Traffic spikes, the site goes down, support lines light up — you are probably facing a DDoS attack. This plan helps you stop the bleeding, get back online, and avoid being taken down again.

Step 1: Confirm it is actually a DDoS

Not every slowdown is an attack. Rule out first:

  • Normal traffic peaks (campaigns, sales)
  • Application bugs or database locks
  • Upstream datacenter or link failures

Telltale sign: traffic from thousands of different IPs at once, arriving as UDP/TCP/SYN floods or as huge volumes of looks-normal requests, is almost certainly a DDoS or CC attack.

If unsure, start with How to Tell If Your Site Is Under a DDoS Attack.

Step 2: Stop the bleeding (within 5 minutes)

  1. Contact your host / cloud provider: ask for temporary scrubbing or a higher protection threshold; many providers only enable hidden protection during an active attack.
  2. Turn on CDN and rate limiting: serve static assets from a CDN; add per-IP rate limits and challenges on login and API endpoints.
  3. Hide your origin IP: if the origin IP is exposed, attackers bypass every protection and hit the source directly. Make sure DNS resolves only to protection nodes.
  4. Degrade non-critical features: protect checkout and login first; temporarily disable heavy images, video, and optional functions.

Step 3: Onboard professional scrubbing (get back online)

If DIY or basic cloud protection cannot hold, the fastest fix is professional DDoS protection:

  • DNS steering: point the domain at protection edge nodes; live in minutes, great for websites and APIs.
  • GRE / BGP tunnel: steer an entire IP range into scrubbing centers; ideal for owned racks, hybrid cloud, and non-HTTP protocols.
  • Protected hosting: deploy directly; zero operations.

AwayDDoS uses a two-layer scrubbing architecture: edge nodes dilute volumetric floods near the source, scrubbing centers deeply filter CC, SYN Flood, and Botnet, returning only clean traffic — with fixed pricing, no surge fees, and no blackholing during attacks.

Step 4: During and after the attack

  • During: keep monitoring; log attack time, peak size, and type for post-incident analysis.
  • After: review, confirm the origin IP is hidden and policies are locked in, so you are not hit again right after recovery.

Common mistake

Wait and see; handle it once it gets bigger. The golden window for DDoS is the first 10 to 15 minutes. The later you onboard protection, the bigger the loss.

Summary

Under attack: contact your host, hide the origin, enable CDN and rate limits, then onboard professional scrubbing fast. For real results, see Customer Cases; for choosing a plan, read Free or DIY DDoS Protection vs Professional, or contact us for 7x24 expert help.