• What is a DDoS attack?

    A DDoS attack is an attempt to knock your server offline by flooding it with traffic. DDoS attacks are usually motivated by harassment or extortion, and they are a real threat for anyone running a website or a game server. Mitigating them is difficult and expensive, so many carriers and hosting companies simply null-route or shut down a customer's server once it becomes a target, in order to protect their other customers. DDoS Shield works with major ISPs around the world to stay connected to high-capacity backbones in Japan and elsewhere. Regular signature updates and carefully tuned L4/L7 protection are what make the service work.
  • How can you offer this so cheaply?

    There are two main reasons: what we believe in, and the financial headroom we now have. <1. What we believe in> Around 2022 we were hit by a large DDoS attack ourselves, which took our service down and cost us a great deal of money. We do not want anyone else to go through that, and we believe that making affordable, easy-to-use DDoS protection widely available is a first step towards a safer internet. That is why we keep the price low. <2. Financial headroom> Several years in, we serve customers ranging from individuals to listed companies. Now that the business is on a stable footing, we are able to deal directly with the large international companies that own the network infrastructure. Those companies usually expect a customer to buy — at considerable cost — far more capacity than a single small business could ever use. For most small companies, and certainly for individuals, that is simply out of budget. And even if you could buy it directly, you would still need the in-house expertise to build and maintain the fine-grained L4/L7 protection on top. DDoS Shield uses its established position to sign those large contracts and then divide the capacity into the size each customer actually needs. That keeps your costs low while still covering our staff, our systems and our research into new mitigations. We also automate things like allocating extra backbone capacity to a customer for as long as a large attack lasts. The result is strong protection at a low price for you, and a stable, sustainable business for us — not charity, but a model that genuinely works for both sides. That is why the price stays low.
  • How can traffic be "unlimited"?

    Traffic is unlimited on the Normal, Advance and Premium plans. That said, bandwidth and network capacity are finite resources. To keep the network fair for everyone, the following limit applies. • If monthly traffic exceeds 5 TB → Throughput is limited to 100 Mbps until the end of the month. The B2B plan has no such limit. Even if throughput is limited, the amount of traffic itself remains unlimited. If you expect to exceed 5 TB a month, please consider the B2B plan. Only outbound (upload) traffic counts towards this figure. Inbound (download) traffic is unlimited and free on every plan.
  • Can I cancel at any time?

    Yes. You can cancel whenever you like. There is no need to contact us — you can do it entirely on your own. Cancellation is a single button in the dashboard, available 24/7. Log in to the dashboard → Billing → press the red "Cancel" button, and it takes effect immediately. (On a dedicated node, press "Other features" to reveal the "Billing" button.) In case an incident prevents you from logging in, you can also cancel from this link: https://billing.stripe.com/p/login/5kAbLggxFggy3oQ144 Cancelling never triggers a charge — there are no cancellation or early-termination fees. To change your payment method, use the blue "Change payment method" button under "Billing"; again, no need to contact us.
  • How do I cancel the service?

    - How to cancel Press the red "Cancel" button under "Billing" in the dashboard. The "Manage billing / cancel" link at the bottom of this site does the same thing. Please note that cancelling takes effect immediately, even if there are days left on your current subscription period. After cancelling you can delete your card details yourself. If you intend to request a refund, do not delete them first — we cannot process a refund once the card is removed.
  • Can I use the service if I cannot forward ports?

    • Normal / Advance → No. • Premium / B2B → Yes. You will need to install the Tailscale software and create an account (both are free). Step-by-step instructions are in the help centre, which becomes available once you sign up.
  • How do I measure latency (ping)?

    Run the ping commands below from your own computer or server to measure the latency to a DDoS Shield node. 1. Shared node (Oracle) ping common.shield.broccoli.network 2. Dedicated node (Akamai) ping 23.192.45.248 Shared nodes are more affected by congestion, so if latency matters most to you we recommend the Premium or B2B plan with its dedicated node.
  • Is there a dashboard or customer portal?

    Yes. The dashboard lets you register and edit protected servers and adjust the details of the mitigation system yourself. For MAF there is also a setting for the MOTD shown while your server is offline — the screen is tailored to Minecraft. Shared nodes use the URL shield.brcl.me, where you can add, edit and delete servers. Dedicated nodes (Premium and B2B) get their own dashboard at a subdomain of the form (node name).brcl.me. There you hold administrative rights over the whole node, which unlocks detailed mitigation settings, real-time traffic graphs, Tailscale connectivity, user management, bulk management of every endpoint on the node, and more.
  • Can I see the real IP address of my end users?

    Yes. Even though traffic passes through DDoS Shield, your origin server can still see each visitor's real public IP address. Proxy Protocol is used to restore the original address. For applications that do not support Proxy Protocol, the B2B plan can include dedicated software (for Linux and Windows) that restores the Proxy Protocol header at the kernel / OS level.
  • Do you support Minecraft servers?

