+359 893 560 371 Support 24/7 · sales 9:00–18:00 All services operational
Included in every plan - nothing to order

DDoS attack protection

DDoS protection works from the first minute on every plan - no separate fee and no request needed. Traffic is filtered before it reaches your site.

Up to 500 Gbit of capacityNo fee during an attackWe do not take your site offline
What happens during an attack
Traffic passes through a filterEvery request is checked before it reaches the server. An ordinary visitor notices nothing.
Detection is automaticRules adjust on the fly - we do not wait for someone to notice that something is wrong.
Your site stays onlineWe do not take it down or pull it off the network to relieve the server.
An attack is never chargedHowever large it is and however long it lasts, you do not get a bill for it.

We do not show third-party attack statistics. When we have our own figures worth showing, they will be here.

Is it a DDoS attack, or is the site simply slow?

The two are easy to tell apart once you know what to look for. Compare the columns - in most cases it is not an attack.

Signs of an attack
  • It stopped suddenly, within minutes, without you changing anything
  • The site does not open at all - it is not merely slow
  • The hosting panel is unresponsive too, not just the site
  • It opens over mobile data but not from the office - or the other way round
  • It comes in waves: works, stops, works again
What we do: the filter engages by itself and we are already working on the attack. You do not need to write - but if you want to know exactly what is going on, write and we will tell you.
Signs that it is simply slow
  • It opens, but slowly - it is not down
  • It has been slow for days, not since the last hour
  • It started after you installed a new plugin or updated something
  • Only the admin area is slow, the site itself is fine
  • Everyone sees it equally slow, from every network
What we do: write to us and we check where the time goes - database, plugin, cache or disk. We tell you what we found and how it gets fixed.

Where the attack stops, layer by layer

"Multi-layered protection" says nothing on its own. Here is what gets dropped at each of the four steps and how much traffic is left after it.

An attack passes through four filters before it reaches your site
1At the internet carrierMost fake traffic is stopped inside the large network before it even reaches us. This is the coarsest sieve and it removes the most.−90 %removed
2At the edge of our networkHere we drop requests from addresses that do not exist and those with plainly wrong data. The rule list is updated every day.−8 %removed
3Right in front of the serverWe look at behaviour: whether one address sends hundreds of requests a second, whether it asks for the same thing over and over, whether it does something a real visitor would not.−1,7 %removed
4Inside the siteThe little that is left is served from cache - ready-made pages, without asking the database. That is why the site does not slow down.0,3 %get through
0,3 % of the attack traffic reaches your server - and it handles that without slowing down.

How an attack unfolds, step by step

An example scenario minute by minute - what happens and who does what.

Example scenario
0 secTraffic jumps to many times the usual levelWithin about ten seconds, from thousands of different addresses at once.
+18 secThe network recognises the attack and starts filteringAutomatically, within about twenty seconds. Nobody switches it on by hand.
+6 minThe attack grows and changes shapeIt is no longer only volume - requests to the site search start coming in too.
+8 minThe engineer on duty adds a rule for searchSearch puts the heaviest load on the database, so it is limited first.
+41 minThe attack stops on its ownThat is how most of them end - when nothing is achieved, the attacker gives up.
next morningThe owner learns about it from the reportUntil then they noticed nothing, because the site kept working throughout.
The site keeps working throughout. Orders go through even at the peak of the attack - that is the point of everything described above.

How far DDoS protection goes and what is left for you

On the left - how far our protection goes. On the right - what you need to do, which is almost nothing.

The limits of the protection
Above 500 Gbit it no longer depends on us alone

Up to 500 Gbit we absorb the attack ourselves. Anything larger is stopped together with the internet carrier - we almost always manage, but we do not put it in a contract as a guarantee.

An attack that looks like real people takes longer to catch

When a thousand addresses behave exactly like customers, separating the real ones from the fake ones takes time. During those minutes the site may slow down, but it stays reachable.

We do not protect against a break-in through your own site

Protection stops traffic. It does not fix an outdated plugin or a weak password - if someone gets in through those, that is a different problem. We help with it too, but by other means.

If an attack lasts for days, we may change the address

If it affects the other customers on the same server, we will give you a new address. We tell you in advance and move everything for you.

What you need to doUsually nothing. But it is worth saying plainly, rather than leaving you to hunt for settings.
Nothing

The protection is on and working. No button, no setting, nothing to miss.

Write to us if the site stops

You do not need to know whether it is an attack. Just say “it does not open” and we will see what it is.

Keep your plugins updated

That is not about attacks, it is about break-ins. The two get confused, but they are different things.

Which sites most often become a DDoS target

Attacks are not random. Here are the four kinds of sites that see them most often, and why.

Online shops in peak season

Black Friday, Christmas, sales. Sometimes the attack comes from a competitor, sometimes with a demand for money to stop it.

News sites

After a sharp article or report. Usually short and from a single source.

Game servers and communities

Forums and game servers. Attacks here are the most frequent and the most persistent, because the attacker is often a player.

Sites with a registration deadline

Applications, exams, tickets. The attack comes on exactly the day the site must work.

Frequently asked questions about DDoS protection

The eight things customers ask most often, answered briefly.

How much does DDoS protection cost?

Nothing. It is included in every plan, from the cheapest one up. You do not order it separately, you do not request it, and there is no fee when an attack happens.

Will you take my site offline during an attack?

No. Some hosts suspend the service to protect their other customers - for us that is the last resort. If a very long attack gets that far, we tell you in advance and offer another address.

How will I know my site has been attacked?

Usually you will not - that is exactly the point. If the attack was large or long, we write to you. On managed services it also goes into the monthly report.

Do I need to configure anything?

No. There is no switch and no setting - protection works from the first minute. If your site has a quirk, for example many requests from one address for a normal reason, tell us and we will note it.

Will the protection slow my site down?

In normal operation, no. The check happens at network level and adds no measurable time. During an attack there can be brief delays while the filter is being tuned.

Can you block real visitors?

Rarely, and usually when an attack imitates real people. That is why we slow down first and block second: a real visitor waits two seconds, a machine gives up.

Does it also protect against hacking?

No, that is a different thing. DDoS protection stops traffic, while hacking comes through a hole in a plugin or a weak password. We watch for that too, but with other means - the two should not be confused.

Does it work for email and the other services too?

Yes. The protection sits at network level, so it covers everything on the address - site, email, database, application. It is not an add-on in front of the site only.

Your site will not open?

You do not need to know whether it is an attack. Just write “it does not open” and we will see what it is — at any hour.

AI assistantinstant answers, 24/7