How packets get in and out
A server is only ever as good as the path to it. This page is the whole of ours: how many transits a site runs and why there is never only one, where we peer, what your routes do while you are being attacked, and the exact number behind the word “unmetered”.
Transit, and why there is never only one
Single-homed hosting is cheap, and it works right up until the afternoon your one provider has a bad day in a city you have never visited.
Three providers is the floor. The four 400-gigabit sites run five.
Every site takes transit from at least three separate networks, none of them reselling another. That is deliberate and it costs real money: the last provider you add carries the least traffic at the highest price per bit, right until the day it carries all of it.
Capacity gets bought for the failure case rather than the average one. A site advertising 200 Gbit/s of uplink can lose its largest session at peak without dropping a packet, because everything else is sized to absorb the shift. Nobody notices. That is the point.
At least three transits per site
Distinct networks with distinct upstream paths, landing on distinct routers. No single provider is allowed above forty percent of a site’s committed capacity, which is the number that stops diversity from being decorative.
Sized for n-1, not for the mean
Utilisation targets assume the biggest session is already down. When a site crosses sixty percent under that assumption we start buying; by seventy the new capacity is lit. Average utilisation is a vanity figure and we do not manage to it.
The site figure is not your port
Four hundred gigabits at a site says nothing about your instance. Your port is 10, 25 or 40 Gbit/s, it is dedicated, and the site number only tells you how much room exists behind it.
The routing policy is ours
We hold it, not an upstream. If one provider’s path to a given network turns ugly at three in the morning, we depreference it and the traffic moves before anyone has opened a ticket about it.
Peering, which is unglamorous and works
Open policy at every exchange where we have a port. No ratio requirement, no fee, either direction.
We peer at the regional exchange in each metro that has one, and privately with the large consumer networks wherever the volume justifies a cross-connect. Sessions are settlement-free. Nobody pays us to be reachable and we pay nobody for the privilege of reaching them.
Peering does not make a packet travel faster in any physical sense. What it does is delete a hop, and the hop it deletes is usually the one that was congested at nine on a Sunday evening. Cheaper for us, shorter for you, incentives pointing the same direction for once.
Open, at the exchange
If you are on a fabric we are on, you can have the session. There is no traffic ratio to meet and no paperwork beyond the technical details.
Private where the volume is
Traffic to a single network past a few gigabits sustained gets its own interconnect. That is a capacity decision, not a commercial one, and it is reviewed every quarter.
Filtering in both directions
Customer announcements are filtered to what the customer is entitled to announce. From peers we accept nothing a peer has no business originating, and RPKI-invalid routes are dropped rather than quietly depreferenced.
No paid peering, in or out
A route either exists or it does not. Selling reachability to the networks your users sit behind is a business we have decided to stay out of.
IPv6, on by default rather than on request
Half of this industry still treats IPv6 as a feature request with a queue in front of it. Here it has been the cheaper half of the address plan for years, and every image boots dual-stack without being asked.
A routed /64 with every instance. Subnetting behind it costs four euro for a /48.
Routed, never proxied
The /64 terminates on your instance. Nothing translates it, nothing sits in the middle of it, and reverse DNS is editable from the panel for every address inside it.
A /48 when a /64 runs out
Four euro a month, delegated properly, for anyone putting containers or nested virtual machines on real addresses. Open a ticket and it is routed the same day.
Static, not autoconfigured
Images come up with a static address and router advertisements ignored. Autoconfiguration on a shared hosting VLAN is a coin flip, and a static address survives a live migration without renumbering anything.
v6-only is a supported choice
Run without a public IPv4 address if you like; the platform does not care either way. Every plan includes IPv4 because much of the internet still requires it, not because we insist you switch it on.
Additional IPv4 addresses cost three euro each per month. Above four on one account we will ask what they are for, which is a routing question rather than an identity one: address space is finite and the upstreams audit it.
What your routes do while you are being hit
Almost nothing visible. Filtering already sits in the path, so an attack changes what gets dropped rather than where your traffic goes.
- 01
Telemetry fires
Flow data from every edge router is aggregated on a two-second window. A volumetric event trips the threshold before most monitoring systems have finished their first poll.
- 02
Signatures do the easy work
Amplification and malformed traffic get dropped in hardware at the edge on a match, with no diversion and no human involved. By count, this is the great majority of what arrives.
