DDoS Protection
Null Routing DDoS Protection: Why It Doesn’t Actually Protect You
Published 4 August 2026 · GigaNodes Team

If a hosting provider tells you their DDoS protection is “null routing,” what they’re really telling you is that when an attack hits, they take your server offline themselves. Null routing DDoS protection isn’t protection at all. It’s a way for a provider to stop an attack from affecting their network by sacrificing your uptime instead.
This confusion is common because most budget VPS and dedicated server providers advertise “DDoS protected” without explaining what that actually means underneath. Once you understand what null routing does, and what real DDoS protection looks like instead, it becomes obvious why the two aren’t the same thing.
What Null Routing Actually Does
Null routing, also called blackhole routing, is a network-level response to an attack. When a provider detects a large volume of malicious traffic heading toward one of your server’s IP addresses, they configure their routers to drop every packet destined for that IP, both the attack traffic and your legitimate traffic. Your server effectively disappears from the internet until the attack stops or the provider manually lifts the block.
From the provider’s perspective, this works. Their network stays stable, their other customers aren’t affected, and the attack traffic never reaches their infrastructure. From your perspective, you’re offline exactly when it matters most, since most DDoS attacks are timed to cause maximum damage: during a product launch, a competitive game server event, a trading session, or peak business hours.
Some providers null-route automatically the moment attack traffic crosses a threshold, sometimes within seconds. Others do it manually after a support ticket, which means your server can stay dark for much longer while someone gets around to it. Either way, the outcome is the same: your IP goes dark, and being taken offline by your own host isn’t functionally different from being taken offline by the attacker.
Why Providers Rely on Null Routing
Null routing is cheap and simple to implement, which is exactly why it’s common among budget VPS and dedicated server providers. Real DDoS mitigation requires scrubbing infrastructure, capacity to absorb attack traffic without passing it through to the origin server, and engineering investment that most low-cost hosts don’t want to build or maintain. Blackholing your IP costs them almost nothing.
The marketing language rarely distinguishes between the two. “DDoS protected VPS” and “DDoS protection included” show up on pricing pages regardless of whether the provider is actually filtering attack traffic or just null-routing it. The only way to know which one you’re getting is to ask directly, or to check what happens to your uptime during an actual attack.
What Real DDoS Protection Looks Like
Genuine DDoS protection filters attack traffic before it reaches your server, while letting clean traffic through without interruption. Instead of dropping everything at the first sign of an attack, your traffic is routed through scrubbing infrastructure that inspects packets, discards the malicious ones, and forwards the legitimate ones on to your origin server in near real time.
This is the model GigaNodes uses through Cloudflare Magic Transit. Every VPS and dedicated server on the platform routes through Cloudflare’s network first, where attacks are filtered across a large global network of scrubbing locations before clean traffic ever reaches Yotta DC Noida or our other origin infrastructure. Your IP never goes dark. There’s no null-routing threshold to cross, no support ticket to wait on, and no per-GB scrubbing fee that shows up on your invoice after the fact.
This is included on every plan, from the smallest Cloud Nano VPS up to our largest EPYC dedicated servers, not gated behind a premium tier. Protection also extends past HTTP traffic to cover UDP and TCP-based attacks, which matters because a lot of budget “DDoS protection” only covers HTTP floods and leaves game servers, VoIP, and UDP-based APIs completely exposed.
How to Tell What You’re Actually Getting
Since almost every provider advertises DDoS protection in some form, the marketing page alone won’t tell you whether it’s real filtering or null routing in disguise. A few questions cut through the ambiguity quickly:
- Does your IP stay online during an attack, or does the provider take it offline?
- Is there a traffic threshold that triggers an automatic blackhole, and what is it?
- Is UDP and TCP traffic covered, or only HTTP?
- Is protection included on every plan, or is it a paid add-on with a separate scrubbing fee?
- Where does filtering happen: at a scrubbing network before your server, or only after the attack has already been detected on-network?
If a provider can’t answer the first question clearly, the honest answer is usually null routing. This matters most for exactly the workloads attackers actually target: public Discord and Telegram bots, competitive game server communities, trading bots and APIs with predictable endpoints, and anything else with a stable, guessable IP address. These are the workloads where going offline for even a few minutes has a real cost, which is why the difference between null routing and real mitigation isn’t academic.
Choosing Infrastructure That Doesn’t Blackhole You
If uptime during an attack actually matters for what you’re running, it’s worth checking this before you sign up rather than after your first incident. GigaNodes routes every VPS and dedicated server through Cloudflare Magic Transit by default, with no separate protection tier to upgrade into and no gap in coverage between HTTP and non-HTTP traffic.
For a closer look at how this works end to end, our guide on why GigaNodes is the best VPS hosting in India covers the broader infrastructure picture, and our DDoS-protected VPS plans page has the specifics on pricing and coverage. If you’re running a dedicated workload instead, the same Magic Transit protection applies across our AMD EPYC dedicated servers as well.
Frequently Asked Questions
Is null routing the same as DDoS protection?
No. Null routing takes your IP offline entirely during an attack, which is not protection, it’s the provider preventing the attack from reaching their own network at the cost of your uptime. Real DDoS protection filters malicious traffic while keeping your legitimate traffic online.
How do I know if my provider null-routes instead of filtering traffic?
Ask directly what happens to your server’s uptime during an attack. If the answer involves your IP being temporarily disabled or blackholed until the attack subsides, that’s null routing, not active mitigation.
Does GigaNodes null-route servers during an attack?
No. Every GigaNodes VPS and dedicated server routes through Cloudflare Magic Transit, which filters attack traffic at the network edge before it reaches your server. Your IP stays online and reachable throughout an attack.
Does DDoS protection cover game servers and UDP traffic?
It depends on the provider. Many budget DDoS protection plans only cover HTTP traffic, leaving UDP-based traffic like game servers, VoIP, and certain APIs unprotected. GigaNodes’ Magic Transit coverage includes UDP and TCP protocol attacks, not just HTTP.
Is DDoS protection included free on all GigaNodes plans?
Yes. Cloudflare Magic Transit protection is included on every VPS and dedicated server plan by default, with no separate protection tier and no per-GB scrubbing fee.