ShieldFlare Documentation
Welcome to ShieldFlare. Everything you need to protect your websites, servers and game servers against DDoS attacks and cyber threats.
What is ShieldFlare?
ShieldFlare is a next-generation DDoS protection platform built for websites, servers and game servers. We provide enterprise-grade security at an accessible price โ fully managed from a single dashboard.
Nameservers
To use ShieldFlare DNS management, point your domain to our nameservers:
ns1.shieldflare.nl โ 149.202.63.64
ns2.shieldflare.nl โ 51.38.13.157
Platform Status
Check real-time status of all ShieldFlare services at status.shieldflare.nl.
Quickstart
Get your website protected with ShieldFlare in under 5 minutes.
Create an account
Sign up for free at shieldflare.nl/register. No credit card required.
Add your domain
Go to Add Service โ Domain Protection and enter your domain name.
Set nameservers
At your domain registrar, update your nameservers to ns1.shieldflare.nl and ns2.shieldflare.nl.
Add DNS records
Add an A record pointing to your server IP. Enable the proxy (orange cloud) to activate DDoS protection.
Done!
Your website is now protected. DNS propagation can take up to 24 hours depending on your previous TTL.
Core Concepts
Understanding the key concepts behind ShieldFlare.
Proxy Mode
When a DNS record is set to Proxied, all traffic flows through ShieldFlare before reaching your server. Visitors see the ShieldFlare IP instead of your real server IP, protecting it from direct attacks.
DNS-Only Mode
When set to DNS-Only, ShieldFlare resolves the domain to your real server IP. There is no proxy protection but DNS is still managed through ShieldFlare.
WAF Rules
The Web Application Firewall inspects every HTTP request for known attack patterns including SQL injection, Cross-Site Scripting (XSS), path traversal and bot signatures.
IP Guard
IP Guard uses a WireGuard VPN tunnel to protect your server. All incoming traffic passes through a dedicated ShieldFlare IP, which filters attacks before forwarding clean traffic to your server. Your real IP remains hidden at all times.
Dedicated IPs
Each IP Guard tunnel and Game Server gets a dedicated IP address from the ShieldFlare pool. This IP is exclusively used for your service and is never shared with other customers.
Domain Protection
Protect your website with our Cloudflare-style proxy and Layer 3/4/7 DDoS mitigation.
How it works
When proxy is enabled, all traffic to your domain flows through ShieldFlare first. We analyze the traffic, block attacks in real-time, and forward clean requests to your origin server. Visitors never see your real IP.
Attack types blocked
| Type | Description | Auto-blocked |
|---|---|---|
| SYN Flood | TCP SYN packet floods | โ Yes |
| UDP Flood | UDP packet floods | โ Yes |
| HTTP Flood | Large volume HTTP requests | โ Yes |
| ICMP Flood | Ping flood attacks | โ Yes |
| Slowloris | Slow HTTP connections | โ Yes |
| Amplification | DNS/NTP/SSDP amplification | โ Yes |
Settings
Per domain you can configure:
- Proxy toggle โ Enable/disable proxy per DNS record
- WAF โ Web Application Firewall rules
- Geo-blocking โ Block traffic from specific countries
- Bot protection โ Challenge page for automated traffic
- SSL โ Free Let's Encrypt certificates
DNS Management
Manage all DNS records for your domains through the ShieldFlare dashboard.
Supported record types
| Type | Use case | Proxy support |
|---|---|---|
A | IPv4 address | โ Yes |
AAAA | IPv6 address | โ Yes |
CNAME | Alias to another domain | โ Yes |
MX | Mail server | โ No |
TXT | Text records (SPF, DKIM, etc.) | โ No |
NS | Nameserver | โ No |
SRV | Service record | โ No |
CAA | Certificate Authority | โ No |
Nameservers
ns1.shieldflare.nl โ 149.202.63.64
ns2.shieldflare.nl โ 51.38.13.157
SSL Certificates
ShieldFlare automatically provisions and renews free SSL certificates via Let's Encrypt.
Automatic renewal
SSL certificates are automatically renewed 30 days before expiry. You will receive a notification if renewal fails.
Requirements
- Proxy must be enabled for the domain
- Nameservers must point to ShieldFlare
- Domain must be active and resolving
SSL Monitor
View SSL status for all your domains under Domains โ SSL tab. You will receive a push notification and email when a certificate expires within 14 days.
Web Application Firewall
Protect your website against known attack patterns and malicious requests.
Built-in rules
| Attack type | Example | Action |
|---|---|---|
| SQL Injection | ' OR 1=1-- | Block |
| XSS | <script>alert(1)</script> | Block |
| Path Traversal | ../../../etc/passwd | Block |
| Command Injection | ; ls -la | Block |
| Scanner detection | Nikto, sqlmap, etc. | Block |
Custom rules
Add custom WAF rules under Domains โ WAF tab. Rules can be based on:
- IP address or CIDR range
- Country code
- User-Agent string
- URL pattern
- Request method
IP Guard
Protect your server with an encrypted WireGuard VPN tunnel and a dedicated ShieldFlare IP.
