Every host claims DDoS protection. The useful distinction is where the scrubbing happens, how large an attack can be absorbed before the customer is affected, and how quickly the network can null-route or divert when the automated systems are not enough.
What actually protects a customer
- Capacity and filtering at the edge, before the traffic reaches the customer’s VPS or shared node.
- Anycast or distributed scrubbing that can handle volumetric attacks without saturating a single transit link.
- The ability to null-route a targeted IP quickly when the attack is focused and the customer agrees.
- Upstream relationships that allow the host to request filtering further upstream when needed.
A software firewall on the VPS itself is useful for application-layer noise. It is not a substitute for network-layer capacity.
The tickets that appear during an attack
- “The site is unreachable and I did not change anything.”
- “Only some networks are affected.”
- “Can you null-route this IP while we move the service?”
The quality of the response depends on whether the host can see the attack on its own network telemetry and whether it has the operational ability to act. Hosts that own their routing and have practiced the playbooks close these tickets faster.
Honest limits
No host can absorb an unlimited attack. The difference is the threshold at which the customer is affected and the speed of the response once the threshold is crossed. Clear communication during the event matters as much as the scrubbing capacity.
Written at the desk
ChadBe the first to weigh in.