All Products
Search
Document Center

Anti-DDoS:Billing center

Last Updated:Jul 15, 2026

This topic describes how to query usage details when you use a DDoS Native Protection 2.0 instance.

Usage notes

In a multi-account management scenario, you can query usage details for the public IP assets of member accounts only by using the management account. You cannot query such information by using member accounts. For more information, see Multi-account management.

Pay-as-you-go instances

Query usage details of a pay-as-you-go instance

  1. Go to the Billing Management page of the Traffic Security console.

  2. On the Pay-as-you-go Instances tab, view the overview and details of the current month's usage.

    Usage metric

    Description

    Feature activation

    You are billed based on the number of days the feature is activated. The fee varies depending on the region where your protected assets are deployed.

    Protected IP addresses

    This includes the number of standard cloud products and DDoS Protection (Enhanced Edition) EIPs.

    • You are charged based on a tiered pricing model according to the number of protected asset IP addresses.

    • The IP usage on day T is calculated on day T+1, based on the approximate IP count around 23:00 Beijing time on day T.

    • In a multi-account unified management scenario, the system separately displays the number of IP addresses under the current Alibaba Cloud account and under member accounts.

    Clean traffic

    Clean traffic refers to the normal business traffic generated on cloud products, excluding attack traffic. You can query the actual traffic usage and bill measurement value for a specified date, and view more detailed traffic data by region and asset IP dimension. For more information, see the Query traffic usage of a pay-as-you-go instance section below.

    • To simplify and standardize billing, the traffic measurement data is sourced from cloud products and uses the larger value between outbound and inbound traffic.

    • Standard cloud products and DDoS Protection (Enhanced Edition) EIPs are billed separately at different unit prices.

    • Traffic within mainland China and traffic outside mainland China are separately billed based on a tiered pricing model.

    • The clean traffic usage on day T is calculated on day T+1.

    • In a multi-account unified management scenario, the system separately displays the traffic of IP assets under the current Alibaba Cloud account and under member accounts.

Query traffic usage of a pay-as-you-go instance

A minimum traffic commitment applies. If your daily traffic is less than the minimum commitment, you are billed for the minimum committed amount.

Asset type

Asset IP region

IP count

Minimum daily traffic per IP

Regular Alibaba Cloud service

Chinese mainland

No minimum traffic commitment. You are billed for your actual traffic.

Regions outside the Chinese mainland

EIP with Anti-DDoS (Enhanced) enabled

Chinese mainland

IP count ≤ 30

0 GB

31 ≤ IP count ≤ 99

20 GB

IP count ≥ 100

40 GB

Regions outside the Chinese mainland

No minimum traffic commitment. You are billed for your actual traffic.

  • Example 1: You protect 32 EIPs with Anti-DDoS (Enhanced) enabled. Among them, 12 IP addresses each generate 10 GB of daily traffic, and 20 IP addresses each generate 15 GB of daily traffic.

    The total billable daily traffic is 32 × 20 GB = 640 GB.

  • Example 2: You protect 32 EIPs with Anti-DDoS (Enhanced) enabled. Among them, 12 IP addresses each generate 30 GB of daily traffic, and 20 IP addresses each generate 15 GB of daily traffic.

    The total billable daily traffic is (12 × 30 GB) + (20 × 20 GB) = 760 GB.

  1. Go to the Billing Management page of the Traffic Security console.

  2. On the Pay-as-you-go Instances tab, view the traffic usage of standard cloud products and DDoS Protection (Enhanced Edition) EIPs.

    Data description:

    • The system calculates the traffic bill measurement value for protected assets within the current month. You can also view data by region.

    • The traffic bill measurement value for a specified date.

    • The actual traffic usage and bill measurement value for a specified date. You can also view more detailed traffic data by region and asset IP dimension.

      • Regional usage distribution: Click Details in the Usage by Region column to view the actual traffic usage by region.

      • Asset usage distribution: Click Details in the Usage by Asset column to view the actual traffic usage and bill measurement value by asset IP dimension. You can also click Export below the Usage by Asset tab to export all asset usage distribution data in xlsx format by default.

Bandwidth limits for DDoS Protection (Enhanced Edition) EIPs

Bandwidth limits apply only to DDoS Protection (Enhanced Edition) EIPs. Standard cloud products are not subject to bandwidth limits. The bandwidth limits vary based on the region of the protected public IP assets. You can click Details to apply for an adjustment to the peak bandwidth.

  • Peak inbound bandwidth for access within the same region: In this scenario, the client and the DDoS Protection (Enhanced Edition) EIP are deployed in the same region. If both are outside mainland China, the peak inbound bandwidth does not exceed 2 Gbps. If both are in mainland China, the peak inbound bandwidth does not exceed 20 Gbps.

