TCP connection exhaustion
Because the protocol is plain TCP, half open connections are cheap to create and expensive to hold. The slot table fills and real players are refused.
Terraria and tModLoader accept raw TCP connections on a single port with no Steam query in front of them. The connection path is the attack surface, and it is thin.
Terraria hosting from $12.50/mo, protection included.
Absorbed at the edge
Game aware filtering
Every region we run
Never an upsell
The filtering in front of your server is the Terabit mitigation network. It keeps hosting online through volumetric floods, protocol abuse and the game specific patterns that generic filtering treats as ordinary traffic, and it does that without adding latency to a single player.
Mitigation is only as good as its understanding of what it is protecting. These are the ports a server has to leave open to be playable, and what each one invites.
Plain TCP with no Steam query in front of it. The handshake is the attack surface: half open connections are cheap to create and expensive to hold.
These are the player facing defaults, the same ones published in every server browser. Control ports are deliberately not listed: on a page about attack surface, enumerating the control plane is pointing at it.
Volumetric floods are the easy half. The half that breaks game servers is abuse that looks almost exactly like a real player.
Because the protocol is plain TCP, half open connections are cheap to create and expensive to hold. The slot table fills and real players are refused.
The classic TCP attack, and directly applicable here in a way it is not for the UDP games. It costs the attacker almost nothing per packet.
Straightforward saturation of the link, which a healthy server cannot detect from the inside because nothing on it is failing.
UDP and TCP floods, ICMP, DNS amplification, NTP reflection and memcached abuse. Traffic profiles whose only goal is to saturate the link, which they can do without the server ever noticing.
SYN floods, fragmented packets, LAND variants and state exhaustion. These do not need volume, only asymmetry: each packet costs far more to process than it does to send.
Distributed traffic from compromised hosts with mixed signatures that adapt over time, and novel patterns nobody has a filter for yet. Both are answered by people rather than by a rule written in advance.
Filtering happens upstream. By the time traffic reaches your server it has already been through every stage below.
Traffic enters at the closest edge instead of one choke point, so a flood is split geographically before anything is filtered.
L3 and L4 floods are absorbed at edge capacity. The bulk of any attack dies here, off your node entirely.
What survives meets protocol aware rules that understand what a real Terraria join looks like and what a forged one looks like.
Only validated traffic reaches your server. Your players stay connected and your tick rate does not move.
What generic hosting ships out of the box, next to the filtering in front of your Terraria server.
| Terabit.io Parent company | OVHcloud | Qonzer | Serverse | Hetzner | Nitrado | |
|---|---|---|---|---|---|---|
| Edge filtering capacity | 500+ Tbps / 13+ Tbps | 50+ Tbps | 20+ Tbps / 100+ Gbps | 10 Gbps | Not stated | Not stated |
| Global points of presence | 13+ | 40+ | Not stated | Not stated | 5+ | 12 |
| Mitigation latency | 0 ms | 0 to 5 ms | Variable | 0 to 5 ms | 0 ms | Variable |
| Filtering pipeline | Triple layer | Advanced | Advanced | Advanced | Basic | Basic |
| Layer protection | L3 / L4 / L7 | L3 / L4 / L7 | L3 / L4 | L3 / L4 / L7 | L3 / L4 | L3 / L4 |
| Always on mitigation | Included | Partial | Included | Partial | Not included | Not included |
| Anycast network | Included | Included | Included | Included | Not included | Not included |
| Game aware filters | Included | Partial | Included | Partial | Not included | Not included |
| Custom filters | Included | Not included | Not included | Not included | Not included | Not included |
| A2S query caching | Included | Not included | Not included | Not included | Not included | Not included |
| Mitigation dashboard | Included | Partial | Included | Not included | Not included | Not included |
| Owned infrastructure | Included | Included | Partial | Not included | Partial | Not included |
| Attack leak response | Live engineer response | Standard | Not stated | Not stated | Standard | Not stated |
| Get protected | ||||||
Scroll the table sideways to see every provider.
Comparison data is drawn from each provider's publicly advertised pages, checked August 2026. Providers change what they publish, so treat it as a snapshot rather than a live feed.
A modded Terraria world is a specific set of mods at specific versions plus the world they built. Restarting that is not a small ask.
That is the entire argument for filtering that is always on rather than filtering somebody switches on after the complaints start.
Generic filtering is written for websites. Almost none of what breaks a game server looks like a web request.
Up to 13+ Tbps of stateful filtering worldwide, owned and operated rather than rented from someone further upstream.
Up to 500+ Tbps of volumetric capacity through transit partners, absorbed at the edge before it reaches a node.
Filtering never waits to be switched on, and engaging it does not cost your players a millisecond of ping.
When something novel gets through, the people who tune the filters work here. It is not a ticket handed to an upstream vendor.
You pay for memory, cores and storage. Protection is not a tier, an add on, or a reason to sell you a bigger plan.
A hundred gigabits of junk and a precisely crafted handshake abuse are different problems. The pipeline is designed to answer both.
The filtering is identical on every server we run. The only thing left to decide is whether you want an IP address that is yours alone.
Loafhosts is part of Terabit.io, and the protection on your Terraria server is the Terabit mitigation network: 500+ Tbps of volumetric capacity absorbed at the edge, and 13+ Tbps of stateful filtering that admits only the traffic your server expects. It runs in Dallas, Los Angeles, New York, Montreal, Frankfurt and Sydney, which is every region we operate.
Yes. Terabit DDoS Protection is on every Terraria server from the first minute, at no extra cost. There is no tier to choose, nothing to switch on, and no upsell. It covers 500+ Tbps of volumetric capacity and 13+ Tbps of stateful filtering.
TCP connection exhaustion, SYN flood, Volumetric flood, alongside the general volumetric and protocol families. Terraria and tModLoader accept raw TCP connections on a single port with no Steam query in front of them. The connection path is the attack surface, and it is thin.
No. Mitigation is always on and runs upstream of your node rather than on it, so there is no detection delay to wait through and no filtering cost on your own hardware.
No. The filtering is the same on every server regardless of whether the IP is shared or yours alone. A dedicated IP is offered because some people want an address of their own, not because it filters differently.
Attack leak patching is handled by the Terabit network team rather than passed to an upstream vendor. Every server keeps its own attack history, so you can see when you were hit and how long it ran.
Same network, same posture, a different surface to defend.
You do not configure it, you do not pay extra for it, and you do not wait for an attack to find out whether it works.
Included on every plan No setup fees Cancel any time