Self-hosted bot challenge for stock nginx, or a gateway container in front of any HTTP server. Proof-of-work first, behavioral CAPTCHA when suspicious; search and AI crawlers pass, verified by IP range. RPM/DEB/APK + Docker.
See the codeThe bot challenge that respects search engines. Proof-of-work first, a CAPTCHA only when it looks automated.
Website: https://unmask.sh/

unmask is a self-hosted bot management gateway for nginx and Apache. It layers signals (the TLS fingerprint (JA4), network (ASN), country, request rate, honeypot paths and a shared ban list) and answers with a challenge that grows with suspicion: a proof-of-work that runs by itself for ordinary visitors, its own behavioral CAPTCHA when a visit looks automated or matches a rule you set, and a block only where you choose one. Search and AI crawlers pass by default, verified by their published IP ranges wherever the vendor publishes them.
subscribe_mode: off to disconnect. Submitting your own reports is opt-in (country is tagged by default — opt out in settings). GDPR by design: the hub keeps reporting installs' addresses only as per-day salted hashes, scrubbed after 30 days.The install guide takes you through either way, step by step: https://unmask.sh/install/
unmask.sh/unmask, is the official nginx image with the module plus the daemon in one container, placed in front of your server (served from unmask.sh, mirrored on GHCR).
→ https://unmask.sh/install/#gatewayEvery package (rpm / deb / apk) is signed; unmask-release installs the public
keys, and the package manager verifies everything from then on. Fingerprints
for bootstrapping trust by hand (cross-check with https://unmask.sh/keys/):
RPM-GPG-KEY-unmask):
C03D D45E 28C4 446F DDC4 8EFC 34A3 20B5 44B2 8158unmask.rsa.pub), SHA-256 of the DER public key:
63:77:6a:f3:57:b7:be:aa:db:2a:83:67:9d:ae:46:42:ac:78:6d:ad:49:95:9b:7c:1f:cb:3d:16:5c:c9:a5:dcOfficial docs: https://unmask.sh/docs/
Choosing a deployment (native module or gateway container), JA4 behind a load balancer, per-server config examples, FAQ.
See CONTRIBUTING.md.
Released. Signed rpm / deb / apk for x86_64 + arm64, the gateway container image, an install wizard, and both ways to deploy (the native nginx module and the gateway container) are shipping. It runs in production on the author's own sites.
Still 0.x: configuration may change between minor versions.
Security reports (see SECURITY.md) get priority response. Bug reports, documentation fixes, and PRs are reviewed regularly.
Self-hosted bot challenge for stock nginx, or a gateway container in front of any HTTP server. Proof-of-work first, behavioral CAPTCHA when suspicious; search and AI crawlers pass, verified by IP range. RPM/DEB/APK + Docker.
See the codeThe bot challenge that respects search engines. Proof-of-work first, a CAPTCHA only when it looks automated.
Website: https://unmask.sh/

unmask is a self-hosted bot management gateway for nginx and Apache. It layers signals (the TLS fingerprint (JA4), network (ASN), country, request rate, honeypot paths and a shared ban list) and answers with a challenge that grows with suspicion: a proof-of-work that runs by itself for ordinary visitors, its own behavioral CAPTCHA when a visit looks automated or matches a rule you set, and a block only where you choose one. Search and AI crawlers pass by default, verified by their published IP ranges wherever the vendor publishes them.
subscribe_mode: off to disconnect. Submitting your own reports is opt-in (country is tagged by default — opt out in settings). GDPR by design: the hub keeps reporting installs' addresses only as per-day salted hashes, scrubbed after 30 days.The install guide takes you through either way, step by step: https://unmask.sh/install/
unmask.sh/unmask, is the official nginx image with the module plus the daemon in one container, placed in front of your server (served from unmask.sh, mirrored on GHCR).
→ https://unmask.sh/install/#gatewayEvery package (rpm / deb / apk) is signed; unmask-release installs the public
keys, and the package manager verifies everything from then on. Fingerprints
for bootstrapping trust by hand (cross-check with https://unmask.sh/keys/):
RPM-GPG-KEY-unmask):
C03D D45E 28C4 446F DDC4 8EFC 34A3 20B5 44B2 8158unmask.rsa.pub), SHA-256 of the DER public key:
63:77:6a:f3:57:b7:be:aa:db:2a:83:67:9d:ae:46:42:ac:78:6d:ad:49:95:9b:7c:1f:cb:3d:16:5c:c9:a5:dcOfficial docs: https://unmask.sh/docs/
Choosing a deployment (native module or gateway container), JA4 behind a load balancer, per-server config examples, FAQ.
See CONTRIBUTING.md.
Released. Signed rpm / deb / apk for x86_64 + arm64, the gateway container image, an install wizard, and both ways to deploy (the native nginx module and the gateway container) are shipping. It runs in production on the author's own sites.
Still 0.x: configuration may change between minor versions.
Security reports (see SECURITY.md) get priority response. Bug reports, documentation fixes, and PRs are reviewed regularly.