Shield

DNS Level Security. Enterprise Grade Protection.

Edge Shield provides real-time threat detection and response with fine-grained DNS and firewall controls. Advanced geo-location filtering, rate limiting, and automated threat response keep your infrastructure secure at the network edge.

Get started now

Product

Enterprise Security That Scales With Your Infrastructure

RRL

DNS Response Rate Limiting (RRL) Industry-standard protection against DNS amplification attacks with configurable slip ratios.

Deploy Now
Geo-Location

Hierarchical Geo-Location Filtering Continental, regional, and state-level access control with automatic US state detection

Deploy Now
CIDR

Advanced IP Filtering Granular blacklisting and whitelisting with CIDR support for IPv4 and IPv6

Deploy Now

Comprehensive Protection for Modern DNS Security Challenges

Stop attackers from using your DNS infrastructure to launch devastating DDoS attacks
Multi-bucket Rate Limiting

Per-IP, per-query, and combined rate limits

Slip Ratio Control

Maintain service availability during attacks

Response Categorization

Different limits for normal, NXDOMAIN, error responses

Subnet-Based Limiting

/24 IPv4 and /56 IPv6 prefix protection

Real-Time Monitoring

Immediate attack detection and response

Automated Mitigation

Dynamic rate adjustment based on attack patterns

Perfect for
High-traffic domains, public DNS services, and enterprise networks vulnerable to amplification abuse
FAQ

Start Protecting Today.

Deploy enterprise DNS security in under 60 seconds. Get comprehensive threat protection immediately.

Deploy Shield Now

Why Choose Edge Shield

Real-Time Threat Intelligence

Advanced pattern recognition automatically identifies and blocks emerging threats before they impact your infrastructure. Our distributed network processes millions of queries to identify attack signatures.

Global Edge Network

Deploy protection across our high-performance regions with sub-10ms latency. Global reach ensures optimal performance regardless of user location.

RFC Compliant Protection

Built on industry-standard protocols including RFC 1035 (DNS), RFC 7871 (EDNS Client Subnet), and DNS RRL specifications. Ensures compatibility with all major DNS resolvers and client software.

Enterprise Integration

Seamless integration with existing DNS infrastructure, monitoring systems, and security tools. API-driven configuration enables automated security orchestration.

Zero False Positives

Intelligent slip ratios and hierarchical filtering ensure legitimate traffic always reaches your services, even during active attacks. Advanced whitelisting prevents blocking of critical infrastructure.

Transparent Operation

Detailed logging, real-time metrics, and comprehensive reporting provide complete visibility into threats, mitigation actions, and service performance.

Advanced Security
Features

DNS Response Rate Limiting (RRL)
Industry-standard protection against amplification attacks
Per-IP Rate Limiting

Protect against single-source floods

Per-Query Rate Limiting

Prevent specific record abuse

Response Type Limiting

Control NXDOMAIN and error response rates

Combined IP+Query Limiting

Advanced multi-vector protection

Configurable Slip Ratios

Maintain service during attacks (1 in 2, 1 in 3, etc.)

Sliding Time Windows

Adaptive rate limiting with 15-second default windows

Typical Configuration:

5 responses/second per source subnet

50% slip ratio for legitimate traffic

Separate limits for normal, NXDOMAIN, and error responses

Automatic escalation during attack detection

Hierarchical Geo-Location Control

Precision geographical access control from continental to state level

Advanced IP Filtering
Granular network-level access control
Blacklisting Capabilities:
Individual IP addresses
CIDR blocks (IPv4 and IPv6)
Dynamic threat intelligence integration
Automated pattern-based blocking
Whitelisting Protection:
Critical infrastructure preservation
Trusted network definitions
Override protection during attacks
Emergency access maintenance
Supported Formats
IIPv4: 192.168.1.100, 10.0.0.0/8, 172.16.0.0/12
IPv6: 2001:db8::1, 2001:db8::/32, ::1/128
The ECS Advantage
Without ECS:
User (Tokyo) → Google DNS (8.8.8.8 USA) → Your Server Server sees: US location
With ECS:
User (Tokyo) → Google DNS + ECS → Your Server Server sees: Real Tokyo IP

Shield Plans

50% less than AWS Route 53 for DNS queries, plus enterprise security

Shield Essential

Core DNS security for growing businesses

£25

/month + query volume

DNS Response Rate Limiting (5 req/sec default)

