DDoS-Protected VPS Explained — What Filtering Actually Covers

Volumetric L3/L4 filtering rides every plan at no extra fee; L7 floods need your application. Where the platform's job ends and yours starts.
Le corps de l'article est en anglais. L'interface, le catalogue et la caisse sont traduits.
The layers that matter
Attack names are layer names. L3/L4 floods — SYN storms, UDP amplification, ACK abuse — aim at your pipe and your state tables, and upstream scrubbing centers absorb them before a single packet reaches your host. L7 floods — HTTP hammers, slowloris, API abuse — arrive dressed as legitimate requests, and no network filter can separate them from real users without knowing your application. That separation is the whole story: the platform owns the volumetric layer, the application owns everything that looks like traffic.
VPS from $3* (fund $50+), storage 1–5 TB NVMe from $24/mo annual-eff, dedicated with IPMI from $30.80/mo. Crypto invoice, no KYC.
Launch nowWhat is included on every plan
- VPS and Storage: automatic L3/L4 filtering, always on, no toggle, no extra fee.
- Dedicated: the same filtering plus IPMI access, letting a compromised box be reimaged out-of-band.
- Citadel (top dedicated): an L3/L7 scrubber on the 25 Gbps uplink.

Sizing against an attack
- Port speed is your clean-traffic ceiling: unmetered 1 Gbps on entry VPS, 2.5–10 Gbps up the ladder, 1–25 Gbps across the dedicated tiers.
- Carry the stateful defenses in your stack: connection caps, bot scoring, and a CDN in front of HTTP where the surface is web-only.
- Shrink the target — a VPN endpoint or a game server with a community whitelist presents a far narrower face than an open WordPress install.
Is DDoS protection really included, not an upsell?
Yes. L3/L4 filtering ships enabled on every VPS, storage and dedicated SKU, with no per-IP fee and no support ticket to request it. The one upgrade is Citadel's L3/L7 scrubber at the top of the metal ladder.
Will filtering block my legitimate users?
Volumetric scrubbing is statistical and tuned upstream, so ordinary traffic patterns — browsers, APIs, game clients — pass without notice. What it cannot judge is application-shaped abuse: a slowloris or a valid-looking API flood belongs to your rate limiting or a CDN.
Do Tor exits get DDoS protection?
Yes, on the same terms as any server, and exits attract more ambient noise than almost any other workload. Exits are provisioned on request with an abuse contact attached, since the role generates complaints by design.
What happens if an attack still saturates my service?
The filters keep the pipe and state tables alive, but an L7 flood that mimics users can still exhaust your application — check connection limits, add caching, or move HTTP behind a CDN. If the box itself wedges, dedicated IPMI lets you reimage without waiting on a KVM ticket.
Ready to launch?
Build the box — VPS, storage or bare metal — create the password, pay the invoice that follows.