Skip to content
WP Cloud
WP Cloud
    • For Hosts
    • For Agencies
    • For Registrars
    • For Native Hosting
    • Performance
    • Security
    • Real-Time Automated Failover
    • Vertical Scaling and Bursting
    • WordPress Management
    • PanelAlpha Integration: White-Label WordPress Control Panel for Hosts
    • EasyEngine Panel Integration: Visual WordPress Management for WP Cloud
    • FAQs
    • WP Cloud API
    • Partner Portal
    • Documentation
    • New Partner Guide
    • Pressable
    • Convesio
    • Porkbun
    • PanelAlpha
    • Ivapix
    • UNC Greensboro
    • Impressive Hosting
    • Blog
    • Performance Benchmarks
  • Connect With Us
  • Login ↗
Start Here ↗
  • Solutions

    • For Hosts
    • For Agencies
    • For Registrars
    • For Native Hosting
    • Featured Partners

    Features

    • Performance
    • Security
    • Real-Time Automated Failover
    • Vertical Scaling and Bursting
    • WordPress Management

    Integrations

    • PanelAlpha Integration
    • Easy Engine Panel Integration

    Resources

    • FAQs
    • WP Cloud API
    • Partner Portal
    • Documentation
    • New Partner Guide
  • Case Studies
    • PressableA case study about how WP Cloud supports Pressable to power millions of page views daily.
    • Convesio
    • Porkbun
    • PanelAlpha
    • Ivapix
    • UNC Greensboro
    • Newspack
    • Inverse Paradox
  • Insights
    • Podcast
    • BlogWP Cloud blog page with latest news and updates about the platform.
    • Performance Benchmarks
  • Connect With Us
  • Login ↗
Start Here ↗

Browse

    • WP Cloud platform overview
    • Onboard and launch with WP Cloud
    • WP Cloud Partner Portal
    • Get support from WP Cloud
    • WP Cloud glossary
    • Manage and secure API keys
    • Client SSH
    • WP Cloud API quick start
    • Webhooks
    • Run bulk tasks across sites
      • Manage site domains and aliases
      • Domain verification records
      • TLS certificates
      • Manage custom TLS certificates
      • Cloudflare and WP Cloud
    • Clone a site
    • Configure resources, site type, and billing with site meta
    • Delete a site
    • Persistent data
    • Staging sites
    • Migrate a site to WP Cloud
      • SSH and SFTP access models
      • Client SSH
      • User SSH and SFTP access
      • Database credentials
      • phpMyAdmin
      • ABSPATH
      • Default wp-config.php
      • Site constants
      • Configure redirects and headers with custom-redirects.php
      • Akismet and Jetpack
      • Blocked and unsupported plugins
      • PHP lifecycle and supported versions
      • Symlinks and managed software
      • WordPress versions
      • Install Composer and WP-CLI packages
      • Manage platform software with WP-CLI
      • Useful WP-CLI commands
    • Transactional email
    • WordPress multisite
    • Cron scheduling
    • Decoupled and headless WordPress
    • Repair Yoast indexables
      • Page Cache
      • Edge Cache
      • Object Cache
      • Image transformation
      • Offload image sub-sizes
    • Configure lightweight 404s for static files
      • DDoS protection
      • Defensive Mode
      • Rate limiting
      • Network and web application firewalls
      • Bot protection
      • Password protection
      • HTTP and security headers
      • PHP filesystem access permissions
      • Scan a site for malware
    • Backups overview
    • Create an on-demand backup
    • Restore a backup
    • Jetpack backups
      • Error logs
      • Web server logs
    • Metrics
    • Application performance monitoring
    • Automated failover
    • IP ranges
    • Origin and edge servers
    • Server specifications and settings
    • EasyEngine integration
    • PanelAlpha integration
      • White labelling and co-marketing WP Cloud
      • WP Cloud logos
      • Terms of Service & Compliance
      • Prohibited content
      • Copyright infringement and takedown notifications
    • WP Cloud billing
    • WP Cloud for agencies and site networks
    • WP Cloud partner support options
    • Troubleshoot Page and Edge Cache
    • Troubleshoot HTTP 429 and 599 errors
    • WP Cloud HTTP status codes
    • Troubleshoot site performance
    • Cache slow database queries
    • Troubleshoot duplicate core files, wp-config.php, and wp-admin 403 errors
    • Troubleshoot email delivery
    • Troubleshoot PDF thumbnail generation
    • Troubleshoot TLS certificate provisioning
Documentation/Security/Traffic protection/DDoS protection

DDoS protection

LAST UPDATED

3 months ago

    WP Cloud uses edge routing, traffic classification, rate limiting, and network-level mitigation to protect sites from denial-of-service and distributed denial-of-service (DDoS) attacks. These protections operate at the platform level without requiring a site administrator to enable them.

    How WP Cloud handles DDoS traffic

    Inbound requests use an Anycast range of IP addresses. Anycast connects a visitor to a nearby WP Cloud edge data center and limits direct exposure of origin server addresses.

    At the edge, an NGINX load balancer decides whether to serve an eligible response from Edge Cache or send the request to the site’s origin. WP Cloud can also change how traffic is routed when demand changes. This edge layer filters and distributes traffic before it reaches WordPress.

    Most sites can absorb a large increase in traffic without any manual action. Traffic classification, rate limiting, and Edge Cache increase the amount of unwanted or repeated traffic the platform can handle. A dedicated WP Cloud team monitors the network, responds to alerts, and adjusts platform resources and DDoS mitigations when needed.

    Add a browser challenge when needed

    Defensive Mode provides an additional on-demand challenge during a suspected bot or DDoS event. It can reduce automated requests that are still reaching the site or using PHP resources.

    Avoid third-party proxying when possible

    Enable Edge Cache and send traffic directly to WP Cloud whenever possible. A third-party proxy can hide request information that WP Cloud uses for traffic classification and DDoS mitigation. It can also prevent visitors from connecting directly to the nearest WP Cloud edge data center.

    If Cloudflare proxying is required, follow the recommended Cloudflare configuration.

    Previous Configure lightweight 404s for static files
    Next Defensive Mode

    Related Guides

    • Defensive Mode

      Use an on-demand browser challenge to reduce unwanted automated traffic during a bot or DDoS…

      3 Min.

      READ

    • Rate limiting

      Understand how WP Cloud classifies excessive requests, when HTTP 429 responses are expected, and when…

      3 Min.

      READ

    • Network and web application firewalls

      Understand WP Cloud inbound access, outbound firewall rules, and web application firewall responses.

      2 Min.

      READ

    On this page

      Contact support

      Contact us with Support issues and questions related to WP Cloud, the WP Cloud Atomic API, API-key IP allow list changes, Station, and more.

      Check the FAQs

      Have questions? Please visit our FAQ to learn more.

      An Automattic venture

      Work With Us

      Press

      Privacy Policy

      © 2021-2026 Automattic Inc.

      Notifications