Skip to content
Loafhosts
Included on every plan

Project Zomboid DDoS protection that is already on.

Project Zomboid holds a Steam relay port beside the game port and keeps the world, and every character in it, on the server. Long running saves are the whole point of the game.

Project Zomboid hosting from $19.50/mo, protection included.

always on
500+ Tbps

Absorbed at the edge

13+ Tbps

Game aware filtering

6

Every region we run

$0

Never an upsell

Terabit DDoS Protection, on every Project Zomboid build
Built for Project Zomboid

Project Zomboid server protection, tuned to how the game talks.

The filtering in front of your server is the Terabit mitigation network. It keeps hosting online through volumetric floods, protocol abuse and the game specific patterns that generic filtering treats as ordinary traffic, and it does that without adding latency to a single player.

  • Stateful, game aware filtering with up to 13+ Tbps of capacity worldwide.
  • Up to 500+ Tbps of volumetric capacity absorbed through transit partners.
  • Always on, with no detection delay and no added latency when it engages.
  • Attack leak patching handled by the network's own engineers.
Configure your Project Zomboid server
Key art from Project Zomboid

What the internet can reach.

Mitigation is only as good as its understanding of what it is protecting. These are the ports a server has to leave open to be playable, and what each one invites.

UDP 16261
Game

The world and every character in it, none of which live on the player's machine.

UDP 16262
Steam

Reachable independently of the game port, so it can be pressured on its own while the game port still looks perfectly healthy.

These are the player facing defaults, the same ones published in every server browser. Control ports are deliberately not listed: on a page about attack surface, enumerating the control plane is pointing at it.

Attacks Project Zomboid servers face.

Volumetric floods are the easy half. The half that breaks game servers is abuse that looks almost exactly like a real player.

Project Zomboid specific

Relay port abuse

The Steam facing port is reachable independently of the game port, so it can be pressured on its own while the game port looks entirely healthy.

Project Zomboid specific

Volumetric flood

Enough raw traffic to saturate the link in front of an otherwise healthy server. Nothing on the box is wrong, which is what makes it hard to diagnose without filtering upstream.

Project Zomboid specific

Save window targeting

An unclean stop between writes costs progress the server had not committed yet, which on a months old save is not a small loss.

Every server

Volumetric floods

UDP and TCP floods, ICMP, DNS amplification, NTP reflection and memcached abuse. Traffic profiles whose only goal is to saturate the link, which they can do without the server ever noticing.

Every server

Protocol attacks

SYN floods, fragmented packets, LAND variants and state exhaustion. These do not need volume, only asymmetry: each packet costs far more to process than it does to send.

Every server

Botnet and zero day

Distributed traffic from compromised hosts with mixed signatures that adapt over time, and novel patterns nobody has a filter for yet. Both are answered by people rather than by a rule written in advance.

Four stages, none of them on your node.

Filtering happens upstream. By the time traffic reaches your server it has already been through every stage below.

01

Anycast ingress

Traffic enters at the closest edge instead of one choke point, so a flood is split geographically before anything is filtered.

02

Volumetric scrubbing

L3 and L4 floods are absorbed at edge capacity. The bulk of any attack dies here, off your node entirely.

03

Stateful filtering

What survives meets protocol aware rules that understand what a real Project Zomboid join looks like and what a forged one looks like.

04

Clean traffic

Only validated traffic reaches your server. Your players stay connected and your tick rate does not move.

How the network compares.

What generic hosting ships out of the box, next to the filtering in front of your Project Zomboid server.

