Skip to main content
HostingSeller
Shop plans

Operator's Guide

Hosting with DDoS protection — One client's enemy is every other client's outage

Written for whoever holds a list of client sites and has to explain why one of them being unpopular made the rest of them slow.

Straight answer first

Buy infrastructure where filtering sits at the network edge as ordinary hygiene rather than as an upgrade sold during the incident — DDoS filtering runs in front of every account here, and the unmanaged VPS range carries filtering measured in terabits per second with a 20 Gbps uplink on every hypervisor.

For a reseller the reason is shared fate. Attack traffic aimed at one client arrives on infrastructure that other clients also use, so mitigation is not a per-site feature you sell to the client who needs it. It is the property that decides how many apology emails you write.

Written by the Hosting Seller staff · Checked 24 August 2026

99.9%

Uptime target we hold

24/7

Second line, any hour

Free

SSL on every account

NVMe

Disk under every account

Attack traffic has become a commodity. Rented floods are within anybody's pocket money, which is why perfectly ordinary sites now get hit — a disputed review, a competitor, a school-holiday grudge — and why always-on mitigation stopped being an enterprise line item.

The reseller reading is different from the single-site reading. You are not asking whether your site can survive an attack. You are asking what happens to the other eleven accounts when one of them attracts attention, and what you are going to say to them.

What arrives before you are involved at all

Mitigation at network level means the flood is scrubbed upstream while genuine requests carry on through. The practical effect is that most attacks show up in graphs rather than in downtime, and you find out afterwards rather than during.

That is the arrangement you want, because the alternative is being the person who notices. An operator discovering an attack from a client's phone call has already lost the part of the incident that mattered.

A very large attack can still add latency. The design goal is reachability rather than invisibility, and being honest with clients about that distinction in advance is much easier than explaining it while it is happening.

Shared fate, and how to reduce it

On a shared or reseller arrangement, accounts share infrastructure by definition. Edge filtering is what keeps one client's attention from becoming everybody's outage, and it is the reason this is a supplier property rather than something you can bolt on per client.

Where one client is a genuinely likely target — a forum, a political site, a shop with an aggrieved competitor — the honest answer may be to move that client onto their own resources. The unmanaged VPS range gives them a machine of their own behind the same filtering, with a choice of counter in London or Dallas.

That is also a commercial conversation rather than a technical one. A client who attracts attacks costs more to host, and pricing that into their retainer is more sustainable than absorbing it across the rest of your list.

What you tell the other eleven clients

Prepare the note before you need it. Something short and factual: a specific account was targeted, filtering absorbed it upstream, other accounts were unaffected, here is what we watched. Written calmly in advance, it takes two minutes to send during an incident.

Do not name the targeted client. It is not the other clients' business, it invites speculation, and it teaches everybody on your list that you discuss customers by name.

Follow up afterwards with what changed, even if the answer is nothing. Silence after an incident is read as embarrassment, and embarrassment is read as fault.

Credits, and what you can honestly pass on

Know your own position first. The uptime target here is 99.9%, with a pro-rated credit on any month that falls short through a fault at our end — asked for and applied rather than automatic. It is deliberately described as a target rather than a contractual service level.

Whatever you promise your clients is funded by you, not by that. Promising a service level richer than the one you buy is a decision, not an oversight, and it is worth making it deliberately with a number attached.

The safer commitment for most agencies is a response promise rather than an availability one: you will notice, you will explain, and you will say what changed. Those are things you control, and they are what clients actually remember.

A shield icon standing in for site security and DDoS filtering

Where we stand on this

We provide the filtering being described, so this is a supplier's argument rather than an assessment. The checkable part is what a supplier will say plainly about capacity and about what an attack looks like from the customer's side — ask, and ask everybody else the same question.

Including mitigation rather than selling it during an incident is a commercial position as much as a technical one. Protection sold to somebody mid-attack is not protection; it is leverage.

  • Filtering at the network edge in front of every account
  • Terabit-scale filtering on the unmanaged VPS range
  • A 20 Gbps uplink on every hypervisor
  • A counter in London or Dallas for VPS orders

Why Hosting Seller

On every plan, as standard

Included rather than sold mid-attack

Filtering is ordinary network hygiene here, not an upgrade offered at the moment you have least negotiating power.

