When your business is under attack, the most terrifying outcome is not the attack itself — it is your protection provider cutting your IP off entirely. That practice is called blackholing.
The irony: technically it is called "protection," but in outcome terms, the attacker has won.
How blackholing works
Blackholing (also called null routing) is brutally simple:
When traffic to an IP exceeds a preset threshold, the ISP or cloud provider drops all traffic destined for that IP at the edge router.
- ✅ The attack traffic is indeed stopped
- ❌ Legitimate user traffic is dropped along with it
- ❌ Your business goes completely offline until the attack ends
From the provider's perspective, this is convenient: it protects other tenants on their network from your attack traffic. From your perspective, it means your provider unilaterally terminated your service.
Why providers do it
Understand the three motives and you can judge whether a provider is trustworthy:
1. Cost control
Scrubbing attack traffic costs real money — scrubbing appliances, bandwidth, and compute. On a shared pool, your attack consumes resources that other customers paid for. Blackholing is the cheapest possible response: one routing command, zero cost.
2. Business model incentives
This is the critical one. If a provider bills by scrubbed traffic volume, its revenue scales with your attack size — but scrubbing a massive attack has high marginal cost, so the overage may actually lose them money. "Blackhole past a certain point" becomes commercially rational.
Conversely: only a provider on a fixed-fee model has an incentive to genuinely scrub your attack clean. No matter how hard you are hit, their revenue is unchanged and their costs are manageable — so the optimal move is to actually stop the attack.
3. Liability avoidance
Some providers write "attacks above a certain scale are not covered" into their terms of service. That clause lets them legally blackhole you at will.
The real cost of blackholing
Let's do the math. Suppose you run an e-commerce business:
| Dimension | Consequence of blackholing |
|---|---|
| Outage | You are down as long as the attack lasts (potentially hours) |
| Revenue | Online sales drop to zero for the entire duration |
| Customer loss | Users will not wait — they buy from a competitor, and often never return |
| Brand damage | "It was down when I needed it" is nearly impossible to undo |
| SEO impact | Prolonged unavailability affects how search engines rate your site |
| Attacker wins | Extortionists see you cave easily and escalate their demands |
Attackers count on this. They know you will be blackholed, so a campaign sized "just above your threshold" is enough to take you offline.
Our position: never blackhole
AwayDDoS operates on an iron rule: no blackholing and no surge pricing during an attack.
Concretely:
- Massive scrubbing capacity — the combined capacity of our global nodes absorbs Tbps-scale floods with no hard cap
- Two-layer cleaning architecture — near-source scrubbing dilutes the peak first, then deep cleaning filters precisely, so capacity and appliances are spent where they matter
- Fixed pricing — costs do not scale with attack volume, which aligns our interests completely with your uptime
- 7×24 expert operations — our security team intervenes and tunes policies during an attack instead of just dropping a blocklist
For you, the practical experience is simple: when an attack happens, your users never even know it happened.
How to spot a blackhole clause during procurement
Ask these four questions and watch how they answer:
- [ ] "What happens if attack traffic exceeds my plan?"
- [ ] "Will pricing increase or require an upgrade during an attack?"
- [ ] "Does your terms of service exclude 'attacks above a certain scale'?"
- [ ] "Will you commit in writing to no blackholing during an attack?"
Vague answers on the second and third questions are a strong signal that blackholing risk exists.
Key takeaways
Blackholing is a sign of failed protection, not a protection method. A "defense" that shuts your business down is essentially finishing the attacker's job for them.
When evaluating providers, always confirm how they handle extreme attacks. It tells you more than any bandwidth figure ever will.
AwayDDoS commits to zero blackholing during attacks. To explore our full protection architecture and fixed-fee model, get in touch — or read How to Choose a DDoS Protection Provider: 5 Key Metrics.