Skip to content
What Is Hetzner DDoS Protection? Complete Review & Guide (2026)

What Is Hetzner DDoS Protection? Complete Review & Guide (2026)

Everything you need to know about Hetzner DDoS Protection: features, pricing, pros & cons, and the best alternatives.

ServerSpotter Team··10 min read
Hetzner DDoS Protection logo

Hetzner DDoS Protection

Hardware-backed DDoS mitigation for high-traffic infrastructure

View Hetzner DDoS Protection on ServerSpotter →

What Is Hetzner DDoS Protection?

Hetzner DDoS Protection is a network-edge mitigation service designed to filter volumetric and application-layer attacks before they reach customer infrastructure. Built directly into Hetzner's hosting environment, it operates at the network perimeter across Hetzner's data centers in Germany, Finland, and the United States.

The service filters malicious traffic targeting both Hetzner Cloud instances and bare-metal dedicated servers. Rather than routing traffic through third-party scrubbing centers, Hetzner processes attack mitigation within its own autonomous system (AS24940), maintaining a single-vendor architecture. This approach reduces latency overhead and eliminates the need to coordinate between multiple providers during an incident.

Hetzner positions this tool for infrastructure operators who already host workloads on Hetzner's platform and need straightforward DDoS defense without introducing external dependencies. It automatically activates when attack traffic exceeds predefined thresholds, though manual activation via API or web console is also available for organizations that prefer explicit control over mitigation triggers.

Key Features and Specs

Hetzner DDoS Protection operates at OSI layers 3, 4, and 7, targeting different attack vectors. Layer 3/4 protection addresses volumetric floods (UDP amplification, SYN floods, ICMP storms), while layer 7 filtering handles HTTP GET/POST floods and slowloris-style application attacks. The system analyzes packet headers, connection rates, and traffic patterns to distinguish legitimate requests from attack payloads.

The service integrates with both Hetzner Cloud and Hetzner Dedicated Root Servers. Cloud instances receive protection automatically; dedicated server customers enable it through the Robot management panel or via API calls. Once active, traffic flows through Hetzner's mitigation infrastructure before reaching the target server, with clean packets forwarded and malicious traffic dropped at the edge.

Activation modes include automatic (default for Cloud) and manual. Automatic mode triggers when incoming traffic volume or packet rates exceed learned baselines. Manual mode requires explicit activation, giving operators control over when mitigation starts—useful for planned traffic events where legitimate spikes might otherwise trigger false positives.

The system maintains traffic baselines by monitoring normal usage patterns over time. Administrators can view attack reports through the Hetzner console, showing attack type, peak traffic volume, duration, and mitigation status. API endpoints allow querying protection status and historical incident logs, enabling integration with monitoring dashboards and alerting systems.

Hetzner does not publish specific throughput capacities or maximum attack size thresholds publicly. The documentation states the service handles "multi-gigabit" attacks but does not specify exact figures like 100 Gbps, 500 Gbps, or higher. Organizations requiring guaranteed mitigation capacity for attacks exceeding certain sizes should contact Hetzner support for capacity details relevant to their specific server locations.

Hetzner DDoS Protection Pricing

Hetzner DDoS Protection is included at no additional charge for all Hetzner Cloud instances and dedicated servers. There are no per-incident fees, bandwidth surcharges during attacks, or tiered pricing based on mitigation capacity. Once enabled on a server, the service remains active without recurring costs.

This zero-cost model differs from specialized DDoS providers that charge monthly subscriptions (often $200-$2,000+ depending on capacity) or per-incident fees. The tradeoff is that Hetzner's offering is limited to protecting infrastructure hosted within Hetzner's network—it cannot shield external targets like on-premises servers or resources hosted with other cloud providers.

The free pricing makes sense for existing Hetzner customers who need baseline protection against common volumetric attacks. Organizations running high-traffic APIs, gaming servers, or e-commerce platforms on Hetzner infrastructure gain mitigation capability without budget adjustments or vendor procurement processes. However, the lack of cost means fewer customization options and less granular control compared to paid, enterprise-grade DDoS services.

Performance and Locations

Hetzner operates data centers in three regions: Falkenstein and Nuremberg (Germany), Helsinki (Finland), and Ashburn and Hillsboro (United States). DDoS Protection operates at the network edge within these facilities, filtering attack traffic before it reaches customer servers. Traffic does not route through distant scrubbing centers, which keeps latency overhead minimal compared to multi-hop mitigation architectures.

