Skip to content
VPSDen
AS64508 (placeholder) · our own prefixes

Our network, our addresses, our scrubbing.

A privacy host that rents IP space from somebody else has a single point of failure it does not control: one abuse email to the actual holder and your address disappears. We hold our own ASN and our own allocations, which means the decision about your address is ours, and we have already told you what our policy is.

Short answer

Is any traffic filtered, shaped or inspected?

No. We do not perform deep packet inspection, we run no IDS on customer traffic, we do not throttle by protocol, and we do not detect or discourage VPN, Tor or torrent traffic. The single exception is outbound port 25, closed by default on new instances and opened on request — a spam-control measure, not a content one.

We own the addresses

Our own autonomous system, with our own IPv4 allocations and a /29 of IPv6. Nobody upstream can take an address away from you over a complaint, because it is not theirs to take. The AS number shown on this page is AS64508, from the RFC 5398 documentation range — it is a placeholder, not our real allocation, and it is not routable.

Scrubbing at our own edge

Between 600 Gbps and 6 Tbps of mitigation capacity per region, engaging within 10 seconds. Your traffic is not redirected through a third-party network and your TLS is never terminated outside our racks.

No DPI, ever

We do not inspect packet contents. Not for abuse detection, not for shaping, not for "network optimisation". The instrument does not exist in our infrastructure.

Clean addresses

Every IPv4 is checked against 38 blocklists before assignment and re-checked monthly. If yours lands on one through no fault of yours, we swap it within 4 hours free of charge.

IPv6 as a first-class citizen

A routed /64 free on every plan, /48 available for €1. Not a single address — an actual subnet, so per-container and per-service addressing works.

Bring your own space

BGP session from our edge for €9/month, full table optional. We will help with IRR objects and RPKI ROAs, which is the part everyone finds tedious.

Per region

Capacity, peering and transit

Named, so you can check them in public routing data rather than take our word for it. Our own looking glass is not built yet, so the column that would link to it is not shown.

RegionUplinkMitigationPeering & transit
🇮🇸Reykjavík40 Gbps2.4 Tbps scrubbing
RIXFarice-1IRISCogentArelion
🇳🇱Amsterdam100 Gbps6 Tbps scrubbing
AMS-IXNL-ixCogentArelionLumenHurricane Electric
🇨🇭Zürich40 Gbps3 Tbps scrubbing
SwissIXCIXPInit7Cogent
🇷🇴Bucharest40 Gbps1.5 Tbps scrubbing
InterLANRONIXCogentGTT
🇧🇬Sofia20 Gbps1 Tbps scrubbing
BIX.BGNeterraCogent
🇲🇩Chișinău20 Gbps800 Gbps scrubbing
MD-IXOrange MDRETN
🇵🇦Panama City20 Gbps1 Tbps scrubbing
PAIXCogentLumenTelxius
🇸🇨Victoria10 Gbps600 Gbps scrubbing
SEASPEACE cableAirtelLiquid
🇲🇾Kuala Lumpur40 Gbps2 Tbps scrubbing
MyIXEquinix SGTelekom MalaysiaArelion
Port policy

What is open

DirectionPolicy
Inbound, all portsOpen
Outbound, all ports except 25Open
Outbound port 25 (SMTP)Closed by default, opened on request
IP spoofingFiltered (BCP 38)
Reverse DNSSelf-service in the panel

BCP 38 anti-spoofing is the one filter we apply universally and will not remove. It prevents our network being used as a reflector in amplification attacks, which protects everyone including you.

Explicitly permitted

Traffic other hosts refuse

  • Tor relays and exit nodes, in every region
  • I2P routers and Lokinet nodes
  • Commercial and personal VPN endpoints
  • BitTorrent, seeding and leeching, plus trackers
  • Cryptocurrency nodes, miners and validators
  • Mail servers, once port 25 is opened
  • Game servers and voice servers
  • High-connection-count applications
Tor exits specifically
We run them ourselves and have since 2014. Use a reduced exit policy blocking SMTP, run the standard exit notice on port 80, and take a dedicated IP so complaints do not touch your other services. We will not suspend you over an exit-node abuse complaint, and we will answer the complaint on your behalf if you ask.

How our DDoS mitigation actually works

Most "DDoS protected" hosting means your traffic is redirected through a large third-party scrubbing provider. That works, and for a privacy host it is unacceptable: it means a company you did not choose sees all your traffic, and in the common case where they terminate TLS, sees your plaintext.

We scrub on our own edge:

  • Detection. Flow telemetry at the border, aggregated per destination prefix rather than per customer — the same aggregation that makes metadata-free mode possible. Anomalies trigger mitigation within about 10 seconds.
  • L3/L4 mitigation. Hardware filtering at line rate: volumetric floods, amplification and reflection, SYN floods, malformed packets and protocol abuse. Capacity is 600 Gbps to 6 Tbps depending on the region.
  • No traffic redirection. Your packets never leave our network to be cleaned. Nothing is proxied, nothing is decrypted, nothing is logged for analysis.
  • Optional L7 filtering (€4/month) for HTTP workloads: proof-of-work challenges, rate shaping and a bot-scoring engine you control from the panel. TLS is still terminated on your instance, not on ours.

What we do not do

We do not nullroute a customer to protect the network unless the attack exceeds the region's capacity, and we publish that capacity per region so you can judge the risk before you buy. If we do have to nullroute, we tell you immediately, we do not charge you for the attack traffic, and we will help you move to a higher-capacity region at no cost.

Several hosts in this market nullroute at a few gigabits and bill the customer for the transit. We think that is indefensible and we do not do it.

Questions

Network questions

Does VPSDEN block any ports?

Outbound port 25 is closed by default on new instances and opened on request after a short conversation about what you are sending. Nothing else is blocked, inbound or outbound. There is no protocol filtering, no torrent throttling, no VPN detection, and no deep packet inspection.

How does VPSDEN handle DDoS attacks?

Always-on L3/L4 scrubbing at our own edge, engaging within 10 seconds of detection, with 600 Gbps to 6 Tbps of capacity depending on the region. Traffic is not redirected through a third-party provider and TLS is never terminated outside our racks — which means no external party ever sees your plaintext. Layer-7 filtering is an optional add-on for HTTP workloads.

Can I announce my own IP space from VPSDEN?

Yes. We provide a BGP session from our edge for €9 per month, with a full table if you want one, and we will walk you through IRR objects and RPKI ROA creation. You need your own ASN and prefixes, or a Letter of Authorisation from whoever holds them.

Test it before you commit.

The per-region looking glass and test files are not built yet, so measure from your own vantage point instead. 72-hour refund if the numbers do not hold up.

No email · No KYC · Pay in Monero · Deployed in under a minute