All Products
Search
Document Center

Anti-DDoS:Purchase an Anti-DDoS Proxy instance

Last Updated:Jul 15, 2026

Anti-DDoS Proxy diverts traffic to scrubbing centers, filters malicious traffic, and forwards only clean traffic to your origin server, protecting against terabit-level DDoS attacks.

Select an edition

Edition overview

Product Type

Instance Edition

Core Features and Differences

Notes

Anti-DDoS Proxy (Chinese Mainland)

Profession

Provides an exclusive IP address, multi-line Border Gateway Protocol (BGP) protection, and supports both basic and burstable protection.

-

Advanced

Provides two advanced mitigation sessions per month (resets monthly).

Contact your account manager to activate this edition.

Anti-DDoS Proxy (Outside Chinese Mainland)

Insurance and Unlimited

  • Both the Insurance and Unlimited mitigation plans are for services deployed exclusively outside China. They differ in billing method, capacity, and the number of advanced mitigation sessions. The Insurance plan offers two per month, while the Unlimited plan has no limit.

  • To reduce latency for users in the Chinese mainland accessing sites outside China, use these plans with a Secure Acceleration (Sec-CMA) line. For more information, see Configure Sec-CMA for Anti-DDoS Proxy (outside the Chinese mainland).

-

Sec-CMA 2.0

Provides access acceleration for users in the Chinese mainland and application-layer DDoS protection. After you select a specific number of DDoS mitigation sessions, it gains the capability to defend against large-volume DDoS attacks from China Telecom, China Unicom, and China Mobile lines.

None

Sec-CMA 2.0 (Insurance) and Sec-CMA 2.0 (Unlimited)

Features are mostly the same as Sec-CMA 2.0. You can disable the Metering Method of 95th Percentile Burstable Clean Bandwidth and 95th Percentile Burstable QPS modes.

The features have been migrated to Sec-CMA 2.0. We do not recommend purchasing new instances. This option is only for existing instances.

Chinese Mainland Acceleration and Sec-CMA 1.0

Legacy versions that do not support China Mobile lines.

We do not recommend purchasing new instances. We recommend that you upgrade to Sec-CMA 2.0. Contact your account manager to activate the upgrade.

Scenarios and recommendations

Choose an edition based on your server location and user distribution.

Server location

User Source

Business requirements

Recommended edition

The Chinese mainland

the Chinese mainland and outside the Chinese mainland

General-purpose DDoS protection.

Anti-DDoS Proxy (Chinese Mainland) - Profession

Outside the Chinese mainland

Outside the Chinese mainland only

No cross-border acceleration needed.

Anti-DDoS Proxy (Outside Chinese Mainland) -Insurance or Unlimited

Outside the Chinese mainland

the Chinese mainland

Requires cross-border acceleration to ensure low latency and stability.

Anti-DDoS Proxy (Outside Chinese Mainland)-Sec-CMA 2.0

Outside the Chinese mainland

the Chinese mainland and outside the Chinese mainland

Cross-border acceleration needed without server migration, plus access from outside the Chinese mainland.

Combined purchase:

  • Anti-DDoS Proxy (Outside Chinese Mainland)-Sec-CMA 2.0

  • Anti-DDoS Proxy (Outside Chinese Mainland) -Insurance or Unlimited

Outside the Chinese mainland

within and outside the Chinese mainland

Migrate servers by user region. After migration, each region's users access locally hosted services protected by the corresponding edition.

  • Services for users in the Chinese mainland: Anti-DDoS Proxy (Chinese Mainland) - Profession

  • Services for users outside the Chinese mainland: Anti-DDoS Proxy (Outside Chinese Mainland) - Insurance or Unlimited

Purchase Anti-DDoS Proxy instance

  1. Open the purchase page

    Visit the or the Anti-DDoS Proxy (Chinese Mainland) international purchase page, or visit the or the Anti-DDoS Proxy (Outside Chinese Mainland) international purchase page.

  2. Select Protection Instance and Protection Parameters

    Based on the Purchasing Guide above, select Product Type and DDoS Plan.

    Anti-DDoS Proxy (Chinese Mainland)-Profession

    • Professional Description

      • Connection type: DNS diversion.

      • Resource reservation: 1 exclusive IP address.

      • Bandwidth type: Multi-line BGP.

      • Mitigation capability: Basic protection (subscription) plus burstable protection (pay-as-you-go).

