Control your edge.
Manage authoritative DNS, origin routing, and access protection in one place.
Use your configured HTTPS management domain or an SSH tunnel to the server’s loopback port 9080. Unlock the panel with your management API token.
Overview
Route traffic. Set the rules. Keep control.
Your first domain starts here.
Add a domain and its origin IP, then update its nameservers at your registrar.
Visitor activity
One row per IP, including this domain and its enabled www hostname. Visits count HTML page navigations allowed through the edge. Assets and challenge redirects do not add visits. Requests include assets and blocked attempts.
This domain is DNS only. New traffic bypasses the edge and cannot be counted here. Existing history remains available.
| IP address | Visits | Country | ISP / network | Requests | Allowed | Challenged | Blocked | Errors | Verified | Last seen (UTC) |
|---|
Protection comparison
Counts stay with the mode, strength and policy version used when the event occurred. Verified counts completed challenge verifications. Use these counts alongside your own investigation; passing a challenge does not prove a visitor is human.
| Mode | Strength | Policy | Visits | Requests | Allowed | Challenged | Blocked | Errors | Verified |
|---|
History is kept for 30 days and starts after this update. Allowed means the protection gate permitted a request; it does not confirm the origin loaded successfully. An IP may represent several people or a proxy. Country and ISP use your saved ip-api Pro key and can show Unknown while lookup is pending or unavailable.
New domain
Additional DNS records
Apex and enabled www addresses, plus apex NS records, are managed automatically and excluded here. Additional records are DNS-only. Keep mail hostnames directed to your mail server.
Provider keys
Save your verification and IP lookup keys here. Then choose a browser challenge, country rules, or invisible IP risk checks for each domain.
These defaults apply to domains using “Server default”. Named credential profiles stay unchanged. Configured means saved, not verified with the provider. Secret keys are never displayed after saving.
Provider keys changed in another session. Your edits have been kept. Choose Reload keys to review the saved settings before trying again.