Country-level geo-filtering (50 countries)

Basic IP blacklisting (1,000 IPs)

Standard logging and alerts

99.9% uptime SLA

EDNS Client Subnet protection

Real-time threat intelligence

Advanced analytics dashboard

Custom alert integrations

Query pricing: £0.20 per million queries (Route 53: £0.40)
Learn more
Shield Professional

Advanced protection for enterprise infrastructure

£65

/month + query volume

Advanced DNS RRL with custom limits

Hierarchical regional geo-filtering (all regions)

Advanced IP filtering with CIDR support

US state-level precision filtering

EDNS Client Subnet protection

Real-time threat intelligence

Advanced analytics dashboard

Custom alert integrations

99.95% uptime SLA

Query pricing: £0.20 per million queries (Route 53: £0.40)
Learn more
Shield Enterprise

Maximum protection for critical infrastructure

£185

/month + query volume

Custom DNS RRL configurations

Unlimited geo-filtering rules

Advanced threat intelligence integration

Custom IP filtering policies

Dedicated security engineer support

Custom integration development

White-label dashboard options

99.99% uptime SLA

24/7 security operations center

Query pricing: £0.15 per million queries (Route 53: £0.40)
Learn more

Security Event Types

Event Type

Description

Automatic Response

Amplification Attack

High-volume, low-diversity queries

Rate limiting activation

Geographic Anomaly

Unusual traffic from blocked regions

Enhanced geo-filtering

IP Reputation

Traffic from known malicious sources

Automatic blacklisting

Query Pattern

Suspicious query patterns detected

Pattern-based blocking

Volume Spike

Unusual traffic volume increases

Dynamic rate adjustment

Attack Detection Dashboard

Live Threat Metrics:

Real-time query volume and patterns

Attack detection and mitigation status

Geographic distribution of threats

Rate limiting effectiveness

False positive monitoring

Historical Analysis:

30-day threat trend analysis

Attack pattern identification

Mitigation effectiveness reports

Performance impact assessment

Alert Integration:

Webhook notifications

Custom alert thresholds

Escalation policies

Automated response triggers

Cost Calculator

Compare Shield vs AWS Route 53 + separate security solutions

Monthly Queries

Shield Professional

AWS Route 53

Security Add-ons

Total AWS Cost

Savings

100M

£85

£40

£80

£120

£35/month

500M

£165

£200

£80

£280

£115/month

1B

£265

£400

£80

£480

£215/month

2B

£465

£800

£80

£880

£415/month

AWS costs include Route 53 DNS queries + AWS WAF + CloudFront for equivalent security features

Deploy Shield Now

The Security First Choice

Traditional DNS infrastructure leaves you vulnerable to modern threats. Edge Shield provides comprehensive protection without compromising performance or availability.

00.0
0.0

%

Attack mitigation effectiveness

00.0
0

%

%

Better power usage

Shield offers

Ready to Secure Your Infrastructure?

Instant Protection:

DNS RRL and geo-filtering active in 60 seconds

Threat Visibility:

Real-time dashboard and alert integration

Zero Downtime:

Seamless integration with existing DNS infrastructure

Expert Support:

Security available for configuration assistance

Transparent Pricing:

No hidden fees, clear overage costs

Scalable Solutions:

Grows with your infrastructure needs

Deploy Edge Shield in under 60 seconds. No hardware, no lengthy configurations, just immediate enterprise-grade protection.

Start Free 14-Day Trial

Built For Modern Development

Seamlessly integrate with your existing tools and workflows.

PuppetCircleCIKubernetesPuppetCircleCIKubernetes
PuppetCircleCIKubernetesPuppetCircleCIKubernetes
DockerAnsibleTerraformGitLabDockerAnsibleTerraformGitLab
DockerAnsibleTerraformGitLabDockerAnsibleTerraformGitLab

Signup and Get Started Today!

Sign up now and receive $25 free credit using promo code.

Experience the Future of Blockchain with XE

If you’re interested in contributing or exploring its tokenomics, you can learn more directly on the website.

Open network explorer

Join The Community

Edge is driven by transparency and community engagement. Operating as a DAO, the project’s Open Governance system allows anyone to participate in its future.

Not ready for Web3?

Visit our Web2 distributed cloud platform.

Open Platform