    Yes. Minecraft traffic can use our advanced protection, including layer 7. Bot login floods, forged handshake responses and most other attacks are blocked automatically on the network. Our own MAF (Minecraft Application Filter) can also block any incoming traffic that is not Minecraft, and lets you customise the MOTD and kick message shown while the server is offline.
  • What does support look like?

    Enquiries are handled by a team of operators. As a rule, a human operator — not an AI — replies within two business days. If your enquiry falls over a weekend or public holiday, please expect a reply from the next business day onwards. Chat support is available through our Discord community before you sign up, and through the "Contact" button in the dashboard afterwards. Contacting us from the dashboard authenticates you automatically, which makes everything quicker. You are welcome to email us as well. If you are a customer, please write from the same address you used at checkout so that we can verify your identity. * Since November 2025 every chat conversation ends with a short satisfaction survey, where you can rate the operator's response as either "good" or "disappointing". The results are aggregated anonymously and are an important metric for our team.
  • Is anything prohibited?

    The service may not be used for any of the following. - Distributing computer viruses - Attempting malicious attacks - Anything else that breaks Japanese law These are prohibited without exception, including for educational or research purposes. If we receive a request from law enforcement (limited to national authorities, courts and the police), we may disclose your information in accordance with Japanese law. * We do so only after our legal team has confirmed that the request has a proper legal basis and comes from a legitimate body.
  • Do you publish a list of the IP addresses DDoS Shield uses?

    Yes. There are source IP addresses that DDoS Shield uses when it connects to your endpoint, which you may need for firewall rules or other access controls. Note that these are different from the dedicated IP addresses assigned to each customer. We send the list of outbound IP addresses by email. On a dedicated node, the primary IP is used as the source address. Depending on when you signed up, we may describe it as the "primary" or the "first" address. If you are unsure, please get in touch.
  • Do you support IPv6?

    IPv6 addresses are not available on the Normal and Advance plans, but they are available on Premium and B2B. * Since July 2026, IPv6 (both dedicated IPs and destinations) is officially supported on the Premium and B2B plans.
  • Can I change plan without cancelling?

    Of course. Press the "Change plan" button under Support in the dashboard and fill in the form. When moving to a higher plan, we settle the difference pro rata. Upgrading keeps your existing endpoint configuration, so there is nothing to set up again.
  • May I resell DDoS Shield?

    Reselling is not permitted on the three main plans (Normal, Advance and Premium). On the B2B plan, reselling is permitted unconditionally. Together with the white-label feature on the B2B plan, you can hide the DDoS Shield name entirely and offer DDoS protection to your own customers under your own brand.
  • I cancelled in the past. Can I sign up again?

    It depends on why the contract ended, but in principle yes. • If you cancelled yourself You are welcome to sign up again as normal. • If we terminated the contract We are unable to accept a new sign-up.
  • My payment is failing (error messages)

    Here is what to do for the most common payment errors. 1. "Declined due to insufficient funds" For a credit card, check whether you are over your limit; for a debit or prepaid card, check the balance. 2. "Your card was declined" Check that 3-D Secure authentication succeeded, that you are within your limit or have enough balance, and that the card has not been reissued or cancelled. For cards reissued after being lost or stolen, we do not tell the customer that a loss or theft report exists, for security reasons. Occasionally a card issuer temporarily blocks a payment because it looks unusual. In that case the issuer normally contacts you straight away by phone, SMS or app notification — please follow their instructions. 3. "Please try a debit card" This appears after a generic decline on a credit card. Because the decline is generic, the payment usually succeeds once you fix the underlying cause — being over your limit, insufficient balance, or a 3-D Secure problem. There is no need to switch to a debit card. 4. The card works fine elsewhere Payments are declined by design if you are using a VPN or proxy. If you use iCloud Private Relay, turn it off and try again. If the payment still fails, our security system may have blocked the card, or you. * If you use another Broccoli Network service (for example Broccoli Records), your first payment here may be blocked to prevent duplicate contracts. Contact us and we will sort it out individually. For customers whose contract we terminated, all payments are blocked to prevent a new contract. Get in touch and we will look into the error for you.
  • Can I use a card belonging to a family member or friend?

    No. You may only use a card in your own name. That applies to family members too — if the name on the card is not yours, it cannot be used. If you are a minor and need to use a parent's card, please have the parent sign up instead. It is perfectly fine for the parent to hold the contract while you are the one using the service.
  • Are there scheduled reboots or maintenance?

    Shared nodes (Normal and Advance) are rebooted daily at around 4 a.m. Japan time. That may cause a few seconds of downtime or a dropped connection. Dedicated nodes (Premium and B2B) are not rebooted on a schedule. If you want to reboot, use the "Reboot" menu in the dashboard whenever it suits you. When unplanned hardware maintenance is expected to cause downtime, we announce the scheduled time and the expected duration in advance.
  • Is there documentation for the setup?

    Yes. The "Help" page in the dashboard walks through DNS configuration, Proxy Protocol support and everything else you need, with screenshots. If anything is still unclear, please do get in touch.