    • Mitigation parameters

      • Endpoint Type: The IP protocol for the instance. Valid values: IPv4 or IPv6. Function Introduction.

        Important

        An IPv6 Anti-DDoS Proxy instance forwards requests from IPv6 clients, with these limits:

        • Website Config supports IPv4 origin servers only.

        • Port Config supports IPv4 or IPv6 origin servers.

      • Basic Protection: The DDoS mitigation threshold.

      • Burstable Protection Bandwidth: Automatically activates burstable protection when attack traffic exceeds the Basic Protection, ensuring uninterrupted service. Pricing: Billing method for elastic protection capability.

        Note

        If you set the Burstable Protection Bandwidth and Basic Protection to the same value, burstable protection will not be triggered.

      • Protection Cluster:

        • You can select a protection node only when the Endpoint Type is IPv4. The available options are Default, North China, North China (Beijing), or East China (Hangzhou).

        • Choose a node based on mitigation capability and access latency. How to choose a protection node.

          Note

          Example: If your origin server is in China (Hangzhou), choose the China (Hangzhou) node for the lowest access latency. Choose the default node for the highest mitigation capabilities.

    Anti-DDoS Proxy (Outside Chinese Mainland)-Insurance and Unlimited

    • Mitigation plan description:

      Warning

      If you use the Insurance or Unlimited alone, users in the Chinese mainland will experience significantly increased latency or access failures. We recommend that you use Sec-CMA 2.0 in combination with these plans to optimize access quality.

      • Access Mode: Traffic steering via DNS parsing.

      • Resource reservation: 1 exclusive Anycast IP address.

      • Mitigation sessions:

        • Insurance: 2 advanced mitigations per month (refreshed monthly)

        • Unlimited: unlimited advanced mitigation

    • Mitigation parameters

      IP Registration Address: Select the IP geolocation based on your actual business needs. Supported locations: Singapore, China (Hong Kong), Japan, US West, US East, United Kingdom, Germany, Malaysia, and Indonesia.

      Note
      • The Indonesia protection node is available only if the IP geolocation is Indonesia.

      • The Malaysia node is available only if the IP geolocation is Malaysia.

    Anti-DDoS Proxy (Outside Chinese Mainland)-Sec-CMA 2.0

    • Mitigation plan description:

      • Connection type: DNS diversion.

      • Resource reservation: 1 exclusive Sec-CMA IP address.

      • Mitigation capability: Accelerates access from the Chinese mainland with application-layer DDoS protection: intelligent protection, global mitigation policy, blacklist/whitelist, geo-blocking, and HTTP flood mitigation.

      • Line support: China Telecom, China Unicom, and China Mobile lines.

    • Mitigation parameters

      • Mitigation Sessions: The number of advanced mitigation sessions. Purchased sessions enable high-volume DDoS advanced mitigation on China Telecom, China Unicom, and China Mobile lines. If set to No, only access acceleration for the Chinese mainland is provided.

        Note

        One session counts for every 24 hours of continuous protection after a DDoS attack starts. The quota resets every calendar month.

      • IP Registration Address: Select the IP registration location based on your actual business requirements. Supported registration locations: Singapore, Japan.

    Anti-DDoS Proxy (Outside Chinese Mainland)-Chinese Mainland Acceleration

    Protection Plan Description

    • Connection type: DNS diversion.

    • Resource reservation: 1 exclusive accelerated IP address.

    Important

    For use only to accelerate access in the Chinese mainland, lacks DDoS mitigation capability, and we recommend that you upgrade to Sec-CMA 2.0.

    Anti-DDoS Proxy (Outside Chinese Mainland) - Sec-CMA1.0

    • Mitigation plan description:

      • Connection type: DNS diversion.

      • Resource reservation: 1 exclusive Sec-CMA IP address.

      • Mitigation sessions: 2 advanced mitigation sessions per month (refreshed monthly).

        Note

        You can purchase a global advanced mitigation session to get more sessions.

      • Mitigation capability: Acceleration for access from the Chinese mainland, plus DDoS protection over China Telecom and China Unicom lines (no China Mobile).

        Note

        To support Anti-DDoS protection for access from outside the Chinese mainland, you can use the Insurance and Unlimited .

      • Line support: China Telecom and China Unicom lines only.

        Important

        If you need support for mobile lines, upgrade to Sec-CMA 2.0.

  3. Configure extended service specifications

    • Clean Bandwidth: Guaranteed bandwidth for normal service traffic.

