331k guest requests
I am an admin on a tech forum (aviation related) and we have been hit with big DDOS attacks. They totally brought the site down - just like is happening here. If you look in your server log it is immediately obvious. They come from rented botnets from all over the world. Every one is a new IP so traditional measures do not work. The browser agent strings are all valid too, etc. and they come from residential IPs because they are infected remotely controlled private PCs and laptops.
There is no defence apart from
- a
much faster server and bandwidth ($$$)
- Cloudflare, and enable Precursor in the High mode - a new feature, very effective and not visible to real users
CF is free to nonprofit organisations. Not sure if EEVBLOG qualifies because you carry adverts (ours is donation funded) but the bottom paid CF tier is very cheap.
I highly recommend CF.
On ours we also use CF to firewall whole countries, because they generate a lot of attacks and hacking but are not relevant to the forum topic. So we block all of China, Russia, and some others. Traffic from those is 99.999% malicious. EEVBLOG can't do that.
We also firewall some server farms because they host a lot of bot attacks. They are not ISPs and people won't access the forum from their IP ranges (unless reading the forum via a VPN terminating there, which is a tiny minority, and who is legitimate and reads EEVBLOG over a VPN???). Digital Ocean is one. Hetzner in Germany is another big one and if you complain they tell you to get lost. I know someone who blocked AWS and immediately reduced his server load by 95%

but I gather google sometimes use AWS and you
do want SEO. You should also not block Claude like you currently do. Claude is the "new SEO" nowadays.
CF offers about 10k IP ranges to block for free. It is simply amazing.
Forums also do accumulate enemies. Probably less in electronics than in aviation

but still... People who have been banned get extremely angry and want revenge. So you have to deal with all of that, and botnets are cheap to rent these days.
There is no downside to CF. It also gives you free HTTPS certificate so that is one less thing to break when the renewal cron job breaks. You have to enable some pass-throughs in CF for stuff like Paypal if you accept payments that way.