The Hidden Limits of “DDoS Protection” Plans
"DDoS protection included" has become a near-universal marketing bullet point across hosting plans, VPS providers, and CDN services, and while the underlying protection is often genuinely real and valuable, the word "included" frequently obscures meaningful limits on exactly what kind of attack, at what scale, actually gets mitigated — gaps that only become apparent, often painfully, during an actual attack that exceeds what the included tier was ever designed to handle.
What a Distributed Denial-of-Service Attack Actually Is
A DDoS attack attempts to overwhelm a target's infrastructure or network capacity with a flood of traffic or requests from many distributed sources simultaneously, aiming to exhaust some finite resource — network bandwidth, server processing capacity, or connection-handling limits — to the point where legitimate traffic can no longer be served at all. Attacks vary enormously in both scale (from a few gigabits per second to attacks exceeding a terabit per second at the largest, most severe end) and technique (some flood raw network bandwidth, others target application-layer resources with seemingly legitimate-looking requests).
The Volumetric vs Application-Layer Distinction That Coverage Often Misses
Most baseline, included DDoS protection is specifically designed and effective against volumetric attacks — simply overwhelming raw network bandwidth with sheer traffic volume — which can be detected and mitigated largely at the network level through traffic scrubbing and filtering, without needing deep, application-specific inspection. Application-layer attacks (like a flood of seemingly legitimate HTTP requests specifically targeting a resource-intensive page or API endpoint) are considerably harder to distinguish from genuine traffic and often require more sophisticated, application-aware mitigation that basic, included DDoS protection tiers frequently don't cover at the same depth, if at all.
The Specific Capacity Ceiling Most Included Plans Carry
Baseline DDoS protection bundled into a standard hosting or VPS plan is typically sized to handle relatively modest, common attack volumes — sufficient for the majority of small-to-medium sites that are unlikely to be targeted by a sophisticated, well-resourced attacker specifically. A genuinely large-scale, sustained volumetric attack, of the kind occasionally deployed against higher-profile targets, can exceed what an included, baseline protection tier is actually provisioned to absorb, at which point a site can still go down despite technically having "DDoS protection included" — the marketing claim wasn't false, but the specific attack simply exceeded the tier's actual designed capacity.
Why the Fine Print on "Unmetered" DDoS Protection Still Has Limits
Some providers advertise DDoS protection as "unmetered" or "unlimited," a claim that, similar to the unmetered bandwidth discussion elsewhere on this blog, describes a billing model rather than an unlimited technical capacity — the underlying network and scrubbing infrastructure still has genuine, finite capacity, and providers generally reserve contractual language allowing them to take additional action (temporary null-routing a severely targeted IP, for instance, as a last resort) if an attack is severe enough to risk affecting other customers sharing the same infrastructure, regardless of what the marketing language for included protection technically promised.
What Higher, Paid Tiers of Protection Actually Add
Dedicated, higher-tier DDoS protection services (offered by specialized providers, and as premium add-ons from major hosting and CDN companies) typically provide meaningfully larger absorption capacity, more sophisticated application-layer attack detection and mitigation, and often a dedicated incident response team actively monitoring and adjusting mitigation in real time during a significant attack, rather than relying purely on automated, generic filtering rules — a genuinely different level of service than what's typically bundled at no extra cost into a standard hosting plan.
What to Actually Ask a Provider Before Assuming Coverage
Rather than taking "DDoS protection included" at face value, it's worth asking a hosting or infrastructure provider directly: what's the actual mitigation capacity of the included tier (in Gbps, if they'll share a specific figure), does the included protection cover application-layer attacks or only volumetric ones, and what happens contractually if an attack exceeds the included tier's capacity — is the site simply taken offline as a protective measure for other customers, or is there an escalation path to additional, paid mitigation capacity in real time during an active incident.
Who Actually Needs to Worry About This
For the large majority of small business and personal sites, baseline included DDoS protection is genuinely adequate, since these sites are unlikely to be specifically targeted by an attacker with the resources to mount an attack exceeding typical baseline capacity. The gap matters considerably more for sites with any characteristic that increases attack likelihood or severity — a controversial or high-visibility public profile, e-commerce operations handling meaningful transaction volume, or any site that has previously been targeted, since a first successful attack often signals to that same or other attackers that a target is vulnerable and worth attacking again.
The Takeaway
"DDoS protection included" is a genuinely real, valuable feature at most hosting providers, but the word "included" frequently describes a specific, bounded capacity tier rather than an unlimited, all-attack-scales guarantee. Understanding the volumetric versus application-layer distinction, and directly asking about actual capacity limits, prevents the unpleasant discovery of a coverage gap in the middle of an actual attack rather than before one occurs.
Tags: attack mitigation, DDoS protection, hosting security