ECH Shield is the next-generation DNS provider with full Encrypted Client Hello support. Stop ISPs and network observers from seeing which sites you visit — even during the TLS handshake.
// How ECH Works
Standard TLS encrypts your data — but leaks which server you're connecting to via the SNI field. ECH encrypts the entire ClientHello message, hiding even the destination hostname.
Network observers can see exactly which website you're visiting.
The real destination is hidden inside the encrypted inner ClientHello.
Browser fetches HTTPS DNS record containing ECH public keys.
Our DNS returns HTTPS records with fresh ECH configurations and HPKE keys.
Browser encrypts the real SNI inside the ClientHello using ECH public key.
Server decrypts inner ClientHello. Full TLS session with zero SNI leakage.
// Core Features
Everything you need to deploy ECH-enabled DNS across your infrastructure.
HTTPS DNS records with ECHConfig, automatic key rotation, and HPKE cipher suite management.
Global anycast network with 300+ PoPs ensures DNS resolution in under 10ms worldwide.
DNS-over-HTTPS, DNS-over-TLS, and DNS-over-QUIC. Your queries are encrypted end-to-end.
Full DNSSEC validation ensures DNS responses haven't been tampered with.
We don't log your queries. Period. Independently audited by third-party security firms.
Real-time malware, phishing, and C2 domain blocking powered by updated threat feeds.
// Secure Proxy
ECH Shield isn't just DNS — it's a full security proxy layer. Our edge network inspects and filters malicious traffic at Layer 7, protecting your origin from application-level attacks before they ever reach your server.
Advanced rate limiting, challenge pages, and behavioral analysis block HTTP floods, slowloris, and application-layer attacks in real time. Handles volumetric attacks up to multi-Tbps.
OWASP Top 10 ruleset, custom WAF rules, bot management, and request inspection. Block SQL injection, XSS, path traversal, and zero-day exploits at the edge.
All traffic is proxied through our encrypted edge. Origin IP stays hidden, TLS is terminated with ECH support, and responses are optimized with caching and compression.
SKT, KT, and LG U+ implement SNI-based filtering to block specific domains. ECH Shield encrypts the SNI field completely, making it impossible for Korean ISPs to identify and block your destination — restoring full access transparently.
// Quick Setup
Point your DNS to ECH Shield and ECH protection activates automatically.
// Pricing
Every organization has different needs. We design a custom plan that fits your scale, traffic, and security requirements.
Custom
ENTERPRISEDedicated infrastructure with full ECH, L7 DDoS protection, WAF, reverse proxy, and Korean ISP bypass — all configured to your exact specifications.
// Trusted By Security Teams
“ECH Shield eliminated the last plaintext metadata leak in our network. The automated ECHConfig key rotation alone is worth switching for.”
“We migrated 200+ domains. Setup was 5 minutes per domain, and ECH negotiated correctly on every endpoint.”
“ECH + DoH + DNSSEC means our entire DNS pipeline is cryptographically verified. This is modern DNS.”
// FAQ
Switch to ECH Shield DNS in under 60 seconds. Free forever for personal use.