DDoS protection

In a DDoS attack (Distributed Denial of Service), thousands of devices send traffic to a single target at the same time, with the sole aim of overloading it. Nothing is broken into and no data is stolen — your site is simply unreachable for as long as the attack lasts. At WWW4, protection against this is included as standard in every hosting plan.

There is nothing to configure and nothing to order on top. Below you can read how it works and — just as important — what it does not protect against.

How the protection works

1

Traffic is monitored

Incoming traffic to our infrastructure is continuously monitored for patterns that point to an attack.

2

Abnormal traffic is filtered

Once an attack is recognised, the malicious traffic is stopped at network level before it reaches your site.

3

Your visitors notice nothing

Genuine traffic keeps flowing. The aim is not to stop the attack — nobody can do that — but to keep your site reachable.

This happens on the infrastructure itself, not inside your website. So there is no plugin to install and nothing that breaks when you update your CMS.

What it does and does not cover

DDoS protection is not general security. It keeps your site reachable during an overload attack, but it is no substitute for properly maintaining your website itself.

Covered

  • Volumetric attacks that try to clog up your connection
  • Attacks at network and protocol level
  • Protection of the entire infrastructure, not a single site
  • Active without you having to configure or order anything

Not covered

  • A break-in through an outdated plugin or a weak password
  • Malware or an infected file within your own website
  • Data leaks caused by a flaw in your application
  • Spam or abuse of your forms

For that second list, ordinary hygiene applies: keep your CMS and plugins up to date, use strong passwords with two-step verification, and make sure there is a working backup for when things do go wrong.

Backup & recovery SSL certificates

Do you think you are under attack?

A slow or unreachable site is not automatically an attack — a heavy plugin, a search engine crawling too fast or a spike after a news item all look the same. Contact us with the time and what you are seeing; we will review the server logs and can determine where it is coming from.

Contact support Service status

Frequently asked questions about DDoS protection

In a DDoS attack (Distributed Denial of Service), thousands of devices send traffic to a single target at the same time with the sole aim of overloading it. Nothing is broken into and no data is stolen — your site is simply unreachable for as long as the attack lasts.
Yes, with every hosting package. You do not need to order anything extra, configure anything or install a plugin: the protection works at network level, not inside your website.
Against intrusion via an outdated plugin or a weak password, against malware in your own website, against data leaks caused by a flaw in your application, and against spam via your forms. DDoS protection keeps your site reachable during an overload attack; it does not replace good maintenance.
Under normal use, nothing. The goal is that genuine traffic simply passes through while malicious traffic is stopped before it reaches your site.
Not necessarily. A heavy plugin, a search engine crawling too fast or a visitor spike after a news item produce the same picture. Contact us with the time and what you are seeing; we will look into the server logs with you and can determine where it is coming from.
No, the filtering happens automatically on our infrastructure. Do let us know when you see something unusual, so we can take a targeted look.
Keep your CMS, theme and plugins up to date, use strong passwords with two-factor authentication, do not give users more rights than necessary, and make sure there is a working backup. Most incidents we see involve sites that had not been updated for months.
Trust Guard Security Scanned
Call us
Send an email