The service is optimized for workloads already hosted on Hetzner infrastructure. Latency-sensitive applications like real-time APIs, gaming backends, and financial data feeds benefit from in-network filtering because clean traffic continues to flow with sub-millisecond added latency under normal conditions. During active mitigation, some additional processing delay occurs, but the service avoids the 10-50+ millisecond penalties associated with rerouting through external scrubbing providers.

Hetzner's European locations (Germany, Finland) serve workloads targeting EU users, while the US regions (Virginia, Oregon) suit applications focused on North American audiences. Asia-Pacific customers must accept higher baseline latency since Hetzner does not maintain Asian data centers. Organizations requiring global low-latency coverage should evaluate multi-region architectures using other providers with broader geographic distribution.

Attack mitigation effectiveness depends on traffic baseline accuracy. The system learns normal patterns over days or weeks. Applications with highly variable traffic (flash sales, viral content, scheduled batch jobs) may experience false positives where legitimate spikes trigger mitigation. Manual activation mode helps in these scenarios by letting operators control when filtering engages.

Hetzner does not publish detailed benchmark data for attack types, mitigation success rates, or maximum sustained throughput under attack. The lack of public performance metrics makes it difficult to compare capacity against providers like Cloudflare, AWS Shield, or Arbor Networks, which publish specific figures (e.g., "mitigated a 2.3 Tbps attack"). For infrastructure handling predictable traffic patterns below several gigabits per second, Hetzner's service likely suffices. For environments expecting attacks exceeding 100 Gbps or requiring guaranteed mitigation SLAs, contact Hetzner support for capacity confirmation.

Who Is Hetzner DDoS Protection Best For?

Hetzner DDoS Protection suits organizations already hosting workloads on Hetzner Cloud or dedicated servers who need straightforward mitigation without multi-vendor complexity. This includes development teams running production APIs, gaming companies hosting multiplayer backends, and small-to-midsize e-commerce sites processing moderate transaction volumes.

The tool works well for infrastructure operators who prefer single-vendor architectures. Managing DNS, servers, and DDoS protection within one provider simplifies troubleshooting and avoids coordination overhead when incidents occur. Teams with limited security staffing benefit from automatic activation, which engages mitigation without requiring 24/7 monitoring or manual intervention during off-hours attacks.

Organizations with predictable traffic patterns gain the most value. SaaS platforms, internal enterprise applications, and content delivery workloads with steady request rates allow the baseline learning system to accurately distinguish attacks from legitimate spikes. Applications with highly variable traffic (viral social media, real-time event platforms) may need manual activation to prevent false positives.

The service is not ideal for hybrid cloud architectures where workloads span multiple providers. Since Hetzner DDoS Protection only shields Hetzner-hosted infrastructure, organizations running resources across AWS, Google Cloud, and Hetzner would need separate DDoS solutions for non-Hetzner components. Similarly, companies requiring protection for on-premises data centers or colocation facilities must look elsewhere.

Teams needing advanced mitigation features—granular rate limiting, custom rule sets, machine learning-based bot detection, or guaranteed capacity SLAs—should evaluate specialized DDoS providers. Hetzner's offering provides essential filtering but lacks the deep customization available from enterprise security vendors.

Pros and Cons of Hetzner DDoS Protection

Pros:

The service integrates natively with Hetzner's infrastructure, eliminating third-party dependencies. Traffic stays within Hetzner's network during mitigation, avoiding the latency penalties and routing complexity that come with external scrubbing services. This single-vendor architecture simplifies management and reduces the number of support contacts needed during incidents.

Zero-cost pricing removes budgeting and procurement friction. Organizations enable protection without finance approvals, subscription negotiations, or surprise invoices after large attacks. The lack of per-incident fees means traffic spikes—even multi-gigabit attacks—do not generate surprise costs.

The service protects both Cloud instances and bare-metal dedicated servers through a unified interface. Organizations running mixed workloads (containerized microservices on Cloud, high-performance databases on dedicated hardware) manage DDoS protection consistently across both environments via the same API and console.

Automatic activation handles common attack scenarios without manual intervention. For teams without 24/7 security operations centers, this default behavior ensures mitigation engages during off-hours, weekends, or holidays without requiring staff to detect and respond manually.

Cons:

Protection only applies to infrastructure hosted within Hetzner's network. Organizations with multi-cloud architectures or on-premises components cannot use Hetzner DDoS Protection for those external resources. This limitation forces teams to implement separate mitigation strategies for non-Hetzner workloads, increasing management overhead.

Effective mitigation requires accurate traffic baseline learning. Applications with irregular patterns or frequent legitimate spikes may experience false positives where normal traffic triggers filtering. While manual activation mode addresses this, it shifts the burden back to operators who must monitor and decide when to enable protection.