  • Peak inbound bandwidth for cross-region access: In this scenario, the client and the DDoS Protection (Enhanced Edition) EIP are deployed in different regions. If the EIP is outside mainland China, the peak inbound bandwidth does not exceed 100 Mbps. If the EIP is in mainland China, there is no limit on the peak inbound bandwidth.

  1. Go to the Billing Management page of the Traffic Security console.

  2. On the Pay-as-you-go Instances tab, view the traffic usage of DDoS Protection (Enhanced Edition) EIPs for the current month.

    The bandwidth limits vary based on the region of the protected public IP assets. On the Billing Management page, click Details in the upper-right corner to apply for an adjustment to the peak bandwidth. In the Instance Specifications section at the bottom of the page, the clean bandwidth quota (inbound) for DDoS Protection (Enhanced Edition) EIPs is displayed: The peak inbound bandwidth for access within the same region is 2 Gbps (outside mainland China) or 20 Gbps (mainland China), and the peak inbound bandwidth for cross-region access is 100 Mbps (outside mainland China) or unlimited (mainland China).

Subscription instances

Query specification overlimit alerts

Procedure

  1. Go to the Billing Management page of the Traffic Security console.

  2. On the Subscription Instances tab, select Alerts on Exceeded Upper Limits. You can also click View in the Actions column to view the overall trends of Clean Bandwidth (Inbound), Clean Bandwidth (Outbound), and Clean Bandwidth.

Usage notes

  • You can query specification overlimit alerts for up to the last 30 days.

  • DDoS Native Protection allows business traffic peaks to temporarily exceed the instance bandwidth. When the cumulative overlimit duration reaches 1 hour, 9 hours, 18 hours, 27 hours, or 36 hours within a month, the system sends a reminder through the Message Center on the following day (T+1) in the morning. When the cumulative overlimit duration reaches 36 hours, the DDoS Native Protection capability becomes invalid, and only basic protection is retained. For more information, see Bandwidth limit and overage recovery.

Query elastic business bandwidth usage

Important

Starting from 10:00 on May 28, 2026, DDoS Native Protection no longer supports the monthly 95th percentile billing mode for elastic business bandwidth. Both new and existing users will have the daily 95th percentile billing mode enabled by default. You will no longer be able to manually adjust the configurations for elastic business bandwidth in the console (including enabling or disabling the feature, changing the billing mode, or modifying the bandwidth specification). For more information, see [Important] Adjustments to Anti-DDoS burstable billing feature.

  1. Go to the Billing Management page of the Traffic Security console.

  2. On the Subscription Instances tab, select Daily 95th Percentile or Monthly 95th Percentile. You can also click View in the Actions column to view details such as the total traffic peak value.

    Billing mode

    Data description

    Daily 95th percentile

    • Total traffic peak value: Within a calendar day, the system samples the business traffic peak at 5-minute intervals, yielding 288 data points per day. After excluding values during DDoS attacks and the top 5 values, the maximum of the remaining values is taken.

    • Portion exceeding baseline bandwidth: Total traffic peak value minus the baseline business bandwidth.

    • 95th percentile billing bandwidth: min(total traffic peak value, total business bandwidth) minus the baseline business bandwidth, where the total business bandwidth is 5 times the baseline business bandwidth.

    Monthly 95th percentile

    • Total traffic peak value: Calculated as follows.

      1. Obtain the daily bandwidth peak: Within a calendar day, the system samples the business traffic peak at 5-minute intervals, yielding 288 data points per day. After excluding values during DDoS attacks, the maximum of the remaining values is taken as the daily bandwidth peak.

      2. Calculate the total traffic peak: Sort the daily bandwidth peaks within a calendar month in descending order and calculate the average of the top 5 values, which is the total traffic peak value.

    • Portion exceeding baseline bandwidth: Total traffic peak value minus the baseline business bandwidth, where the baseline business bandwidth is the baseline bandwidth on the last day when elastic business bandwidth was enabled within the current month.

    • 95th percentile billing bandwidth: min(total traffic peak value, total business bandwidth) minus the baseline business bandwidth.

      • Total business bandwidth: Take the baseline business bandwidth values corresponding to the top 5 daily bandwidth peaks, find the maximum among them, and the total business bandwidth is 5 times that maximum value.

      • Baseline business bandwidth: The baseline business bandwidth on the last day when elastic business bandwidth was enabled within the current month.

Related topics

For specific fees for each usage metric of Anti-DDoS Native 2.0 instances, see Anti-DDoS Native 2.0 (Subscription) and Anti-DDoS Native 2.0 (Pay-as-you-go).