DDoS mitigation compared across Terabit.io, the parent company, and five other hosting providers
Capability Terabit.io Parent company OVHcloud Qonzer Serverse Hetzner Nitrado
Edge filtering capacity 500+ Tbps / 13+ Tbps 50+ Tbps 20+ Tbps / 100+ Gbps 10 Gbps Not stated Not stated
Global points of presence 13+ 40+ Not stated Not stated 5+ 12
Mitigation latency 0 ms 0 to 5 ms Variable 0 to 5 ms 0 ms Variable
Filtering pipeline Triple layer Advanced Advanced Advanced Basic Basic
Layer protection L3 / L4 / L7 L3 / L4 / L7 L3 / L4 L3 / L4 / L7 L3 / L4 L3 / L4
Always on mitigation Included Partial Included Partial Not included Not included
Anycast network Included Included Included Included Not included Not included
Game aware filters Included Partial Included Partial Not included Not included
Custom filters Included Not included Not included Not included Not included Not included
A2S query caching Included Not included Not included Not included Not included Not included
Mitigation dashboard Included Partial Included Not included Not included Not included
Owned infrastructure Included Included Partial Not included Partial Not included
Attack leak response Live engineer response Standard Not stated Not stated Standard Not stated
Get protected

Scroll the table sideways to see every provider.

Comparison data is drawn from each provider's publicly advertised pages, checked August 2026. Providers change what they publish, so treat it as a snapshot rather than a live feed.

A save measured in months

An attack lands when it costs you the most.

Zomboid worlds run for a very long time. The cost of an outage is not the session, it is the risk to a save nobody wants to restart.

That is the entire argument for filtering that is always on rather than filtering somebody switches on after the complaints start.

Mitigation built around game traffic.

Generic filtering is written for websites. Almost none of what breaks a game server looks like a web request.

Stateful capacity, in house

Up to 13+ Tbps of stateful filtering worldwide, owned and operated rather than rented from someone further upstream.

Volumetric headroom

Up to 500+ Tbps of volumetric capacity through transit partners, absorbed at the edge before it reaches a node.

Always on, zero added latency

Filtering never waits to be switched on, and engaging it does not cost your players a millisecond of ping.

Leaks patched by engineers

When something novel gets through, the people who tune the filters work here. It is not a ticket handed to an upstream vendor.

Priced by resources, not slots

You pay for memory, cores and storage. Protection is not a tier, an add on, or a reason to sell you a bigger plan.

Built for both shapes of attack

A hundred gigabits of junk and a precisely crafted handshake abuse are different problems. The pipeline is designed to answer both.

There is no tier to choose.

The filtering is identical on every server we run. The only thing left to decide is whether you want an IP address that is yours alone.

Included
On every plan
Not an add on, and not a tier you select.
Always on
From minute one
Never waits for someone to notice an attack.
0 ms
Added latency
Filtering happens upstream, not on your node.
Alerts
When you are hit
Discord and email when it starts, and when it clears.

Loafhosts is part of Terabit.io, and the protection on your Project Zomboid server is the Terabit mitigation network: 500+ Tbps of volumetric capacity absorbed at the edge, and 13+ Tbps of stateful filtering that admits only the traffic your server expects. It runs in Dallas, Los Angeles, New York, Montreal, Frankfurt and Sydney, which is every region we operate.

Project Zomboid DDoS protection questions.

Is DDoS protection included with every Project Zomboid server?

Yes. Terabit DDoS Protection is on every Project Zomboid server from the first minute, at no extra cost. There is no tier to choose, nothing to switch on, and no upsell. It covers 500+ Tbps of volumetric capacity and 13+ Tbps of stateful filtering.

What kinds of attacks does it stop on a Project Zomboid server?

Relay port abuse, Volumetric flood, Save window targeting, alongside the general volumetric and protocol families. Project Zomboid holds a Steam relay port beside the game port and keeps the world, and every character in it, on the server. Long running saves are the whole point of the game.

Will the filtering add latency to my server?

No. Mitigation is always on and runs upstream of your node rather than on it, so there is no detection delay to wait through and no filtering cost on your own hardware.

Do I need a dedicated IP for Project Zomboid?

No. The filtering is the same on every server regardless of whether the IP is shared or yours alone. A dedicated IP is offered because some people want an address of their own, not because it filters differently.

What happens if an attack gets through?

Attack leak patching is handled by the Terabit network team rather than passed to an upstream vendor. Every server keeps its own attack history, so you can see when you were hit and how long it ran.

Launch a protected Project Zomboid server.

You do not configure it, you do not pay extra for it, and you do not wait for an attack to find out whether it works.

Included on every plan · No setup fees · Cancel any time