01
The more suspicious, the harder the challenge
An ordinary visitor gets a proof-of-work that runs by itself: no click, no
puzzle, and a signed cookie keeps them passed for days. A visit that looks
automated, or that matches a rule you set (a network, a country, a request rate), goes on
to unmask's own behavioral CAPTCHA: built in, with no third-party service,
no site key and nothing sent out. A block happens only where you choose one. The challenge
page carries your logo and speaks the visitor's language.
02
SEO-safe
Googlebot / Bingbot / GPTBot / ClaudeBot and the other search and AI crawlers
pass by default, so you start on the side that never costs you rankings.
Where a vendor publishes its crawler IP ranges, the crawler is recognised by
address, and a borrowed name is challenged like anyone else. 600+ crawler patterns
are built in: one click turns away AI training crawlers while AI search fetches still
pass, and any single crawler can be allowed or challenged on its own.
03
TLS fingerprint (JA4): a new IP does not hide a bot
JA4 is a fingerprint of the client's TLS handshake. It follows the tool (curl, a python
client, a headless browser), not the IP, country, VPN or User-Agent it wears, and unmask
can ban the fingerprint itself, so a new address does not shed the ban.
It is one layer among several: unmask combines it with the network (ASN),
country, request rate, honeypot paths and the shared ban list, and each rule is a few
clicks in the web admin.
04
Native nginx speed, or one container
On nginx, a returning visitor's cookie is checked inside the nginx worker itself: one
in-process check, no subrequest, no extra hop, so it can sit in front of a busy site as is.
For any other server, the gateway container is nginx with the module and the
daemon in one image: one docker run or one compose service in
front of Apache, Node or any HTTP server.
05
Fail open
If unmask stops, nginx keeps serving. Already-passed clients
stay on the cookie fast path — and visitors who haven't passed
yet skip PoW / CAPTCHA entirely and still get the page they asked
for (the site behaves as if unmask wasn't installed).
"Defense degrades, the site stays up" by default —
no more entire-site outages from a bot-mitigation glitch.
06
Self-hosted, your data stays put
Everything runs on your boxes, managed from one web admin: a dashboard,
the log that says why each request was challenged, one-click bans. Challenge verdicts /
cookies / IPs / JA4s / event logs all stay inside your perimeter — no user
behavior leaks to a third-party SaaS. No vendor lock-in.
GDPR-friendly out of the box.