How it works
IP Guard creates an encrypted WireGuard tunnel between your server and ShieldFlare. All incoming traffic passes through your dedicated ShieldFlare IP, which filters attacks before forwarding clean traffic to your server via the tunnel. Your real IP is never exposed.
Setup
Add IP Guard
Go to Add Service โ IP Guard in the dashboard.
Install WireGuard
Run the setup script on your server as root:
apt install wireguard -y
Configure tunnel
Download the WireGuard config from the dashboard and save it as /etc/wireguard/wg0.conf.
Start the tunnel
wg-quick up wg0
systemctl enable wg-quick@wg0
Firewall rules
ShieldFlare automatically configures iptables rules to only allow traffic through the tunnel. Default open ports:
TCP 80 โ HTTP
TCP 443 โ HTTPS
TCP 22 โ SSH
UDP * โ All UDP traffic
Settings
| Setting | Description |
|---|---|
| Threshold (pps) | Packets per second before an IP is blocked |
| Block duration | How long a blocked IP stays blocked (seconds) |
| Geo-blocking | Block traffic from specific countries (ISO codes) |
| Whitelist IPs | IPs that are never blocked, even during an attack |
| Bandwidth limit | Max bandwidth per second (leave empty for unlimited) |
| Max connections/IP | Maximum concurrent connections per IP |
Game Server Protection
Protect your game server with a TCP/UDP proxy and dedicated IP โ no installation required.
Supported games
| Game | Protocol | Default port | Extra features |
|---|---|---|---|
| Minecraft Java | TCP | 25565 | MOTD customization, status monitoring |
| Minecraft Bedrock | UDP | 19132 | Status monitoring |
| FiveM (GTA) | TCP/UDP | 30120 | โ |
| CS2 / CS:GO | UDP | 27015 | โ |
| Valheim | UDP | 2456 | โ |
| Rust | UDP | 28015 | โ |
| Custom | TCP/UDP | Custom | โ |
Failover
Configure a backup server under Game Servers โ Settings โ Failover. If the primary server becomes unreachable, ShieldFlare automatically switches to the backup within 30 seconds.
Minecraft MOTD
Customize the server description players see in the server list under Game Servers โ Settings โ Minecraft MOTD. Standard Minecraft color codes are supported:
ยง6ยงlMy Server ยงrยง7| ยงfWelcome!
Email per Domain
Create professional email addresses for your domains with full spam and spoofing protection.
Setup
Add your domain
Your domain must be active in ShieldFlare with nameservers pointing to us.
Create a mailbox
Go to Dashboard โ Email and click Create mailbox.
Access webmail
Login at mail.shieldflare.nl with your email and password.
Email authentication
ShieldFlare automatically configures SPF, DKIM and DMARC records for your domain to prevent email spoofing and improve deliverability.
| Record | Purpose | Status |
|---|---|---|
| SPF | Authorizes sending servers | Auto-configured |
| DKIM | Cryptographic email signature | Auto-configured |
| DMARC | Email authentication policy | Auto-configured |
Analytics
Real-time traffic statistics and attack reports for all your services.
Traffic overview
View incoming traffic, blocked requests, bandwidth usage and attack statistics under Dashboard โ Analytics. Data is collected every minute and shown in interactive charts.
Metrics available
- Total requests and bandwidth
- Blocked requests and attack rate
- Unique visitors and geographic distribution
- Response time and error rate
- Top blocked IPs
Attack reports
Detailed attack reports are automatically generated during an attack. You also receive a daily summary report at 08:00 AM via email if any attacks occurred in the past 24 hours.
Uptime Monitor
Automatic availability monitoring for all your domains every 5 minutes.
How it works
ShieldFlare checks your domain via HTTP and HTTPS every 5 minutes. If a domain becomes unreachable, you receive an immediate notification. When the domain recovers, you receive a recovery notification.
Viewing uptime
View uptime history for any domain under Domains โ Uptime tab. The 90-day uptime bar shows availability at a glance.
Notifications
When a domain goes offline you receive:
- Push notification in the browser
- Email notification
- Discord DM (if linked)
Alerts & Notifications
Stay informed about security events and service status in real-time.
Notification types
| Event | Push | Discord DM | |
|---|---|---|---|
| ๐จ DDoS attack detected | โ | โ | โ |
| ๐ด Website offline | โ | โ | โ |
| ๐ข Website restored | โ | โ | โ |
| โ ๏ธ SSL expiring soon | โ | โ | โ |
| ๐ Tunnel disconnected | โ | โ | โ |
| ๐ฎ Game server offline | โ | โ | โ |
| ๐ Daily attack report | โ | โ | โ |
Configure notifications
Manage notification preferences under Dashboard โ Notifications. Link your Discord account under My Account to receive Discord DMs.
API Introduction
The ShieldFlare REST API gives you programmatic access to all your account resources and services.
