A comprehensive set of 42 proxy/WAF-level security measures combined with real-time behavioral analytics and statistics. This ready-made solution will help you save more than half of your advertising budget.
an ideal tool against click fraud on your website
1. Stateless-cookie passthrough
2. IP allowlist TTL
3. Self-generated seed + ENV
4. Real Google (CIDR + rDNS + forward-confirm)
5. Real Bing (rDNS + forward-confirm)
6. Service-path exceptions
7. Fake-Google ban
8. Verify2 auto-post + allowlist
9. Safe headers/cache on verify
10. Trust proxy + real client IP
11. GEO-STRICT (US-only)
12. GEO/ASN/ORG/HOSTING cache
13. WHOIS cache (7 days)
14. PTR heuristic for data centers
15. Reputation from ORG/PTR/WHOIS
16. “3 IPs/hour” per fingerprint
17. Empty network identity — log only
18. UA classifier for tools
19. Separation of real search vs. fake
20. Bot score (headers/host/SPF)
21. JS challenge (score 50–79)
22. PoW challenge with dynamic difficulty
23. Anti-replay PoW
24. IP-based rate limiting
25. Network-based rate limiting (/24, /48)
26. Fingerprint-based rate limiting
27. TTL ban + reason
28. Strict Origin/Referer for write methods
29. CORS allowlist + Vary
30. CSRF cookie + header/field
31. Security headers: XFO, XCTO, RP, CSP, PP, COOP/COEP, HSTS*
32. Strict OPTIONS preflight
33. Honeypot (page/fields)
34. Forbidden paths/patterns
35. Method filter (GET/HEAD/POST)
36. IP masking/hashing
37. Log rotation
38. flock writes, safe I/O
39. Data TTL (60 days)
40. Metrics/stat dashboards
41. System status API
42. Fail-safe responses: 403 / Geo-403