- 03
Stateful attacks divert
SYN floods, connection exhaustion and anything else that needs state to understand pass through the scrubbing complex, which holds that state so your instance never has to.
- 04
Your announcement stays put
We do not withdraw your prefix, we do not move your address, and your reverse DNS keeps working. The path in is the path it was an hour ago with the rubbish taken out.
- 05
If capacity runs out, you are told
An attack larger than a site can scrub ends with the target address null-routed rather than the site falling over. You get the figures, not an apology template, and the block lifts when the attack stops.
Each site’s scrubbing capacity is printed on its location page: 4 Tbit/s at the smaller sites, 12 Tbit/s at the anchors. That is capacity held permanently in path, not capacity someone would go and buy during an incident.
Unmetered, with the number printed
“Unmetered” without a figure attached is a threat with good manners. Ours is a 95th-percentile rate that scales with your port, calculated monthly, printed here so you can work out whether you are anywhere near it.
Nobody has ever had a surprise bandwidth invoice from us. No mechanism exists that could produce one.
The percentile is taken from five-minute samples across the billing month, each direction counted separately. Bursting to line rate is fine and always has been. A seedbox running flat out for a fortnight is also fine, which surprises people more than it should.
Go past the figure consistently and you get an email suggesting a dedicated 40 Gbit/s port at forty-five euro a month. What arrives instead of an overage invoice is a sentence, because there is no meter here capable of generating the invoice.
| Port | Fair-use rate, 95th percentile | Equivalent over a month | Instances that exceed it |
|---|---|---|---|
| 10 Gbit/s | 2 Gbit/s sustained | about 648 TB | roughly 1 in 400 |
| 25 Gbit/s | 5 Gbit/s sustained | about 1.6 PB | roughly 1 in 90 |
| 40 Gbit/s | 8 Gbit/s sustained | about 2.6 PB | roughly 1 in 20 |
Spam, scanning and the port 25 conversation
We route packets and do not read them, so everything in this section runs on counters and on complaints from the networks you talk to. It has to. In practice it is enough.
Port 25 starts closed
Outbound SMTP is blocked on a new instance. Ask for it, describe in one sentence what you are sending, and it opens. No documents, no company registration, no interrogation beyond checking that your reverse DNS exists.
New instances are briefly rate-limited
Connections per second and outbound mail are capped for the first 24 hours of an instance’s life. Nearly every disposable spam node we have seen does its work inside that window and then vanishes.
Scanning ends the conversation early
Port sweeps and credential stuffing against third parties are the one category acted on before anyone talks to you. The instance stops, you receive the report we received, and you get one chance to explain it.
A person reads every report
Abuse mail lands in front of someone on the network team rather than a classifier. Automated forwards with no evidence attached still get an answer, but they do not move anything on their own.
What we can see, in full
Aggregate flow counters, port and protocol distributions, and whatever a complainant sends us. Not payloads, not a history of where you connected, and nothing kept past the point it stops being useful.
Reports go to [email protected]. If yours is about content rather than network behaviour, the abuse and DMCA page sets out what the law of the site you are complaining about actually obliges us to do, which is frequently less than the complainant expects.
Questions about the network
On bare metal and on EPYC from the E-32 upward, at sites where the upstream allows it. Send your object details in a ticket and you will have an answer within a day, along with the details you need to build the session.
Within a site, yes, at no cost: a private VLAN with no route to anywhere. Between sites you build your own encrypted overlay, and the knowledge base carries a configuration that works rather than a diagram that does not.
If you announce your own space, that is between you and your upstream policy. For addresses we assign, blackholing is a ticket and takes about a minute at any hour of the day.
Because that hop generated the reply on its control plane, which is busy and deprioritises ICMP. It is the single most common false alarm we receive. The looking glass page explains how to read the output properly.
For your own announced space, at sites where the upstream permits it. We do not sell an anycast product of our own, and we would rather say so than sell you a load balancer with a fashionable name.
Nothing you should see. Uplinks are drained one at a time, sessions move to the remaining transits, and the work happens behind capacity that was already there for the failure case.
Measure the path before you pay for anything
The looking glass runs from every site, needs no account, and will tell you more in four minutes than this page can in four thousand words.