How it works
From adding your website to a firewall that blocks, one step at a time. Each step is on your screen with what to do, and nothing changes for your visitors until you change your DNS.
Add your website and the server it runs on
You enter two things: your website's address, and where the site really runs. That second one is either the address your host gave the site (something like myshop.myhost.com) or the server's numeric address. Your web person or your host can tell you which.
Nothing is contacted yet, and nothing changes for your visitors.
Prove the website is yours
Blackwall only handles the traffic of websites whose owner has asked for it. You prove it by adding one DNS record, uploading one small file, or adding one tag to your home page. Each carries a code that belongs to your account alone.
The proof is looked for again every day. If it goes missing, for example when a site is rebuilt, your visitors still reach your site but nothing is inspected until it is back.
Blackwall checks it can reach your server
It asks the server you named for your home page. If the server does not answer, or its certificate is for a different name, you are told exactly that, before anything depends on it.
A server on a private network is refused. Blackwall only forwards to addresses on the public internet.
Preview your site through it
You get a private link that shows your site passing through Blackwall, in your browser only. Click around, send a form, sign in. If something does not work, this is where you find out, with no visitor affected.
Point your DNS at Blackwall
When you choose to go live you are shown the DNS records to set where your domain is managed. If someone else looks after your domain, Blackwall emails them the records, and the ones that were there before so the change can be undone.
Blackwall watches for the change and goes live by itself. The certificate for your site is issued and renewed for you. For the first minutes after the change, some visitors may see a certificate warning while it is issued, so pick a quiet hour.
Your email is not affected.
Watch first
A new site starts in watch mode. Every request reaches your site, and the ones that would have been stopped are listed with what they were trying to do.
Most are attacks. Now and then one is a real visitor: a page editor that saves HTML, or a note that happens to read like a database command. You open it, press "This was a real visitor", and requests like it are let through from then on. The exception is narrow: one rule, on one page, for one field.
Switch to blocking
When the list only shows things you are glad to see stopped, turn blocking on. From then on, an attack gets a short page saying it was stopped, with a reference number, and never reaches your website.
If a customer tells you they were stopped, the reference finds their request.
Lock your server
Blackwall only protects requests that pass through it. If your server still answers anyone who contacts it directly, the firewall can be skipped. Two ways to close that door are shown in the app, and Blackwall checks from outside whether it is closed.
Worth knowing
- What is inspected
- The address, the headers and the first 1 megabyte of what a request sends. Larger uploads pass, with the rest unread.
- What is kept
- Stopped and noted requests, for 30 days: when, from where, which page, what the sender called its software, which rule, and the part that matched. Never cookies, passwords or sign-in tokens. Requests that simply pass are counted, not kept.
- If Blackwall has a problem
- The firewall keeps running on the settings it has even when the rest of the service cannot be reached. Pass-through, one click in the app, stops all inspection and keeps your site up.
- If your own server stops answering
- Visitors see a plain page saying the website is not answering, and you get an email.
Want out again? Leaving is one DNS change
Start free trial