DDoS attack protection
DDoS protection works from the first minute on every plan - no separate fee and no request needed. Traffic is filtered before it reaches your site.
We do not show third-party attack statistics. When we have our own figures worth showing, they will be here.
Is it a DDoS attack, or is the site simply slow?
The two are easy to tell apart once you know what to look for. Compare the columns - in most cases it is not an attack.
- It stopped suddenly, within minutes, without you changing anything
- The site does not open at all - it is not merely slow
- The hosting panel is unresponsive too, not just the site
- It opens over mobile data but not from the office - or the other way round
- It comes in waves: works, stops, works again
- It opens, but slowly - it is not down
- It has been slow for days, not since the last hour
- It started after you installed a new plugin or updated something
- Only the admin area is slow, the site itself is fine
- Everyone sees it equally slow, from every network
Where the attack stops, layer by layer
"Multi-layered protection" says nothing on its own. Here is what gets dropped at each of the four steps and how much traffic is left after it.
How an attack unfolds, step by step
An example scenario minute by minute - what happens and who does what.

How far DDoS protection goes and what is left for you
On the left - how far our protection goes. On the right - what you need to do, which is almost nothing.
Up to 500 Gbit we absorb the attack ourselves. Anything larger is stopped together with the internet carrier - we almost always manage, but we do not put it in a contract as a guarantee.
When a thousand addresses behave exactly like customers, separating the real ones from the fake ones takes time. During those minutes the site may slow down, but it stays reachable.
Protection stops traffic. It does not fix an outdated plugin or a weak password - if someone gets in through those, that is a different problem. We help with it too, but by other means.
If it affects the other customers on the same server, we will give you a new address. We tell you in advance and move everything for you.
The protection is on and working. No button, no setting, nothing to miss.
You do not need to know whether it is an attack. Just say “it does not open” and we will see what it is.
That is not about attacks, it is about break-ins. The two get confused, but they are different things.
Which sites most often become a DDoS target
Attacks are not random. Here are the four kinds of sites that see them most often, and why.
Black Friday, Christmas, sales. Sometimes the attack comes from a competitor, sometimes with a demand for money to stop it.
After a sharp article or report. Usually short and from a single source.
Forums and game servers. Attacks here are the most frequent and the most persistent, because the attacker is often a player.
Applications, exams, tickets. The attack comes on exactly the day the site must work.
Frequently asked questions about DDoS protection
The eight things customers ask most often, answered briefly.
How much does DDoS protection cost?
Nothing. It is included in every plan, from the cheapest one up. You do not order it separately, you do not request it, and there is no fee when an attack happens.
Will you take my site offline during an attack?
No. Some hosts suspend the service to protect their other customers - for us that is the last resort. If a very long attack gets that far, we tell you in advance and offer another address.
How will I know my site has been attacked?
Usually you will not - that is exactly the point. If the attack was large or long, we write to you. On managed services it also goes into the monthly report.
Do I need to configure anything?
No. There is no switch and no setting - protection works from the first minute. If your site has a quirk, for example many requests from one address for a normal reason, tell us and we will note it.
Will the protection slow my site down?
In normal operation, no. The check happens at network level and adds no measurable time. During an attack there can be brief delays while the filter is being tuned.
Can you block real visitors?
Rarely, and usually when an attack imitates real people. That is why we slow down first and block second: a real visitor waits two seconds, a machine gives up.
Does it also protect against hacking?
No, that is a different thing. DDoS protection stops traffic, while hacking comes through a hole in a plugin or a weak password. We watch for that too, but with other means - the two should not be confused.
Does it work for email and the other services too?
Yes. The protection sits at network level, so it covers everything on the address - site, email, database, application. It is not an add-on in front of the site only.
Your site will not open?
You do not need to know whether it is an attack. Just write “it does not open” and we will see what it is — at any hour.