How screening works
Last updated 2 October 2026
This page documents, in plain English, everything that decides whether a request to squishes.shop is served — the lists it is checked against, the test you are sometimes asked to pass, how fast you may click, and what a ban means. It is written for the person who just got blocked and wants to know why, and it is deliberately specific. Using a VPN here is allowed.
- The order things happen
- The lists
- The check
- Rate limits
- Bans
- Device identity
- Cloudflare
- What is recorded
- If you are blocked
- Reporting a flaw
1. The order things happen
Every request walks the same ladder, and the first rung that says no is the one that answers. Nothing further down ever runs.
- Is this address banned? If yes,
403, and that is the end of it. - Is this address on a published abuse list? If yes,
403with a line naming your address and the list that matched. - Is it a verified search engine crawler? If yes, served, no check, no limit beyond politeness. Verified means a reverse lookup of the address resolves back to the engine its User-Agent claims to be — a crawler name on an unrelated address is a script pretending.
- Does it read as a VPN, proxy, Tor exit or datacentre? If yes, you get the check once. Pass it and you are through for 24 hours.
- How fast is this address going? Too fast for its lane gets
429and a cooldown. - Otherwise the page is served.
Assets — stylesheets, scripts, images, the game files themselves — short-circuit near the top on purpose. A page that loads sixty files is one visit, not sixty, and counting them as sixty is how a person clicking around gets mistaken for a flood.
2. The lists
Addresses are checked against 20 public blocklists published by other people, refreshed every six hours and held in memory as sorted ranges — about 2.6 million of them. A lookup is a binary search and takes well under a microsecond, so this costs you nothing in page load time.
Each list sits in one of three tiers, and the tier decides the answer:
| Tier | Answer | Lists |
|---|---|---|
| Malicious | Refused | Spamhaus DROP, FireHOL level 1, FireHOL level 2, FireHOL web client, blocklist.de, Emerging Threats (compromised and block), DShield, CINS Army, IPsum, Binary Defense |
| Anonymiser | Checked | FireHOL anonymous, X4B VPN, Tor exit nodes (two sources), SOCKS proxy lists, SSL proxy lists, public proxy lists |
| Datacentre | Checked | X4B datacentre ranges, hosting and VPN ranges |
If an address appears on more than one list, the worst tier wins. Only the malicious tier refuses outright, and only lists that publish evidence of actual attacks are allowed into it. An anonymiser list can never ban you on its own — being on a VPN is not an offence here, and FireHOL's own broadest lists (level 3, the 30-day abusers set) are deliberately excluded because their maintainers warn against blocking on them.
3. The check
When an address reads as anonymised, you get one page with one checkbox on it. Passing it does three things: a Cloudflare Turnstile widget confirms a browser is really driving, a small proof-of-work sum runs in the background so that solving it a thousand times costs something, and your browser reports what it is — screen size, fonts, graphics card, how the page was scrolled.
That last part is scored against what your User-Agent claims. The scoring looks at
the order and capitalisation of your HTTP headers, whether the set of them matches the browser
named, and whether the page behaved like something a person was using. A browser saying it is
Chrome while sending headers Chrome has never sent is the thing being caught.
A pass is bound to your address, signed, and good for 24 hours. It is not a cookie you can copy to a friend; it stops working from a different address.
4. Rate limits
Requests are counted per address in a sliding one-minute window, and separately per kind of request, so that heavy, cheap traffic cannot crowd out the things that matter. The per-minute allowances for a normal home connection:
| Lane | Per minute | What is in it |
|---|---|---|
| Assets | 900 | Stylesheets, scripts, images, game files |
| Pages | 150 | Anything that renders |
| Saves | 60 | Game progress |
| API | 30 | Catalogue, play counts, lookups |
| Writes | 10 | Comments, chat, anything that stores text |
Those numbers are then scaled by what the address looks like: a home connection gets all of it, an unclassified address 75%, a VPN or proxy 35%, something scoring as a bot 12%, and an address already in trouble 5%. No lane ever drops below five requests a minute, however bad the verdict — there is always enough to read the page you are on.
Going over earns a 429 and a cooldown: 20 seconds for a home
connection, up to a minute for a bad verdict. Refreshing the 429 page does not add
time. The cooldown page is deliberately plain — the number, the seconds left, nothing
else — because styling it would mean loading more files from a site that just told you to wait.
