DDoS protection for websites: what it does and doesn’t do
Published on 3 October 2026
In a DDoS attack, thousands of devices send traffic to your website at once, until the server or the connection can’t keep up and your site becomes unreachable. DDoS protection at your host deals with that brute force on the network. What it doesn’t stop: a stolen password, a hole in a plugin, or an attack that disguises itself as ordinary visitors. For those you take a few steps yourself, and you’ll find them below.
What exactly is a DDoS attack?
DDoS stands for distributed denial of service. In a joint guide, the US agencies CISA and FBI describe how such attacks come from many sources at once, often a botnet of hijacked computers and other devices whose owners have no idea they’re taking part. Because the traffic comes from everywhere, you can’t stop it with a single block.
What kinds of DDoS attacks are there?
CISA splits DDoS attacks into three types. For a website that matters, because each type needs a different defence.
| Type | What happens | What helps |
|---|---|---|
| Volume | The connection is flooded with so much traffic that nothing else gets through | Filtering on your host’s network, with enough capacity |
| Protocol | Weak spots in network protocols are abused to exhaust servers and firewalls (layers 3 and 4) | Network filtering and well-configured firewalls |
| Application | Pages, the search function or the login page are requested en masse (layer 7) | Caching, a limit on the number of requests and a web application firewall (WAF) |
Why would anyone attack a small website?
You don’t have to be a bank. According to Europol, anyone can hire a DDoS attack for as little as ten euros from so-called booter or stresser services, which are used by criminals and hacktivists alike. So the bar is low. On top of that, you can be hit without being the target yourself: on shared hosting, an attack on another site on the same server can affect yours too. That’s why your host’s protection matters, even if nobody has it in for you.
What does your host’s DDoS protection do?
Good protection sits on the network, in front of your server. CISA advises using a DDoS mitigation service, which has the infrastructure to handle large attacks and filters out malicious traffic before it reaches your network, while ordinary visitors get through. The key ingredient is capacity: the protection has to handle more traffic than the attacker can send.
At CakeHosting, every website gets DDoS protection through RoyaleHosting, with more than 6 Tbps of capacity. It’s built for exactly those volume and protocol attacks: the traffic is filtered before it reaches your site, and there’s nothing for you to set up. Running a game server with us as well? Our Premium game servers come with DDoS protection through Cloudflare Magic Transit.
What doesn’t DDoS protection stop?
A DDoS filter isn’t a virus scanner and it isn’t a backup. A few things simply get past it:
- Attacks that look like ordinary visitors. A botnet calmly requesting your search function or login page doesn’t stand out much on the network. Every request still makes PHP and your database work.
- Brute-force attacks on your login. According to WordPress, even failed login attempts can overwhelm your site when they arrive in bulk.
- Break-ins through a vulnerability. An outdated plugin or a leaked password has nothing to do with DDoS. Updates and good passwords are what help there.
- Your own heavy pages. A page that crunches numbers for seconds on every visit will fall over on a busy day, attack or no attack.
Web hosting at CakeHosting: your website gets DDoS protection through RoyaleHosting, with more than 6 Tbps of capacity, plus SSD storage, databases and mailboxes on your own domain. View the plans.
What can you do yourself?
- Turn on caching. A cached page costs your server very little, so a wave of requests hurts a lot less. CISA also recommends a content delivery network, which spreads your content across many servers.
- Limit the number of requests. Rate limiting caps the number of requests per IP address. Definitely do this for your login page. WordPress also advises disabling or restricting XML-RPC if you don’t use it.
- Secure your login. Use strong, unique passwords and turn on two-factor authentication for every administrator, as WordPress itself recommends. And don’t have an account called admin.
- Consider a web application firewall. A WAF filters suspicious requests at the application level, before your WordPress has to deal with them. WordPress prefers this kind of edge protection over relying on plugins alone.
- Keep everything updated. On 22 September 2026, WordPress released version 7.1.2 to fix a critical security vulnerability. Installing updates is part of the job.
- Make backups. Not against DDoS, but against everything that can go wrong afterwards. Keep copies off the server too.
What should you do during an attack?
Stay calm and gather information: when did it start, which pages are slow and which error messages do you see? Contact your host, because it sees far more on the network than you do. If you’re a customer of ours, let us know straight away. A DDoS attack is a crime, so report it to the police as well. Is someone threatening an attack unless you pay? Don’t play along, keep the messages and report it.
Can you test your own site with a DDoS tool?
No, not with one of those online stressers. Even if it’s your own site, you’re sending attack traffic across your host’s network and hitting other customers. Europol and police forces in dozens of countries go after these services and their users, and our terms forbid DDoS attacks. Want to know how many visitors your site can handle? Only run a load test in agreement with your host.
So DDoS protection is a solid cake base: without it everything collapses, but you still have to bake the cake on top properly yourself.