Project and sites
Your order creates a project. You will find it in the customer area under My products > ShieldCache. The project shows your sites, the request quota for the month, the plan with its options and the task history.
A site brings together a website with its domains, its origin server and its rules. A site can have up to 20 domains of the same registrable domain, for example muster.de and www.muster.de.
Each site has tabs, and long tabs are divided into sub-tabs:
| Tab | What you do there |
|---|---|
| Overview | First steps, status, key figures for the last 24 hours, latest tasks |
| Domains & DNS | Add and verify domains, all DNS records ready to copy |
| Origin | Your website's server, further origins, timeouts and visitor IP |
| Cache | Cache duration, rules, file types and clearing the cache |
| Optimisation | HTTP/3, compression and HSTS |
| Firewall | Mode, check level, attack categories, exceptions and WAF log |
| Access | IP rules, access protection, countries, network operators, captcha check and block log |
| Rate limits | Limit requests per path and view hits |
| Statistics | Requests, traffic, cache share and blocks |
| Versions | History of all applied changes, restore earlier versions |
| Settings | Operating mode, redirect, security headers, certificate, headers and error pages |
The address in your browser remembers the tab, for example #firewall/protokoll. This lets you share a specific view as a link.
Draft and Apply
All settings of a site start out as a draft. As soon as there are changes, the notice “Pending changes” appears above the tabs with the Apply button. Only then do the changes go to the proxy - this usually takes less than a minute. Every apply creates a numbered version that you can restore later. Only the operating mode and “Clear cache” take effect immediately, without applying.
Plans and limits
Firewall, cache, access rules, captcha check and statistics are included in every plan. The plans differ in these limits:
| Starter | Professional | Enterprise | |
|---|---|---|---|
| Protected websites (sites) | 1 | 3 | 10 |
| Requests per month included | 100,000 | 500,000 | unlimited (fair use) |
| Rate limit paths | 3 | 10 | 50 |
| Custom certificate | as an option | as an option | included |
| Custom error pages | - | - | included |
You can book additional domains for further websites, packs of five more rate limit paths and a custom certificate in the project under Plan & options. If you exceed the request quota, your website keeps running: you receive a message at 80% and 100%, and every 100,000 requests or part thereof above the quota are charged on your next invoice. You will find current prices on the product page ShieldCache.
What next?
Do I have to change my host?
No. Your website stays where it is. You only enter your server's address in ShieldCache and point the DNS records of your domain to ShieldCache.
What counts as a request?
Every HTTP request that ShieldCache answers for your sites - page views as well as images, scripts and stylesheets, regardless of whether the response comes from the cache or from your server. You can see your current usage in the project under “Request quota”.
Does ShieldCache protect against DDoS attacks?
ShieldCache limits requests per path, blocks addresses, countries and networks, drops traffic from global blocklists and fends off attacks at application level. ShieldCache is not designed for high-volume DDoS attacks - that is what our threat protection is for.