How to Evaluate DDoS Protection on a Dedicated Server

Knowledge blog

TL;DR
- “Strongest DDoS protection” is not a single number. It is default capacity, scalability, detection speed and reporting, together.
- Every dedicated server should ship with DDoS protection included by default, not as a paid add-on you have to remember to enable.
- Ask for the default mitigation capacity in Gbit/s and what happens when an attack exceeds it.
- Detection and mitigation speed matters as much as raw capacity. A slow trigger means real downtime even with a big pipe.
- Get proof: ask if the provider can hand you a mitigation report after an incident.
- Contract terms (fixed pricing, no surprise invoices after an attack) are part of DDoS protection too, not a separate topic.
Why this question is harder than it looks
Buyers searching for “strongest DDoS protection” usually want a single winner. That is not how this works. DDoS defense is a stack: network capacity, scrubbing technology, detection latency, and what the provider does once traffic crosses the threshold.
A provider quoting a huge mitigation number is only useful if that capacity is actually reachable for your server, is switched on by default, and reacts fast enough that your application never drops. So instead of hunting for a ranking, learn what to check. Then apply it to any shortlist you build.
What capacity should be included by default?
This is the first real filter. Some providers treat DDoS protection as a paid extra you have to request and configure. Others include a baseline on every server automatically, with the option to scale it up for larger attacks.
Ask any provider:
- Is DDoS protection on by default, or something I have to activate myself?
- What is the default mitigation capacity, and can it scale if an attack is bigger?
- Does the protection cover both volumetric attacks (raw traffic) and more targeted, protocol-level attacks?
- Is the protection layer specific to dedicated servers, or shared infrastructure built for VPS or shared hosting that may behave differently under load?
Default-on protection matters because attacks do not wait for you to notice them. If protection needs manual activation, the gap between attack start and activation is exactly when you go down.
How fast does it actually react?
Capacity numbers get attention, but detection speed decides your actual downtime. A network that can absorb 1 Tbit/s is not very useful if it takes ten minutes to notice the attack and reroute traffic. Ask providers directly:
- How is malicious traffic detected? Automated, always-on monitoring, or manual escalation?
- What is the typical time between an attack starting and mitigation kicking in?
- Does the provider use dedicated scrubbing technology or a third-party DDoS security layer, and can they name it?
- Is mitigation applied automatically, or does someone need to be paged first?
These answers separate marketing copy from an actual working system.
What proof can you get after an incident?
Anyone can claim strong DDoS protection. Fewer providers can show you what happened during a real attack on your server. A mitigation report, showing attack size, duration and how it was handled, is a good sign the provider actually monitors and logs this rather than just claiming a number on a spec sheet.
Ask:
- Can I request a report after an attack that shows size, duration and mitigation steps?
- Is this report available to any customer, or only above a certain contract tier?
- Does support proactively tell you when your server was under attack, or do you find out from your own monitoring?
What to verify before you sign anything
Use this checklist against any shortlist.
- Default DDoS protection is included on every server, with no manual step to switch it on.
- The default mitigation capacity is stated in Gbit/s, not vague marketing language.
- There is a documented path to scale protection if an attack is larger than the default.
- The detection and mitigation system is described concretely (technology or partner named), not just “advanced protection”.
- You can request an incident report after an attack.
- Pricing for DDoS protection and mitigation is fixed and known in advance, so an attack does not turn into a surprise invoice.
- Support is reachable 24/7 and can tell you what is happening during an incident, not just after.
A fair way to compare providers
Do not compare a single headline Gbit/s number across providers. Compare the whole answer set from the checklist above. A provider with a lower published number but fast automated detection and a scalable response can hold up better in practice than one with a bigger number and slow manual escalation.
Worldstream’s own approach can serve as one reference point for what “included by default” could look like: 20 Gbit/s of DDoS protection standard on every server, scalable, with mitigation capacity above 1 Tbit/s, plus the option to request a mitigation report after an attack. Use that as a baseline to hold any provider to, not as a reason to skip your own due diligence.
What to check next
Before you sign a contract, ask each provider on your list to answer the checklist above in writing. If they cannot answer clearly, that is itself useful information. Strong DDoS protection is less about one impressive number and more about a system that is on by default, reacts fast, and can prove what happened when it mattered.
FAQ
There is no single required number, but the protection should be active by default, not something you need to request. Ask for the exact Gbit/s figure and whether it can scale if an attack exceeds it.