The service offers fewer customization options compared to specialized DDoS providers. Organizations needing granular rate limits, custom filtering rules, or whitelist/blacklist management may find Hetzner's offering too basic. The automatic mitigation logic cannot be tuned as precisely as enterprise solutions like Arbor or Cloudflare.

Hetzner does not publish detailed capacity metrics or mitigation SLAs. Organizations requiring guaranteed protection against attacks exceeding specific thresholds (e.g., "must handle 500 Gbps") cannot verify capacity from public documentation. This lack of transparency makes capacity planning difficult for high-risk targets.

Hetzner DDoS Protection Alternatives

Cloudflare DDoS Protection operates at the CDN and DNS layers, filtering attacks before they reach origin servers. Cloudflare's Anycast network spans 300+ data centers globally, providing broader geographic coverage than Hetzner's three regions. The service protects any internet-facing application regardless of hosting provider, making it suitable for multi-cloud and hybrid architectures. Cloudflare publishes detailed mitigation reports and handles terabit-scale attacks regularly. Pricing starts free for basic protection, with Pro ($20/month), Business ($200/month), and Enterprise tiers adding advanced features. The tradeoff is that traffic routes through Cloudflare's network, adding latency compared to Hetzner's in-network filtering.

AWS Shield provides managed DDoS protection integrated with AWS infrastructure. Shield Standard (free) offers basic layer 3/4 filtering for all AWS resources. Shield Advanced ($3,000/month per organization) adds layer 7 protection, 24/7 incident response, and cost protection against scaling charges during attacks. AWS Shield suits organizations already invested in AWS services, similar to how Hetzner's offering serves Hetzner customers. Shield Advanced provides guaranteed SLA and dedicated support, features absent from Hetzner's free service. However, Shield only protects AWS-hosted resources, limiting usefulness for multi-cloud environments.

OVHcloud DDoS Protection offers another provider-native mitigation service comparable to Hetzner's approach. OVHcloud filters attacks at network edge across data centers in Europe, North America, and Asia-Pacific. The service includes both automatic and manual activation modes, handling layer 3/4 and layer 7 attacks. Like Hetzner, OVHcloud includes DDoS protection free with hosting services but limits protection to OVHcloud infrastructure. OVHcloud publishes more detailed capacity metrics (claims to mitigate multi-terabit attacks) and operates more data center locations than Hetzner, providing broader geographic options.

Final Verdict

Hetzner DDoS Protection delivers practical value for organizations already hosting workloads on Hetzner infrastructure who need baseline defense against volumetric attacks. The zero-cost model and native integration eliminate procurement friction and maintain single-vendor simplicity. For teams running production APIs, gaming servers, or e-commerce platforms on Hetzner Cloud or dedicated servers, enabling the service provides essential protection without budget impact or architectural complexity.

The tool works best in scenarios where traffic patterns are predictable and infrastructure remains entirely within Hetzner's network. Organizations with these characteristics gain meaningful security improvement simply by activating a feature already included with their hosting. Automatic activation mode suits small-to-midsize teams lacking dedicated security operations resources.

Limitations become apparent in multi-cloud architectures, high-variance traffic environments, or situations requiring guaranteed mitigation capacity. The service cannot protect external resources, making it insufficient as a sole DDoS strategy for hybrid infrastructures. The lack of published capacity metrics and advanced customization options means high-risk targets or enterprises with specific compliance requirements will need to evaluate specialized providers.

For Hetzner customers seeking straightforward DDoS defense included free with hosting, the service is worth enabling—there is no downside to activation. Organizations requiring broader protection, guaranteed SLAs, or infrastructure spanning multiple providers should compare dedicated DDoS solutions. Visit ServerSpotter to evaluate DDoS protection options across providers, comparing coverage areas, capacity metrics, and integration requirements for your specific infrastructure needs.

Tools mentioned in this article

H

Hetzner DDoS Protection

Hardware-backed DDoS mitigation for high-traffic infrastructure

Free tier
4.9 ()
View Tool →
Hetzner DDoS Protection logo

Ready to try Hetzner DDoS Protection?

Hardware-backed DDoS mitigation for high-traffic infrastructure

View Hetzner DDoS Protection on ServerSpotter →
S

ServerSpotter Team

Infrastructure analyst at ServerSpotter. We benchmark cloud providers with real provisioning tests — CPU, disk I/O, network, and pricing — updated weekly. See our methodology

Share this article

Stay in the loop

Get weekly updates on the best new AI tools, deals, and comparisons.

No spam. Unsubscribe anytime.