Skip to content
DDoS Protection · All 16 Plans

Filtered before it reaches you — and honest about what that misses.

Volumetric attacks are filtered at the network edge, upstream of your server, on every plan. That handles the floods designed to fill the pipe. It does not handle application-layer attacks, and any host implying otherwise is selling you a false sense of security — so this page draws the line clearly and tells you which side of it you are responsible for.

  • Filtered upstream, not on your box
  • Scoped to your dedicated IP
  • No add-on charge
  • All 56 datacenter countries
Ranges stating DDoS protection

12 plans

NVMe VPS and Cloud VPS and VDS · from $9.95/mo

  • Network filtering on all 16 plans
  • Never billed as an add-on
  • No agent installed on your server
  • Does not cover layer-7 attacks

What Network-Level Mitigation Actually Covers

A volumetric DDoS wins by filling the pipe, not by breaking your software. By the time that traffic reaches your server it has already done its damage, which is why the only place to stop it is upstream — at the network edge, before it gets near your operating system. That filtering applies to every plan here and is not billed as an add-on. What it cannot do is recognise an attack made of individually reasonable-looking requests: a slow flood of expensive page loads, or credential stuffing against a login form. Those look like customers to a network filter. Defending against them is configuration you own, because every plan is unmanaged — and being clear about that division is more useful to you than a bigger promise would be.

  • Covered upstream: volumetric floods, filtered before your server sees them.
  • Scoped to you: your own dedicated IPv4, not a shared address.
  • Not covered: layer-7 attacks, brute force, application abuse.
  • Stated explicitly on: the NVMe VPS and Cloud VPS and VDS ranges.
  • No agent: nothing is installed on your server, root access unaffected.
  • No add-on charge on any plan.

Who Handles What

Five rows. The first two are ours and need nothing from you. The next two are yours and no provider can do them for you on an unmanaged server. The last one is a phone call.

  1. Volumetric floods — handled upstream A UDP or SYN flood aimed at filling the pipe never has to reach your server to hurt you, so filtering it at the network edge is the only thing that works. This happens before the traffic gets anywhere near your operating system, and there is nothing for you to configure. Network
  2. Scoped to your own address Every plan includes a dedicated IPv4 address, so mitigation applies to your IP rather than being shared with unrelated tenants on the same address. An attack on someone else's service is not your outage. Dedicated IPv4 → Network
  3. Application-layer attacks — your job A slow, low-volume flood of expensive HTTP requests, or credential stuffing against your login form, looks like ordinary traffic at the network edge. Rate limiting, a web application firewall and sensible timeouts are the defence, and you configure them. Yours
  4. Brute force on SSH and logins — your job fail2ban, key-only SSH authentication and a firewall that closes what you are not using. The knowledgebase has step-by-step guides for all three; nobody will do it for you, because every plan is unmanaged. What unmanaged means → Yours
  5. When something is clearly wrong If you see traffic you cannot explain, contact support with the details. We can look at it from the network side, which is the view you do not have from inside your server. Contact support → Shared
The uncomfortable truth about “DDoS protected hosting” as a category: most successful attacks against small servers are layer-7, and network-level filtering is not aimed at those. If your application is exposed, the hour you spend on rate limiting and fail2ban will do more for you than any upstream filtering will. That is not a reason to skip the filtering — it is a reason not to treat it as the whole answer.

Which Ranges State DDoS Protection Explicitly

Network filtering applies to every plan. These are the ranges that name it as an included feature in the plan catalogue, which is a different and stronger statement.

DDoS protection status and starting price for each VPS range
Range Network-level filtering Named in plan features Plans From
NVMe VPS Applies Stated 4 $9.95/mo
Cloud VPS Applies Stated 4 $13.95/mo
Classic VPS Applies Not stated 4 $4.95/mo
VDS Applies Stated 4 $24.95/mo
“Not stated” means exactly that — the plan description does not list it, not that the network stops filtering at that plan's boundary. The filtering itself is provided upstream by each datacenter, so what varies in practice is the location rather than the range. What the range changes is whether the protection is written into the plan — and if you want it in writing, that is the NVMe VPS or Cloud VPS or VDS range from $9.95/month, where it is written into the plan rather than inherited from the infrastructure.

DDoS Protection Questions

Network-level filtering on every plan, from $4.95.

Never an add-on charge, never an agent on your server — and if DDoS resilience is why you are here, the NVMe VPS and Cloud VPS and VDS ranges from $9.95/month state it in the plan itself.