Free WAF Checker & Web Application Firewall Detection Tool
Detects which WAF or CDN sits in front of your site from the signatures in a normal HTTPS response: headers like CF-Ray or X-Sucuri-ID, cookies like __cf_bm, and Server or Via banners. No attack payloads, no challenge pages triggered.
- WAF/CDN detection from response headers, cookies and banners
- Names the provider and the signals it matched
- Security headers and TLS graded in the same run

What you get for free
18 core security checks via this tool, passive scans, step-by-step remediation, security score on every result.
What Essential adds from €199/mo
Pentest credits every month, +17 advanced checks, weekly passive scans, email alerts and audit-ready PDFs for SOC 2 / ISO 27001 / PCI.
What this scan checks
- Provider headers (CF-Ray, X-Amz-Cf-Id, X-Sucuri-ID, X-Azure-Ref and more)
- Provider cookies (__cf_bm, incap_ses_, BIGipServer, AWSALB and more)
- Server and Via banners (cloudflare, AkamaiGHost, CloudFront, Vercel)
- Security headers, TLS and cookie settings
- No signature doesn't mean no WAF: providers can be set to strip their headers
- Cannot detect WAF rules, rate limiting, or bot protection mechanisms
- Cannot test challenge pages or active protection features
- A detected provider may only be caching, with no WAF rules enabled
Why WAF checking matters
Verifying your WAF configuration helps ensure your website is properly protected. This tool helps you:
- Identify your edge provider: See which WAF or CDN the response points to, and the signals it was matched on
- Catch a bypassed edge: A site you expect behind a WAF that shows no signature may be served straight from its origin
- Check security headers and TLS: The same scan grades headers, TLS and cookies
For WAF configuration, rule testing and active protection checks, use your WAF management console or a penetration test.
How Barrion verifies this
Barrion loads your site once, like a normal visitor, and reads the response it gets back. No challenge pages are triggered and no attack payloads are sent.
The WAF/CDN check matches that response against known provider signatures: headers such as CF-Ray, X-Amz-Cf-Id, X-Sucuri-ID, X-Iinfo or X-Akamai-*, cookies such as __cf_bm, incap_ses_ or BIGipServer, and Server or Via banners. The result names every provider it matched and the signals behind each one.
It covers Cloudflare, Akamai, Amazon CloudFront, AWS WAF and Elastic Load Balancing, Fastly, Imperva, Sucuri, F5 BIG-IP, Azure Front Door, Google Cloud Load Balancing, Vercel, Netlify and Barracuda. The same run also grades your security headers, TLS and cookies.
A match shows the provider is in the request path. It doesn't show which WAF rules are on, rate-limit thresholds, bot management or whether the WAF blocks or only logs. Check those in your WAF console.
What to do with WAF check results
After checking your WAF protection, use the results to improve your security:
- Provider detected: Confirm in its console that WAF rules are enabled for this domain, not just caching
- None detected but you use one: Check that the hostname's DNS points at the provider, or whether it strips its headers
- Check WAF configuration: Review WAF rules and settings in your WAF platform (Cloudflare, AWS WAF, etc.)
- Review security headers: Ensure security headers are properly configured
- If you have no WAF: Consider adding one if your site handles sensitive data
Note: This tool detects a provider from response signatures only. For WAF rule configuration, rate limiting, bot protection, and active security testing, use your WAF management console or professional security assessments.
Tool-specific questions
What is a Web Application Firewall (WAF)?
Does this tool detect my WAF?
What's the difference between a WAF and a regular firewall?
Do I need a WAF if I have other security controls?
What are challenge pages and why do WAFs use them?
How do I know if my WAF is working correctly?
What should I do if I don't have a WAF?
Can this tool help with WAF configuration?
Is WAF protection required for compliance?
Built for the engineers who already have enough to fix.
Fast results
Comprehensive checks
Step-by-step fixes
More free checks, for the rest of your surface.
Complete Security Scan
Pre-Pentest Security Scan
Security Compliance Checker
Security Headers Test
TLS/SSL Security Checker
Content Security Policy (CSP) Checker
Frequently asked.
What is Barrion?
How safe is Barrion to use for security testing?
What types of security issues does Barrion identify?
What specific security checks does Barrion perform?
Will our auditor or enterprise customer accept the report?
How often does Barrion test my app?
Is Barrion suitable for security testing of all business sizes?
How does Barrion handle data security and privacy during security testing?
What if I'm not satisfied with Barrion's security testing service?
How does Barrion help with SOC 2, ISO 27001, NIS2, and other compliance frameworks?
Anything else? Email contact@barrion.io.