Use coupon MC25OFF for 25% off!

Top-tier Minecraft hosting. Zero lag, instant setup.

Always-on protection

92 Tbps
DDoS Shield.

Three layers of protection — network, application, and transit — working together before a single malicious packet reaches your server.

92 Tbps
Scrubbing capacity
< 5ms
Mitigation onset
3 layers
L3 / L4 / L7
Always on
Zero config needed

Traffic hits us
not you.

Every packet passes through our scrubbing stack before it touches your server. Legitimate traffic flows through. Everything else gets dropped at the edge.

DDoS traffic flow diagram Shows how attack traffic is scrubbed through three layers before reaching the customer server ATTACK Flood traffic LAYER 01 L3 / L4 Scrubbing OVH VAC + XDP/eBPF clean LAYER 02 L7 HTTP Scrubbing ML + Go balancer clean LAYER 03 IP Transit Mitigation Upstream + eBPF clean PROTECTED Your server ↓ attack dropped ↓ bots dropped ↓ volumetric dropped
Attack detected at edge
BGP Flowspec and our upstream ISP filters — Airtel and Fusionnet — flag anomalous traffic patterns the moment they appear on the wire.
Traffic routed to scrubbing
Malicious packets are diverted to OVH VAC scrubbing centers and our own XDP/eBPF bridge nodes before ever reaching your IP.
Layer-specific filtering applied
L3/L4 volumetric attacks are rate-limited at the kernel level. L7 HTTP floods, bots, and WebSocket abuse are filtered by our Go balancer and ML classifier.
Clean traffic delivered
Only verified legitimate packets reach your server. No configuration, no rerouting, no downtime for you.

Three shields.
One platform.

Each layer is purpose-built for a different class of attack. Together they cover every vector — from packet floods to slowloris bots.

Layer 01 — Network

L3/L4 Scrubbing
— In-house + upstream

Volumetric and protocol attacks — UDP floods, SYN floods, ICMP amplification — are absorbed at the network edge before they reach your server's NIC. We combine OVH's VAC scrubbing backbone with custom rules deployed directly at our ISPs, plus dedicated XDP/eBPF bridge nodes for kernel-level PPS filtering.

L3 / L4 Always on XDP / eBPF
  • OVH VAC
    OVH's scrubbing centers absorb volumetric attacks up to 92 Tbps via anycast re-routing. Traffic is scrubbed and clean packets returned over GRE tunnels.
  • Custom ISP rules
    BGP Flowspec rules deployed directly at Airtel and Fusionnet at the network edge. Drops traffic before it enters our infrastructure — zero bandwidth cost.
  • XDP/eBPF bridge nodes
    Dedicated bare-metal bridge servers running XDP programs in the kernel's fast path. Process millions of packets per second with sub-microsecond decision latency.
  • PPS rate limiting
    eBPF maps track per-source PPS counters. Sources exceeding thresholds are instantly blackholed without entering the network stack.
  • Protocol anomaly filtering
    XDP programs inspect TCP flags, UDP payloads, and ICMP types to drop malformed or amplified traffic patterns at wire speed.
L3/L4 scrubbing architecture Shows attack traffic being filtered by OVH VAC, ISP rules, and XDP/eBPF bridge before reaching the server ATTACKER Flood / amplify OVH VAC 92 Tbps scrub ← drop ISP RULES Airtel · Fusionnet ← drop XDP / eBPF PPS rate limiting ← drop YOUR SERVER Volume attacks absorbed at anycast edge nodes. BGP Flowspec rules at ISP level, zero cost. Kernel-path XDP drops PPS floods in <1µs. Clean traffic delivered.
Infrastructure OVH VAC Airtel BGP Fusionnet BGP XDP/eBPF bridges GRE tunnel return
Layer 02 — Application

L7 HTTP/HTTPS/WebSocket
— In-house

Application-layer attacks survive network scrubbing because they look like legitimate requests. Our L7 stack runs software rate limiting, machine learning classifiers, Shulker Tunnels, and our custom Go reverse proxy to distinguish real users from bots, scrapers, and slow-burn HTTP floods at the request level.

