Traffic spikes, the site goes down, support lines light up — you are probably facing a DDoS attack. This plan helps you stop the bleeding, get back online, and avoid being taken down again.
Step 1: Confirm it is actually a DDoS
Not every slowdown is an attack. Rule out first:
- Normal traffic peaks (campaigns, sales)
- Application bugs or database locks
- Upstream datacenter or link failures
Telltale sign: traffic from thousands of different IPs at once, arriving as UDP/TCP/SYN floods or as huge volumes of looks-normal requests, is almost certainly a DDoS or CC attack.
If unsure, start with How to Tell If Your Site Is Under a DDoS Attack.
Step 2: Stop the bleeding (within 5 minutes)
- Contact your host / cloud provider: ask for temporary scrubbing or a higher protection threshold; many providers only enable hidden protection during an active attack.
- Turn on CDN and rate limiting: serve static assets from a CDN; add per-IP rate limits and challenges on login and API endpoints.
- Hide your origin IP: if the origin IP is exposed, attackers bypass every protection and hit the source directly. Make sure DNS resolves only to protection nodes.
- Degrade non-critical features: protect checkout and login first; temporarily disable heavy images, video, and optional functions.
Step 3: Onboard professional scrubbing (get back online)
If DIY or basic cloud protection cannot hold, the fastest fix is professional DDoS protection:
- DNS steering: point the domain at protection edge nodes; live in minutes, great for websites and APIs.
- GRE / BGP tunnel: steer an entire IP range into scrubbing centers; ideal for owned racks, hybrid cloud, and non-HTTP protocols.
- Protected hosting: deploy directly; zero operations.
AwayDDoS uses a two-layer scrubbing architecture: edge nodes dilute volumetric floods near the source, scrubbing centers deeply filter CC, SYN Flood, and Botnet, returning only clean traffic — with fixed pricing, no surge fees, and no blackholing during attacks.
Step 4: During and after the attack
- During: keep monitoring; log attack time, peak size, and type for post-incident analysis.
- After: review, confirm the origin IP is hidden and policies are locked in, so you are not hit again right after recovery.
Common mistake
Wait and see; handle it once it gets bigger. The golden window for DDoS is the first 10 to 15 minutes. The later you onboard protection, the bigger the loss.
Summary
Under attack: contact your host, hide the origin, enable CDN and rate limits, then onboard professional scrubbing fast. For real results, see Customer Cases; for choosing a plan, read Free or DIY DDoS Protection vs Professional, or contact us for 7x24 expert help.