Repeated trips do stack, up to a ceiling of two hours, and the stack decays after three quiet hours. But hammering a cooldown is itself an offence: 50 requests inside one minute while you are already waiting out a cooldown is a ban, not a longer cooldown.
5. Bans
A ban is by address, applies to the whole site, and is graded by what was done. The grades and how long each lasts:
| Grade | Lasts | Earned by |
|---|---|---|
| Nuisance | 1 hour | Hammering a cooldown |
| Scraping | 24 hours | Automated crawling of the catalogue |
| Abuse | 7 days | Coming back from a new address to get around a block |
| Attack | 30 days | Probing, forging headers, going at the API |
| Flood | No expiry | Sustained flooding |
Doing it again costs more than doing it once: each repeat inside 30 days moves you one grade up the ladder, and the ladder ends at permanent. Being unbanned clears that history, so you start over from the bottom.
An address on a malicious abuse list is banned with no expiry. That is not a judgement about you personally — it is what being published on Spamhaus DROP or FireHOL level 1 means. It stays until a person takes it off, and if that is your home connection, it is worth knowing: something on your network is being seen attacking other people, and the listing will follow you to other sites too.
Every automatic ban emails the operator a review the moment it is placed, with the address, the verdict, the reason, and the last 50 requests that address made before it was banned. The review can be approved — which lifts the ban — or denied. That is the human in the loop, and it runs on every automatic ban, not just the ones somebody complains about.
6. Device identity
Changing address does not lift a ban. When a browser is asked to pass the check it reports enough about itself — graphics card, screen, fonts, audio stack, processor count — to recognise the same machine again, and a ban is recorded against the machine as well as the address. Come back on a new address and the new address is banned too, for seven days.
Two things limit this, on purpose:
- A shared address is never condemned. If more than four distinct machines were recently seen behind one address — a school, a library, a carrier NAT, a VPN exit — the ban stays on the address alone and no machine is marked. One person's behaviour does not follow everyone who happens to share their exit.
- Only an exact match travels. A rough match — same graphics card, similar screen — is enough to group two visits for counting, but never enough to carry a ban. Office laptops bought on the same day look identical at that level.
What is stored is a hash. The raw measurements are not kept, and nothing about them is sent anywhere else.
7. Cloudflare
Every ban this site places is also written into Cloudflare's IP Access Rules for the account, so the block is enforced at the edge rather than by the site itself — faster for everyone, and applied across every site on the account rather than just this one. Lifting a ban removes the edge rule too.
That mirror is checked every two minutes and repaired if it has drifted, so a rule Cloudflare rejected or somebody removed by hand comes back. The blocklists themselves are not mirrored — 2.6 million ranges is far past any edge rule limit, and the in-memory check already answers in well under a microsecond.
8. What is recorded
For screening to work at all, visiting addresses are written down. What is kept, and for how long, is set out in the Privacy Policy. In short: the address, what the screening decided and why, and — only for an address already under suspicion — the last 50 requests it made, so that a ban review has something to show. Comments are unsigned; nothing is recorded about who wrote what.
You can see the whole verdict on your own address, live, at security.squishes.shop — the tier, the list that matched if one did, the bot and VPN scores, and the reason in one line.
9. If you are blocked
- Look up your address at security.squishes.shop. It tells you the verdict and the reason, which is usually the whole answer.
- If a list matched, the fix is with that list. Spamhaus, FireHOL and the rest all publish a removal process, and getting off them fixes this site and every other site that uses them.
- If you think the block is wrong, say so through the Comment Box on the homepage, quoting the address. A block covers the whole site from that address, so you will need a different connection to send the message.
School and shared networks are usually blocked for something somebody else behind the same address did. That is the common case and there is rarely more to it.
10. Reporting a flaw
If you have found a way around any of this, or a way to make the site hurt somebody, report it through the Comment Box on the homepage and it will be fixed. Please do not test a finding against other people's saves, other people's comments, or the site's availability.
Probing is otherwise not permitted and is handled as described above — see section 3 of the Terms of Service.
See also the Terms of Service and the Privacy Policy, and security.squishes.shop for a live verdict on your own address. Press ESC twice at any time to switch to Google Classroom.