New feature

Master Your Email Delivery with the Mail Delivery CenterNew: Mail Delivery Center for smarter email delivery Read more >

Included on every plan

DDoS protection you never have to switch on

Filtering sits in front of every WebGee service, in every location, at no extra cost. There is no add-on to buy, no ticket to raise when an attack starts, and no IP change to push out to your DNS mid-incident.

  • IncludedOn every plan, free
  • Always-onNo activation delay
  • L3 · L4 · L7Layers covered
  • 6Protected locations

The short version

  • Cost

    Included — no add-on, no surcharge

  • Activation

    Always on, nothing to enable

  • Coverage

    Network, protocol, and application layers

  • Scrubbing

    Upstream, before traffic reaches your port

  • Locations

    All six datacenters

  • Your IP

    Stays the same during an attack

What it stops

The attacks that actually take sites down

Most outages are not sophisticated. They are volume, aimed at whatever is cheapest to exhaust — your bandwidth, your connection table, or your PHP workers.

  • Volumetric floods

    UDP floods, ICMP floods, and fragmented-packet attacks that try to fill the pipe before anything reaches your server. Dropped upstream, where there is capacity to absorb them.

  • Protocol attacks

    SYN and ACK floods, and connection-exhaustion attacks that leave your server holding thousands of half-open sockets. Filtered before your connection table fills.

  • Application-layer floods

    HTTP floods and slowloris-style attacks that look like real visitors and cost real CPU. This is the layer where an uncached WordPress page is most expensive to serve.

  • Amplification and reflection

    DNS, NTP, and memcached reflection, where a small forged request returns a very large response aimed at you. Recognised by shape, not just by volume.

  • Multi-vector attacks

    Several of the above at once, rotating as each is blocked. Each vector is mitigated independently, so stopping one does not open another.

  • Low-and-slow traffic

    Attacks deliberately kept under obvious thresholds to avoid tripping a volume alarm. Caught on behaviour rather than on a packets-per-second line in the sand.

How it works

Four steps, none of which involve you

Your service does not change during an attack. The same IP, the same DNS records, the same server — the difference is what never arrives.

  1. Traffic hits the filtering layer first

    Everything bound for your service passes through mitigation on the way in. Because it is always in path, there is no window between an attack starting and protection engaging.

  2. Attack traffic is separated from visitors

    Signature matching catches known attack patterns; behavioural analysis catches the ones that have not been seen before. Both run continuously rather than on a trigger.

  3. The bad traffic is dropped upstream

    Attack packets are discarded on a network built to absorb them, far from your port. Your bandwidth, CPU, and connection table never see them.

  4. Clean traffic continues as normal

    Real visitors reach your site on the same IP they always used. In most incidents the first you hear of it is the report, not the downtime.

Why always-on beats on-demand

Plenty of hosts include mitigation that only routes through scrubbing once an attack is detected. That detection window is precisely when your site is down.

WebGee

Always-on — what you get here

  • Filtering is permanently in the traffic path
  • Zero activation delay — nothing has to be noticed first
  • No routing change, so no propagation wait
  • Your IP never changes mid-incident
  • Included on every plan at no cost

Elsewhere

On-demand — the common alternative

  • Traffic routes normally until an attack is detected
  • Seconds to minutes of impact before mitigation engages
  • Re-routing has to propagate before it helps
  • Some providers move you to a different IP under attack
  • Frequently sold as a paid add-on

Six datacenter locations

Host your site next to the people who read it

Distance is latency you cannot optimise away. Pick the location closest to your audience when you order — or ask us to move an existing site, free, whenever your traffic shifts.

  • Sofia, Bulgaria

    Europe

    Best for: European audiences and EU-resident data

  • Los Angeles, United States

    North America

    Best for: US West Coast, and the shortest US hop to Asia-Pacific

  • Dallas, United States

    North America

    Best for: Balanced latency right across the continental US

  • Singapore, Singapore

    Asia-Pacific

    Best for: Southeast Asia, Australia, and the Indian subcontinent

  • Saudi Arabia

    Middle East

    Best for: Gulf traffic and businesses that need data kept in-Kingdom

  • Cairo, Egypt

    Middle East & North Africa

    Best for: Egypt and North Africa, without a hop through Europe

Every location runs the same stack: LiteSpeed, NVMe storage, free SSL, daily backups, and always-on DDoS filtering.

What this does not cover

DDoS filtering stops floods. It is not a web application firewall, and it will not save you from a problem inside your own application.

  • It is not a WAF

    SQL injection, cross-site scripting, and vulnerable plugins are application problems. Filtering sees a valid request and passes it through, because it is valid.

  • It will not fix brute-force logins

    Credential stuffing against wp-login.php is low volume by design. Rate limiting, two-factor authentication, and the malware scanning already on your plan are the right tools.

  • It cannot help an overloaded application

    If legitimate traffic is what is taking your site down, that is a capacity problem with a happier cause. Talk to us about a bigger plan rather than a bigger shield.

DDoS protection, answered plainly

  • Is DDoS protection really included, or is there a catch?

    It is genuinely included on every plan, in every location, at no extra charge. There is no protected tier and unprotected tier — filtering is part of the network, not a line item.

  • Do I have to enable anything?

    No. There is no switch in the control panel because there is nothing to switch. Protection is in the traffic path from the moment your service is provisioned.

  • Will my IP address change during an attack?

    No. Filtering happens upstream of your service, so your IP, your DNS records, and your certificates all stay exactly as they were.

  • Does filtering slow my site down?

    Not in any way your visitors will notice. Traffic passes through mitigation continuously rather than being diverted when something goes wrong, so there is no re-routing penalty and no sudden change in path when an attack begins.

  • What happens if an attack is larger than the platform can absorb?

    Very large or sustained attacks against a single customer are handled case by case with our team, and larger dedicated mitigation can be arranged for deployments that are repeatedly targeted. Open a ticket and we will size it with you.

  • Does this protect against hacking attempts too?

    Not directly — that is a different job. DDoS filtering stops floods; malware scanning, intrusion prevention, and the firewall tooling included with your plan handle intrusion attempts. The two work alongside each other.

Protection is the default here

Every plan, every location, no add-on and no activation. Choose the hosting that fits and the filtering comes with it.

DDoS Protection Included Free on Every Plan | WebGee