Our network, our addresses, our scrubbing.
A privacy host that rents IP space from somebody else has a single point of failure it does not control: one abuse email to the actual holder and your address disappears. We hold our own ASN and our own allocations, which means the decision about your address is ours, and we have already told you what our policy is.
Is any traffic filtered, shaped or inspected?
We own the addresses
Our own autonomous system, with our own IPv4 allocations and a /29 of IPv6. Nobody upstream can take an address away from you over a complaint, because it is not theirs to take. The AS number shown on this page is AS64508, from the RFC 5398 documentation range — it is a placeholder, not our real allocation, and it is not routable.
Scrubbing at our own edge
Between 600 Gbps and 6 Tbps of mitigation capacity per region, engaging within 10 seconds. Your traffic is not redirected through a third-party network and your TLS is never terminated outside our racks.
No DPI, ever
We do not inspect packet contents. Not for abuse detection, not for shaping, not for "network optimisation". The instrument does not exist in our infrastructure.
Clean addresses
Every IPv4 is checked against 38 blocklists before assignment and re-checked monthly. If yours lands on one through no fault of yours, we swap it within 4 hours free of charge.
IPv6 as a first-class citizen
A routed /64 free on every plan, /48 available for €1. Not a single address — an actual subnet, so per-container and per-service addressing works.
Bring your own space
BGP session from our edge for €9/month, full table optional. We will help with IRR objects and RPKI ROAs, which is the part everyone finds tedious.
Capacity, peering and transit
Named, so you can check them in public routing data rather than take our word for it. Our own looking glass is not built yet, so the column that would link to it is not shown.
| Region | Uplink | Mitigation | Peering & transit |
|---|---|---|---|
| 🇮🇸Reykjavík | 40 Gbps | 2.4 Tbps scrubbing | RIXFarice-1IRISCogentArelion |
| 🇳🇱Amsterdam | 100 Gbps | 6 Tbps scrubbing | AMS-IXNL-ixCogentArelionLumenHurricane Electric |
| 🇨🇭Zürich | 40 Gbps | 3 Tbps scrubbing | SwissIXCIXPInit7Cogent |
| 🇷🇴Bucharest | 40 Gbps | 1.5 Tbps scrubbing | InterLANRONIXCogentGTT |
| 🇧🇬Sofia | 20 Gbps | 1 Tbps scrubbing | BIX.BGNeterraCogent |
| 🇲🇩Chișinău | 20 Gbps | 800 Gbps scrubbing | MD-IXOrange MDRETN |
| 🇵🇦Panama City | 20 Gbps | 1 Tbps scrubbing | PAIXCogentLumenTelxius |
| 🇸🇨Victoria | 10 Gbps | 600 Gbps scrubbing | SEASPEACE cableAirtelLiquid |
| 🇲🇾Kuala Lumpur | 40 Gbps | 2 Tbps scrubbing | MyIXEquinix SGTelekom MalaysiaArelion |
What is open
| Direction | Policy |
|---|---|
| Inbound, all ports | Open |
| Outbound, all ports except 25 | Open |
| Outbound port 25 (SMTP) | Closed by default, opened on request |
| IP spoofing | Filtered (BCP 38) |
| Reverse DNS | Self-service in the panel |
BCP 38 anti-spoofing is the one filter we apply universally and will not remove. It prevents our network being used as a reflector in amplification attacks, which protects everyone including you.
Traffic other hosts refuse
- Tor relays and exit nodes, in every region
- I2P routers and Lokinet nodes
- Commercial and personal VPN endpoints
- BitTorrent, seeding and leeching, plus trackers
- Cryptocurrency nodes, miners and validators
- Mail servers, once port 25 is opened
- Game servers and voice servers
- High-connection-count applications
How our DDoS mitigation actually works
Most "DDoS protected" hosting means your traffic is redirected through a large third-party scrubbing provider. That works, and for a privacy host it is unacceptable: it means a company you did not choose sees all your traffic, and in the common case where they terminate TLS, sees your plaintext.
We scrub on our own edge:
- Detection. Flow telemetry at the border, aggregated per destination prefix rather than per customer — the same aggregation that makes metadata-free mode possible. Anomalies trigger mitigation within about 10 seconds.
- L3/L4 mitigation. Hardware filtering at line rate: volumetric floods, amplification and reflection, SYN floods, malformed packets and protocol abuse. Capacity is 600 Gbps to 6 Tbps depending on the region.
- No traffic redirection. Your packets never leave our network to be cleaned. Nothing is proxied, nothing is decrypted, nothing is logged for analysis.
- Optional L7 filtering (€4/month) for HTTP workloads: proof-of-work challenges, rate shaping and a bot-scoring engine you control from the panel. TLS is still terminated on your instance, not on ours.
What we do not do
We do not nullroute a customer to protect the network unless the attack exceeds the region's capacity, and we publish that capacity per region so you can judge the risk before you buy. If we do have to nullroute, we tell you immediately, we do not charge you for the attack traffic, and we will help you move to a higher-capacity region at no cost.
Several hosts in this market nullroute at a few gigabits and bill the customer for the transit. We think that is indefensible and we do not do it.
Network questions
Does VPSDEN block any ports?
Outbound port 25 is closed by default on new instances and opened on request after a short conversation about what you are sending. Nothing else is blocked, inbound or outbound. There is no protocol filtering, no torrent throttling, no VPN detection, and no deep packet inspection.
How does VPSDEN handle DDoS attacks?
Always-on L3/L4 scrubbing at our own edge, engaging within 10 seconds of detection, with 600 Gbps to 6 Tbps of capacity depending on the region. Traffic is not redirected through a third-party provider and TLS is never terminated outside our racks — which means no external party ever sees your plaintext. Layer-7 filtering is an optional add-on for HTTP workloads.
Can I announce my own IP space from VPSDEN?
Yes. We provide a BGP session from our edge for €9 per month, with a full table if you want one, and we will walk you through IRR objects and RPKI ROA creation. You need your own ASN and prefixes, or a Letter of Authorisation from whoever holds them.
Test it before you commit.
The per-region looking glass and test files are not built yet, so measure from your own vantage point instead. 72-hour refund if the numbers do not hold up.
No email · No KYC · Pay in Monero · Deployed in under a minute