Solution

DDoS-protected VPS hosting with always-on scrubbing

Cutter 8 · $34/moClipper 16 · $92/mo
Short answer

DDoS protection has to be always-on and upstream of your instance to be useful — mitigation that activates after an attack starts has already let you go down. OnionVPS includes up to 12 Tbps of L3/L4 edge scrubbing at every tier, with optional L7 filtering. The most-attacked workloads are game servers, and they are exactly the ones sold "protection" as an upgrade elsewhere.

What you need

Specification floor for ddos-protected hosting
ResourceWhat you actually need
MitigationAlways-on L3/L4 at the edge, not triggered on detection
CapacityHeadroom measured in terabits, not gigabits
L7Optional application-layer filtering for HTTP floods
BehaviourFiltering, not null-routing — null-routing is the attacker winning

Recommended plans

Cutter

Cutter 8

$ 34 /month
vCPU
4 × dedicated
RAM
8 GB
Storage
160 GB NVMe SSD
Transfer
10 TB
IPv4 / IPv6
1 / /64 routed
Configure
Clipper

Clipper 16

$ 92 /month
vCPU
8 × dedicated
RAM
16 GB
Storage
400 GB NVMe Gen4 SSD
Transfer
30 TB
IPv4 / IPv6
1 / /64 routed
Configure
Clipper

Clipper 32

$ 174 /month
vCPU
12 × dedicated
RAM
32 GB
Storage
800 GB NVMe Gen4 SSD
Transfer
40 TB
IPv4 / IPv6
1 / /64 routed
Configure

Recommended locations

Location is usually the decision that matters most for this workload — either because latency dominates, or because jurisdiction does.

Why OnionVPS for this

  • Up to 12 Tbps of scrubbing capacity included at every tier, including the $4 plan.
  • We filter rather than null-route: your IP stays reachable through an attack.
  • Game-aware profiles for the UDP protocols that generic filters mishandle.
  • No overage billing for attack traffic — you are not charged for someone else's packets.

How to set it up

  1. Deploy in a scrubbing-enabled region

    Every core region carries the full filtering stack.

  2. Never publish your origin IP

    Most successful attacks start with an origin leak, not a clever technique.

  3. Add L7 filtering if you serve HTTP

    Layer 7 floods look like traffic, so they need a different filter.

  4. Rate-limit at the application too

    Edge scrubbing stops volume; your application must stop expensive requests.

  5. Have a runbook

    Know who to contact and what to change before the first attack, not during it.

Frequently asked questions

Is DDoS protection included or extra?

Always-on L3/L4 scrubbing is included at every tier, including the $4 Skiff 1. Only application-layer L7 filtering is a paid add-on.

Will you null-route my IP during an attack?

Filtering comes first — null-routing means the attacker achieved their goal. We null-route only when an attack exceeds what the edge can absorb without harming other customers, and we tell you when we do.

Does DDoS protection add latency?

A fraction of a millisecond in normal operation. Traffic passes through the scrubbing layer continuously rather than being diverted when an attack begins, so there is no failover spike either.