WAF / Firewall Detector
Identify which Web Application Firewall or CDN security layer is protecting a website.
Sign in to run this scan
Free to use — we just ask you to sign in so scans stay fair for everyone.
How it works
This tool sends requests to a site and inspects response headers, cookies, and behavior patterns for fingerprints unique to major WAF and CDN providers like Cloudflare, Sucuri, Akamai, Imperva, and AWS WAF.
Knowing which WAF sits in front of a site helps security researchers understand what protections are already in place, and helps site owners confirm their WAF is actually active after setup — a surprisingly common thing to misconfigure.
Frequently asked questions
Why does this matter if I already know my hosting setup?
It's most useful for verifying a WAF is actually active after configuration changes, or for checking what protection a third-party site (a vendor, a competitor) is running.
Can a WAF be detected 100% of the time?
No — some WAFs are configured to hide their fingerprint, and this tool relies on identifiable response headers and behavior patterns, so a 'no WAF detected' result means none was identifiable, not necessarily none present.
Related tools