Upstream scrubbing

Attack traffic is filtered before it reaches the account, so most incidents appear in graphs rather than in downtime.

A route for the likely target

A client who genuinely attracts attention can move onto their own VPS behind the same filtering rather than sitting beside everybody else.

Capacity stated, not implied

Terabit-scale filtering and a 20 Gbps uplink on the VPS range, which is a figure you can quote rather than a reassurance.

A credit position you can explain

A 99.9% target with a pro-rated credit on a month missed through our fault — described as a target rather than dressed as a contract.

Faults reaching us first

Platform problems are flagged by monitoring rather than by your clients, which decides who is explaining what to whom.

First Steps

From choosing to live

  1. 1

    Write the client note before you need it

    Short, factual, no names: an account was targeted, filtering absorbed it upstream, others were unaffected. Two minutes of preparation saves an hour of improvisation during the incident.

  2. 2

    Identify the likely targets on your list

    Forums, political sites, shops with aggrieved competitors. Those clients cost more to host, and pricing that into their retainer beats absorbing it across everybody else.

  3. 3

    Match your promise to what you actually buy

    Whatever service level you offer clients is funded by you. Promise a response you control — you will notice, explain and report — rather than an availability figure you do not.

In the Box

Packed with every plan

  • Filtering at the network edge in front of every account
  • Mitigation included in the price rather than sold during an incident
  • Terabit-scale filtering on the unmanaged VPS range
  • A 20 Gbps uplink on every hypervisor
  • A choice of London or Dallas for VPS orders
  • A 99.9% uptime target with a pro-rated credit when missed
  • Platform faults flagged by monitoring rather than by clients
  • A route to isolate a client who is a likely target
  • Support reachable at any hour during an incident
  • Daily backups with restores you run yourself

Across the Counter

Things people ask us all the time

Why is DDoS a shared problem on a reseller account?

Because accounts share infrastructure by definition. Traffic aimed at one client arrives on hardware other clients are also using, so mitigation cannot be a per-site feature you sell to whoever needs it. It is a property of the supplier, and it decides how many apology emails you end up writing.

What should I tell my other clients during an attack?

Something short and factual, prepared in advance: an account was targeted, filtering absorbed it upstream, other accounts were unaffected, and here is what we watched. Do not name the targeted client — it invites speculation and teaches everybody that you discuss customers by name.

Should a client who attracts attacks be moved to their own server?

Often yes, and it is a commercial conversation as much as a technical one. Forums, political sites and shops with aggrieved competitors cost more to host. Moving them onto their own VPS behind the same edge filtering isolates the risk, and pricing it into their retainer is more sustainable than spreading it across the rest of your list.

Can I pass a supplier's uptime credit on to my clients?

Only what you actually receive. The target here is 99.9% with a pro-rated credit on a month missed through a fault at our end, applied on request. Anything richer that you promise a client is funded by you. Most agencies do better promising a response they control — notice, explain, report — than an availability figure they do not.

Read next

  • LiteSpeed Hosting

    The caching arrangement that keeps winning benchmarks, judged by what it costs to support across a fleet.

  • Laravel Hosting Plans

    Laravel work for clients, and how much DevOps you are quietly taking on with it.

  • VPS Hosting

    KVM virtual servers with root access, DDoS filtering at the edge and one flat price.

  • Plesk Reseller Hosting

    Reseller accounts on Plesk for teams whose workflow already lives there.

Moving your site to another host? Start with this checklist.

A step-by-step order of work for a move your visitors never spot: which files to copy first, how to carry email across without losing one message, the right moment to repoint DNS, and the two mistakes behind nearly every hour of downtime people ring us about.

One email brings the checklist, then now and again a note about running a site properly. Leave the list whenever you feel like it. Our privacy policy spells out the rest.

Keep one client's problem off everybody else's account.

Edge filtering in front of every account, terabit-scale mitigation on the VPS range, and monitoring that tells us before your clients do.

See VPS Hosting plans