DDoS mitigation and WAF

Drop the attack.Keep your users.

Sep 20261.99M rps flood, 310 requests reached the origin

Layer7 is a reverse proxy and WAF that scores every request at our edge and passes clean traffic to your origin.

It starts working the moment you point DNS at it.

1.0 Defaults

Protected at request one

Mitigation engages from the first request, not after your error rate crosses some threshold.

2.0 Philosophy

No rate limiting

Every request is scored on its own instead, so real users keep full speed in the middle of an attack.

3.0 Plans

Same protection on every plan

Free included. Paying buys control on top, never a stronger defense.

4.0 Origin

An origin that stays hidden

Origin-side mTLS by default, rotated on a schedule. A leaked IP still has to prove it came from our edge.

Chaos in. Clean traffic out.

01

Fingerprint

Each connection's TLS fingerprint is checked against the browser the client claims to be.

RequestGET /login
ClaimsChrome 130 · Windows
TLS JA4
Fingerprint ≠ browser

The client says it's Chrome 130 on Windows. Its TLS handshake says otherwise.

02

Score

Header consistency and request cadence are weighed together, request by request.

Real users
Request cadence
  • Request cadence is machine-regular
  • Header order inconsistent with the claimed browser
03

Decide

Pass, challenge, or drop. Real users never see a wall.

04

Forward

Clean traffic reaches your origin over mTLS, so a leaked origin IP isn't a way around us.

An origin that stays hidden

Origin-side mTLS by default, rotated on a schedule. A leaked IP still has to prove it came from our edge.

Where this runs today. While we build our own scrubbing network, Layer7 runs on Cloudflare's serverless edge. To be clear about who does what: Cloudflare's application-layer mitigation and bot protection are switched off for the traffic we handle. Everything that judges your traffic, the scoring, the challenges, the rules, is Layer7's engine. When our network comes online, your setup won't change.

Sep 27, 2026 · Layer 7 · Platform record

1.99 million requests a second.

Requests
228.8 million
Source IPs
10,000+
Traffic
1.09 TB
Duration
four minutes
Reached the origin
310
Filtered at the edge
99.9998%
Hitting our edgeReaching your origin
0:000:004:00

The record.

Attacks absorbed, with the numbers. Entries before 2026 come from the network R&D that became this product.

  1. Aug 23, 2026Layer 7975k requests / sec115.6 million requests in one flood. 84 reached the origin.
  2. Aug 21, 2026Layer 7670k requests / sec125.8 million requests in one flood. 22 reached the origin.
  3. May 10, 2025Layer 42.62B packets / secPeaked at 1.4 terabytes per second over a three-minute burst, with no disruption or packet loss.
  4. Apr 26, 2025Layer 41B packets / secAveraged nearly a billion packets per second for 16 minutes straight, without disruption.
  5. Mar 22, 2025Layer 715M requests / secA Meris-based attack on WHMCS. Over 99.99% filtered, using proof-of-work and zero rate limiting.

Our position

A rate limit throttles your real users at the worst possible moment and calls it mitigation. We don't believe in them.

With a rate limit

0 real users throttled

  • Real users get throttled along with the attack
  • It bites hardest when you're under the most load
  • Volume alone decides who gets through

With Layer7

0 real users throttled

  • Each request is judged on its own
  • Real users keep full speed during an attack
  • No thresholds to tune

Every verdict, explained.

The dashboard shows what was blocked, what was challenged, and why, down to a single request.

The Layer7 dashboard listing every protected domain with its status and last attack
Every protected domain, its status, and its last attack, on one screen.

Two ways to connect.

Both get the same mitigation. The difference is how much of your DNS we handle.

Layer7 DNS · example.comDelegated
TypeNameContent
A@203.0.113.10Protected
CNAMEwwwexample.comProtected
Aapi203.0.113.24Protected

Nameserver setup Recommended

Delegate your domain to Layer7 nameservers and manage DNS in the dashboard like normal, with mitigation on top.

  • Covers the whole domain: apex and every subdomain
  • Full DNS management in the Layer7 dashboard
  • Nameserver changes can take hours to propagate
  • Requires a paid plan, Pro or above
; your DNS provider www.example.com. CNAME protect.l7.gg. # keep every other record where it is www.example.com is protected

CNAME setup

Keep your DNS where it is. Point a hostname at your Layer7 target and it's protected.

  • Works from any DNS provider, nothing to delegate
  • Covers the hostnames you point, up to your plan's allowance
  • The apex needs CNAME flattening at your DNS host
  • Available on every plan, free included

Pay for control, not protection.

Priced per protected domain, billed monthly. Mix plans across domains. The defense is identical on every plan.

Free

$0 by application

  • 1 protected hostname
  • No custom rules
  • 1 team seat
  • CNAME setup
Apply

Pro Popular

$25 /mo per domain

  • 3 protected hostnames
  • 25 custom rules
  • 3 team seats
  • CNAME or nameservers
Get Pro

Business

$175 /mo per domain

  • 15 protected hostnames
  • 64 custom rules
  • 10 team seats
  • CNAME or nameservers
Get Business

Enterprise

Custom arranged with us

  • Unlimited hostnames
  • 64 custom rules
  • Custom seats
  • CNAME or nameservers
Contact us

Every plan runs the full mitigation engine, automatic from the first request, no interstitial by default.

Hostname counts apply to CNAME setup only. Nameserver setup covers the whole domain, apex and every subdomain, with nothing to count.

Custom rules are rules you add yourself. The protection underneath is the same on every plan, free included, and most sites never need one.

Seats are people you invite besides yourself. Pending invitations count toward the limit.

War Room

The traffic we drop is evidence.

We'd rather it shut something down at the source.

Aisuru botnet

Provided attack telemetry and infrastructure mapping that supported the law-enforcement effort against the botnet. Write-up on the War Room blog.

Kimwolf botnet

Our threat intelligence was first to reach investigators on Kimwolf and helped drive the law-enforcement response.

Cooperation with law enforcement described above does not imply endorsement by any agency.

Get protected

Point your DNS. That's the setup.

Register, verify your email, add your domain, and check out. You're protected as soon as payment clears.