Firewall & Security Hardening

Understanding DDoS Mitigation Services: Safeguarding Your Online Assets

By the Domain India teamPublished 7 min read
Knowledge base article
Contents (5 sections)

A DDoS mitigation service filters attack traffic away from your website or server so real visitors can still get through. Large floods can only be stopped before they reach your server, which is why these services sit in front of it: in the cloud, as hardware in your own network, or both. This page explains the types of service and how to choose one; the full guide covers the attacks themselves and what you can configure on your own server.

For the full guide

Attack types, server-side settings, monitoring and the Indian reporting rules are in our Comprehensive guide to DDoS mitigation. To check whether a traffic spike is an attack, see how to check for DDoS attacks or excessive traffic from specific IPs.

Key takeaways

DDoS mitigation services come in three forms: cloud-based (a CDN or scrubbing network in front of you), on-premises appliances in your own network, and hybrids of the two. For most websites a cloud service or CDN with DDoS protection is the practical choice, because only a large network can absorb a large flood. On Domain India shared hosting the server firewall is managed for you; you can add a CDN in front of your site by changing DNS and open a ticket when you see abusive traffic.

1. Why a service, not just a firewall

DDoS attacks fall into three groups: volumetric floods that fill the network link, protocol attacks that exhaust connection tables, and application-layer (HTTP) floods that exhaust the web server. A firewall on your server runs after the traffic has already used your bandwidth. If the link is full, nothing configured on the server helps. The flood has to be filtered upstream, and that is the job a mitigation service does.

2. The three ways to deploy mitigation

TypeHow it worksBest forWatch out for
Cloud-based (CDN or scrubbing service)Your DNS or network routes traffic through the provider, which filters it and forwards clean requestsWebsites, APIs and most businessesAttackers can bypass it if your server's real IP is known
On-premises applianceHardware in your own network inspects traffic before your serversOrganisations running their own data-centre networkIt cannot absorb a flood larger than your internet link
HybridAn appliance handles smaller attacks locally and hands large floods to a cloud scrubbing serviceLarge networks with their own links and strict latency needsCost and complexity; two systems to maintain

For a website on hosting or a VPS, "cloud-based" in practice means putting a CDN or reverse-proxy service with DDoS protection in front of the site. See complete Cloudflare setup for one widely used example.

3. What a good service does

Always-on filtering
Traffic passes through the service all the time, so there is no switch-over delay when an attack starts.
Layer 7 protection
A web application firewall, rate limits and bot challenges for HTTP floods, which look like normal visitors.
Enough network capacity
The provider's network must be far larger than any flood you expect.
Caching
Cached pages are served from the edge, so an HTTP flood never reaches your server.
Clear reporting
Graphs and logs that show what was blocked and why, so you can tune rules.
Origin protection
A way to accept traffic only from the service, so attackers cannot go around it.

4. How to choose

  1. Start with what you run. A brochure site or a WordPress shop needs a CDN with DDoS protection and caching. An API or an online game server needs protection for its own ports and protocols, which fewer providers offer.
  2. Check what is included. Many CDN plans include protection against network floods at every tier but charge more for advanced WAF rules, bot management or dedicated support.
  3. Hide your origin. Once the service is in place, make sure your server's IP isn't exposed in old DNS records, mail headers or subdomains that bypass the service.
  4. Decide on challenge pages. JavaScript or CAPTCHA challenges stop many bots but add friction and can block legitimate tools and APIs. Use them during an attack rather than all the time.
  5. Write a response plan. Know who changes DNS, who contacts the provider and how you will tell customers, before you need it.
A mitigation service is not the whole answer

Uncached, expensive pages such as search, login and checkout can still be overwhelmed by a small application-layer attack. Cache what you can, rate-limit the expensive URLs and protect login forms as well.

5. On Domain India hosting

Shared hosting (cPanel, DirectAdmin, Webuzo). The server firewall is managed for every account, and on our cPanel servers Imunify360's DOS protection is enabled. You can't change server-level settings, and you don't need to. What you can do:

  • put a CDN or DDoS-filtering service in front of your site by changing your DNS;
  • block abusive IPs for your own site, for example with cPanel's IP Blocker or .htaccess rules;
  • cache your pages and protect login forms;
  • open a ticket with the IPs, URLs and times you saw, so we can check the server firewall for the same traffic.

VPS. Our VPS plans are self-managed, so the firewall, web server limits and monitoring on the server are yours to configure. The VPS plans list DDoS protection as a feature; ask support what it covers for your plan before relying on it for a large attack. The full guide has the server-side settings.

VPS Starter
₹552.65/mo + GST
  • 1 vCPU
  • 2 GB DDR4 RAM
  • 64 GB NVMe SSD Storage
  • 2 TB Monthly Bandwidth
See plan details

The card shows the live price, excluding 18% GST.

What is a DDoS mitigation service?

It is a service that sits in front of your website or network and filters attack traffic, passing only legitimate requests to your server. Cloud-based services and CDNs do this across their own large networks, so floods never reach your server's link.

Is cloud-based or on-premises DDoS protection better?

For websites, APIs and most businesses, cloud-based protection is the practical choice because only a large network can absorb a large flood. On-premises appliances suit organisations running their own networks, and are usually combined with a cloud service in a hybrid setup.

Can a firewall on my server stop a DDoS attack?

Only a small one. Server firewall rules run after the traffic has used your bandwidth, so a flood that fills the network link must be filtered upstream by the provider, a CDN or a scrubbing service.

Does a CDN protect my site from DDoS attacks?

A CDN with DDoS protection absorbs floods across its network and serves cached pages, which protects most websites well. It only works if attackers cannot reach your server's real IP address directly.

What can I do about a DDoS attack on Domain India shared hosting?

Put a CDN in front of the site by changing DNS, block abusive IPs for your site with cPanel's IP Blocker or .htaccess, cache your pages, and open a support ticket with the IPs, URLs and times. The server firewall itself is managed by Domain India.

Ready to protect your site? Read the full DDoS mitigation guide, check your traffic with these steps, or open a support ticket with the IPs and times you found.

Seeing traffic you can't explain?

Send us the IPs, URLs and times, and we'll check the server-level firewall for the same traffic.

Open a support ticket

Ready when you are

Get VPS from ₹552.65/mo + GST

See plans

Was this article helpful?

Your answer helps us decide what to improve next.

Still need help? Open a support ticket and our team will reply.

Prefer an app? Add this site to your home screen.Get the app
DDoS Mitigation Services Explained: Cloud, On-Prem, Hybrid