How Our DDoS Protection Works
A technical look at the multi-layer DDoS mitigation protecting every XeroHost server.
DDoS attacks are one of the biggest threats to game servers. Here's how XeroHost protects you — automatically, 24/7.
What is a DDoS attack?
A Distributed Denial of Service (DDoS) attack floods your server with traffic from thousands of sources, making it unreachable for legitimate players.
Game servers are a common target because:
- They're always online and publicly accessible
- Rival communities or griefers want to take them down
- The cost of attacks has dropped dramatically
Our mitigation stack
Layer 3 / 4 — Network filtering
We filter malicious traffic at the network edge before it ever reaches your server. Our upstream providers offer 1+ Tbps of scrubbing capacity.
Common attacks blocked at this layer:
- UDP floods
- SYN floods
- ICMP floods
- Amplification attacks (DNS, NTP, SSDP)
Layer 7 — Application filtering
For game protocols, we deploy custom signatures that understand the game's traffic patterns and drop spoofed or malformed packets.
What you should know
- Protection is automatic — no configuration needed
- Mitigation kicks in within seconds of detecting an attack
- Your server IP remains the same during and after an attack
- We don't rate-limit legitimate traffic
Need help with a specific attack type? Open a ticket from your client portal.