Base URL
https://shieldflare.nl/api
Format
All requests and responses use JSON. Include the Content-Type: application/json header with POST and PATCH requests.
Rate limiting
The API is limited to 100 requests per minute per API key. When exceeded, you receive a 429 Too Many Requests response.
HTTP status codes
| Code | Meaning |
|---|---|
200 | Success |
400 | Bad request |
401 | Not authenticated |
403 | Forbidden |
404 | Not found |
429 | Rate limit exceeded |
500 | Server error |
Authentication
The ShieldFlare API uses API keys for authentication.
Creating an API key
Go to Dashboard โ API Keys โ Create new key. Save the key immediately โ it is only shown once.
Using the API key
Include the API key as a Bearer token in the Authorization header:
Authorization: Bearer sf_live_xxxxxxxxxxxxxxxxxxxx
Example request
curl https://shieldflare.nl/api/domains \
-H "Authorization: Bearer sf_live_xxxxxxxxxxxxxxxxxxxx"
API โ Domains
Manage domains via the API.
Example response
{
"domain": {
"id": "clx1234567890",
"name": "example.com",
"status": "ACTIVE",
"proxied": true,
"sslDaysLeft": 45,
"createdAt": "2026-01-01T00:00:00.000Z"
}
}
API โ DNS Records
Manage DNS records via the API.
Create a record
curl -X POST https://shieldflare.nl/api/dns/DOMAIN_ID \
-H "Authorization: Bearer sf_live_xxx" \
-H "Content-Type: application/json" \
-d '{
"type": "A",
"name": "@",
"content": "1.2.3.4",
"ttl": 3600,
"proxied": true
}'
API โ IP Guard
Manage IP Guard tunnels via the API.
API โ Game Servers
Manage game servers via the API.
WHMCS Module
Sell ShieldFlare services through your own WHMCS installation.
Requirements
- WHMCS 8.x
- PHP 8.1+
- ShieldFlare Reseller account
- ShieldFlare API key (reseller type)
Installation
Create API key
Go to Reseller โ API Keys and create a new key of type Reseller.
Upload module
Download the ShieldFlare module and upload the shieldflare/ folder to /modules/servers/ on your WHMCS server.
Add server
In WHMCS go to System Settings โ Servers โ Add New Server.
Configure server
Set Hostname to shieldflare.nl, Password to your API key, Port to 443 and check Secure.
Create products
Add products for each ShieldFlare plan (free, starter, pro, enterprise) and set the module to ShieldFlare.
How provisioning works
When a customer places an order in WHMCS:
- WHMCS calls the ShieldFlare API with the customer's email and chosen plan
- ShieldFlare creates a new account under your reseller profile
- The customer receives a welcome email with login credentials
- The customer appears in your reseller dashboard under Clients
Single Sign-On (SSO)
Customers can click Login to ShieldFlare in WHMCS to automatically log in to their ShieldFlare dashboard without entering a password.
Webhooks
Receive real-time event notifications via HTTP POST to your own endpoint.
Setup
Go to Dashboard โ Webhooks โ Create webhook and enter the URL you want to receive events at.
Events
| Event | Description |
|---|---|
attack.detected | DDoS attack detected |
attack.mitigated | Attack mitigated |
domain.offline | Website went offline |
domain.online | Website came back online |
ssl.expiring | SSL expires within 14 days |
tunnel.disconnected | IP Guard tunnel disconnected |
gameserver.offline | Game server went offline |
gameserver.failover | Failover activated |
Payload example
{
"event": "attack.detected",
"timestamp": "2026-09-12T12:00:00.000Z",
"data": {
"type": "SYN Flood",
"count": 4329,
"mitigated": true,
"service": "5.135.43.126"
}
}
Reseller Program
Offer ShieldFlare services under your own brand and earn 20% commission on every client.
Benefits
- โ 20% commission on every active client
- โ Full white-label โ your own logo, company name and colors
- โ Client management dashboard
- โ Client impersonation โ log in as any of your clients
- โ WHMCS module included
- โ Reseller API for custom integrations
- โ Custom domain for your client portal
Getting started
Contact us via support to apply for a reseller account. We will review your application within 24 hours.
White-label
Configure your white-label settings under Reseller โ White-label:
- Company name โ shown in the navigation and emails
- Logo URL โ your company logo (PNG recommended)
- Primary color โ brand color for the interface
- Support email โ shown to your clients as support contact
- Custom domain โ host the client portal on your own domain
Commission
You earn 20% commission on the monthly plan price of each active client. Commissions are calculated monthly and paid out when your balance reaches โฌ50.
Reseller API
Manage clients and their services programmatically via the Reseller API.
Create client example
curl -X POST https://shieldflare.nl/api/reseller/clients \
-H "Authorization: Bearer sf_live_reseller_xxx" \
-H "Content-Type: application/json" \
-d '{
"email": "client@example.com",
"name": "John Doe",
"planSlug": "starter"
}'
