WAF Detector
Find out which web application firewall, bot protection or security CDN protects a website.
WAF Detector
A web application firewall (WAF) filters traffic before it reaches a website, blocking attacks and bots. This detector identifies more than 35 firewalls, bot-protection services and security CDNs from the evidence they leave in an ordinary response: headers, cookies, server names and block pages. It makes one normal request and sends no attack patterns.
How to use WAF Detector
- Enter the website address.
- Click Detect.
- Read which protections were found, with the evidence and confidence for each.
When it comes in handy
- Checking that your own site is really behind the firewall you pay for.
- Understanding why a crawler, monitor or API client gets blocked.
- Researching a competitor's infrastructure.
Frequently asked questions
- Why was no WAF found?
- Some firewalls are invisible in normal responses and only show themselves when they block something. Active detectors send attack-like requests to trigger that; we do not, so a site can be protected even when nothing is detected.
- Is a CDN the same as a WAF?
- Not always. Cloudflare, Akamai and others bundle a WAF with their CDN, but a site can use the CDN without enabling the firewall rules.