L7 / HTTP WebSocket ML-powered
  • Software rate limiting
    Per-IP, per-path, and per-session request rate windows. Configurable burst allowances mean real users never get 429'd during normal spikes.
  • ML anomaly classifier
    A lightweight gradient-boosted model scores every request on headers, timing, TLS fingerprints, and behavioral patterns. Known bot signatures are rejected in under 2ms.
  • Shulker Tunnels
    Your real IP is never exposed. Tunnels route traffic through our edge PoPs so origin IPs stay hidden from attackers — even on DevSpaces and VPSes.
  • Custom Go balancer
    Our in-house reverse proxy handles TLS termination, connection pooling, WebSocket upgrades, and per-backend health checks with zero off-the-shelf dependencies.
  • Slowloris & CC protection
    Connection lifetime limits, incomplete request timeouts, and per-IP connection caps defeat slow-send attacks and challenge-collapsar floods automatically.
L7 application scrubbing pipeline HTTP/HTTPS/WebSocket request pipeline showing ML classifier, rate limiter, Go balancer and tunnel routing HTTP REQUEST TLS terminated at edge SHULKER TUNNEL Origin IP concealed ML CLASSIFIER TLS fp · timing · UA BLOCKED bot / flood RATE LIMITER per-IP · per-path GO BALANCER → clean to backend Hides origin from direct-IP attackers. Gradient-boosted model scores every request. Sliding window, burst allowance per session.
Stack Shulker Tunnels Custom Go balancer ML classifier Software rate limiting WebSocket protection
Layer 03 — Transit

IP Transit
DDoS Mitigation

For raw IP transit customers — bare metal servers, VPSes, and DevSpaces with direct IP exposure — traffic passes through our eBPF filtering pipeline and OVH's IP Transit VAC before reaching your assigned IP. Upstream protection rules are applied at the peering level, stopping volumetric attacks before they consume your transit capacity.

IP Transit eBPF upstream Always on
  • In-house XDP/eBPF filtering
    Traffic destined for your IP passes through our eBPF-powered filtering plane. Custom programs apply per-IP and per-protocol rules at kernel speed before packets hit any userspace process.
  • Upstream protection rules
    BGP communities and Flowspec rules pushed to our transit providers enforce rate limits and protocol policies at the peering layer — far upstream of our network.
  • OVH IP Transit VAC
    OVH's VAC is applied to all IP transit prefixes. Detected attacks trigger automatic scrubbing via anycast GRE, with return traffic via normal routing.
  • Per-IP traffic baselines
    eBPF maps maintain rolling per-IP traffic baselines. Sudden deviations trigger automatic upstream null-route or scrubbing center activation within seconds.
  • Full TCP/UDP coverage
    UDP reflection, NTP amplification, DNS amplification, SYN floods, and ACK floods are all detected and mitigated at the transit layer without any action required from you.
IP transit DDoS mitigation architecture Shows upstream peering, OVH IP transit VAC, and eBPF filtering before IP delivery INTERNET / PEERS BGP transit providers UPSTREAM RULES Flowspec · BGP comm. drop at peer OVH VAC TRANSIT Anycast GRE scrubbing volumetric drop eBPF FILTER PLANE Per-IP baseline tracking anomaly drop YOUR IP — CLEAN
Infrastructure OVH IP Transit VAC In-house eBPF plane BGP Flowspec rules Per-IP baseline tracking

What we
stop.

Every known DDoS vector across all three OSI layers — covered by at least one protection layer, most by two or three.

Attack type L3/L4 Scrubbing L7 HTTP IP Transit Typical volume
UDP Flood ✓ — ✓ 1–300 Gbps
SYN Flood ✓ — ✓ 10M–2B pps
ICMP Amplification ✓ — ✓ 10–100 Gbps
DNS Amplification ✓ — ✓ 10–500 Gbps
NTP Reflection ✓ — ✓ 50–400 Gbps
HTTP Flood / CC Attack — ✓ — 100K–10M rps
Slowloris — ✓ — Low volume
Bot / Scraper flood — ✓ — Low-medium
WebSocket abuse — ✓ — Medium
TLS exhaustion — ✓ — Medium
BGP hijack / transit — — ✓ Routing-level
IP spoofing floods ✓ — ✓ 10–500 Gbps

Built on
serious iron.

