What “DDoS protected” actually means when you buy hosting
The phrase appears on nearly every hosting page in India and means almost nothing without six specific answers. Here are the six.
Nearly every Indian hosting page carries the phrase. Very few carry a definition. That gap matters most for the people who need protection most — game servers, trading platforms, anything with a competitor who has learned what a booter is.
Here is what to ask before you accept the phrase as a specification.
1. Which prefixes are protected?
Protection is applied to IP space, not to a brand. A provider may protect some of its announced prefixes and not others. The question is not “do you have DDoS protection” but “will the IP you allocate to me sit inside a protected prefix.” Get the answer for your address, not for the network in general.
2. Always-on, or on-demand?
This is the biggest practical difference and it is rarely stated.
Always-on means traffic flows through the filtering path continuously. Attacks are absorbed from the first packet. It costs more to operate.
On-demand means normal traffic takes the direct path, and mitigation is engaged after an attack is detected — either automatically or by a human. There is a window, typically measured in tens of seconds to minutes, during which your service is down.
For a website, an on-demand window is survivable. For a game server, that window is the attack succeeding.
3. Which protocols and layers?
Volumetric protection against UDP floods is the easy, commoditised part. The questions that separate real protection from a badge:
- Is TCP SYN flood mitigation included?
- Is Layer 7 — HTTP request floods, slow-loris, application-level abuse — covered, or only Layers 3 and 4?
- What happens to UDP-based game protocols, which look a great deal like an attack to a naive filter?
A lot of “protected” hosting is Layer 3 and 4 only. If your attacker is sending well-formed HTTP requests, that protection will watch it happen.
4. What happens to legitimate traffic during scrubbing?
Scrubbing is not free. Traffic is diverted through filtering infrastructure, which adds latency and can drop legitimate packets that resemble the attack pattern. Ask what the added latency looks like when mitigation is active, and what the false-positive behaviour is. “We mitigated the attack” and “your users could use the service” are different claims.
5. Is there a threshold above which you get null-routed?
This is the question providers least like answering, and the one that matters most. Many hosts protect up to a certain capacity, and above it they null-route the target IP to protect the rest of the network. That is a rational decision for the provider. From your side it is indistinguishable from a total outage, and it usually lasts hours.
Ask directly: is there a level at which my IP gets dropped, how long does that last, and will I be told?
6. Who actually provides the mitigation?
Most hosting companies do not build their own scrubbing infrastructure. They buy it, from an edge provider, a transit carrier, or a specialist. That is entirely normal — but it means the real answer to “how good is your DDoS protection” is “whose is it, and on what plan.”
What we say, and what we do not
VPSWala infrastructure sits behind a Cloudflare-backed protected edge, on a network with multiple upstream carriers and Indian exchange presence. That is a description of the architecture, and you can verify the routing part yourself on any public BGP tool.
What you will not find anywhere on this site is a mitigation capacity in gigabits, an attack-type guarantee, or an always-on claim applied blanket to every plan. Those are commercial terms. If your workload needs them, ask for them on the quotation, where they are enforceable — and ask the six questions above of every provider you are comparing, including this one.
If you are running something that attracts attention — a game server in particular — settle this before you settle the plan size.
Not sure which size?
Send the stack, get a size.
Tell us the operating system, application stack, current traffic, database size and where it hurts today. You get a sizing recommendation, the matching plan and a price.
Related
Which Indian city should your server actually be in?
Every hosting company claims every city. Here is how to work out which node genuinely serves your users, and how much the answer is worth.