Our protection stack doesn't rely on a single vendor. We layer best-in-class upstream providers with our own in-house filtering for defense-in-depth.

OVH VAC
The backbone of our L3/L4 and IP transit scrubbing. OVH's VAC network handles volumetric attacks up to 92 Tbps via anycast routing, cleaning traffic before returning it via GRE tunnels to our edge.
Airtel
Tier-1 Indian ISP providing upstream BGP peering. Custom Flowspec rules push DDoS drop policies directly to Airtel's routers, stopping attacks before they consume our ingress capacity.
Fusionnet
Secondary ISP transit provider. BGP community-based filtering rules ensure redundant upstream drop policies across multiple peering points for resilience.
XDP/eBPF
In-house Linux kernel programs (XDP + eBPF) running on dedicated bridge servers. Processes millions of packets per second at the driver level with near-zero CPU overhead.
Shulker Go
Our own reverse proxy, written in Go from scratch. Handles TLS termination, ML-scored request routing, per-session rate limiting, and WebSocket proxying for L7 protection.
ML Stack
A gradient-boosted ensemble trained on anonymized attack traffic fingerprints. Scores TLS profiles, request timing, headers, and behavioral patterns to flag bots in under 2ms.

Every product.
Protected.

DDoS protection isn't an add-on. Every Shulker product ships with the right protection layer for its threat model — at no extra cost.

Minecraft Hosting L3/L4 + L7

Minecraft Hosting

Network and application layer protection. Game-protocol aware. TCP/UDP flood protection on your server's port, plus HTTP filtering for web map and store traffic.

VPS / Bare Metal L3/L4 + Transit

VPS / Bare Metal

Network scrubbing and IP transit VAC cover your assigned IP. eBPF filtering at the hypervisor and transit layers. Full 92 Tbps umbrella.

DevSpaces L7 + Tunnel

DevSpaces

Traffic enters via Shulker Tunnels — your real IP is never exposed. ML-scored HTTP/WebSocket filtering on the edge PoPs before reaching your container.

Global Transit IP Transit VAC

Global Transit

OVH VAC + upstream Flowspec protect your raw IP transit. Designed for high-traffic services that need clean BGP-delivered transit at scale.

Tunnels L7 + Origin hide

Tunnels

All traffic through tunnel PoPs is L7-filtered. Origin IP concealment means attackers can't bypass Shulker's scrubbing by targeting you directly.

Web Stores L7 HTTP

Web Stores

Checkout flows, payment callbacks, and API endpoints protected by rate limiting and bot filtering. No revenue lost to cart-filling bots.

Common
questions.

No. All Shulker products include DDoS protection at no additional cost. Minecraft plans include L3/L4 and L7 filtering; VPS and bare metal include transit-layer VAC; DevSpaces are protected via tunnels.

Clean traffic latency impact is under 1ms in normal conditions. Scrubbing centers are geographically distributed, and the XDP/eBPF pipeline runs in the kernel fast path without touching userspace.

L3/L4 attack onset triggers mitigation within seconds via BGP re-announcement. L7 filtering is always-on with no onset delay — every request is scored as it arrives.

Yes. Your panel shows network graphs with flagged attack events. We are also building an attack analytics dashboard — join Discord to follow the rollout.

Open a support ticket immediately. Our team deploys custom upstream Flowspec rules and eBPF programs for novel attack patterns — usually within minutes during business hours, and 24/7 for critical outages.

Yes. Our Go balancer handles WebSocket upgrades and applies per-connection rate limiting and anomaly detection to long-lived WS connections, protecting game servers and real-time apps.

Start
protected.

Every plan ships with DDoS protection.
No config, no waiting, no extra cost.

Get started free Talk to the team

No credit card required for free tier