      Note

      If guaranteed clean bandwidth is insufficient, burstable clean bandwidth is billed on a pay-as-you-go basis. To avoid these charges, upgrade via Upgrade Instance.

      • How to choose:

        • Selection principle

          • If your services run on Alibaba Cloud ECS, view peak traffic in instance monitoring information.

            Note

            This traffic refers to legitimate service traffic and excludes attack traffic.

          • If you deploy multiple origin servers, sum up their legitimate service traffic.

        • Selection example

          You protect three websites. Each has an outbound traffic peak under 50 Mbps. Total traffic does not exceed 150 Mbps. Choose clean bandwidth greater than 150 Mbps.

    • Metering Method of 95th Percentile Burstable Clean Bandwidth: The Daily 95th Percentile is enabled by default (pay-as-you-go). When service traffic exceeds the base Clean Bandwidth, burstable clean bandwidth activates automatically to prevent service interruption. Billing details: Burstable Clean Bandwidth Billing.

      Warning

      Starting 10:00 (UTC+8) on March 6, 2026, the Monthly 95th percentile billing method is no longer available for new purchases. Manual adjustments to burstable clean bandwidth in the console — such as enabling, disabling, changing billing methods, or changing bandwidth specifications — are also no longer available. For details, see [Update] Adjustment to the Anti-DDoS Burstable Billing Feature on March 6, 2026.

      • Formula: Elastic Bandwidth Peak = min(Base Clean Bandwidth × 10, Elastic Bandwidth Upper Limit).

        Note

        The elastic peak represents the default upper limit of allocated elastic resources. When actual business usage exceeds the elastic peak, the product continues to provide service to the best of its ability, and you will incur elastic pay-as-you-go charges based on actual usage. However, packet loss may occur during the cluster scale-out period. We recommend that you promptly upgrade your guaranteed clean bandwidth.

      • Burstable bandwidth limit:

        • Anti-DDoS Proxy (Chinese Mainland): Profession (20,000 Mbps), Advanced (20,000 Mbps)

        • Anti-DDoS Proxy (Outside Chinese Mainland):Insurance(5,000 Mbps), Unlimited (5,000 Mbps), Sec-CMA 2.0 (2,000 Mbps), Chinese Mainland Acceleration (1,000 Mbps), Sec-CMA 1.0 (500 Mbps)

    • QPS: The maximum HTTP/HTTPS request rate the instance handles under normal conditions. Per-tier connection limits: QPS specifications and connection limits.

      Note

      If Clean QPS is exceeded, burstable QPS is billed automatically. Upgrade Clean QPS to avoid these charges. For more information, see Instance upgrade.

      • In the Chinese mainland: The maximum QPS is 100,000.

      • Regions outside the Chinese mainland: The maximum QPS is 150,000.

    • 95th Percentile Burstable QPS: By default, the Daily 95th Percentile is enabled (pay-as-you-go). When actual Clean QPS exceeds the guaranteed baseline QPS, burstable protection activates automatically. For more information, see burstable QPS billing instructions and QPS specifications and corresponding connection limits.

      Warning

      Starting from 10:00:00 UTC+8 on March 6, 2026, new customers can no longer enable the monthly 95th percentile billing mode for burstable QPS. You also cannot manually adjust burstable QPS settings in the console, including enabling or disabling the feature, changing the billing mode, or modifying the specification. For more information, see [Update] Announcement on changes to the burstable billing feature for Anti-DDoS on March 6, 2026.

      • Formula: Burstable QPS peak = min(Clean QPS × 3, Burstable QPS limit).

        Note

        The elastic peak is the upper limit for the elastic resources allocated by default. If your actual usage exceeds the elastic peak, the service is provided on a best-effort basis and you are charged for the elastic resources that you use on a pay-as-you-go basis. However, there is a risk of throttling. To ensure resource reservation beyond the burstable peak, upgrade the clean QPS in advance or contact your account manager for capacity expansion.

      • Burstable QPS limit:

        • The Chinese mainland:

          • IPv4 Anti-DDoS Proxy instance: maximum burstable QPS is 300,000.

          • IPv6 Anti-DDoS Proxy instance: maximum burstable QPS is 100,000.

        • Outside the Chinese mainland: maximum burstable QPS is 150,000.

    • Function Plan: Function plans range from Standard to Enhanced, with different mitigation capabilities and policy limits. Differences between Standard and Enhanced function plans.

      • Standard:

        • Supports 40 HTTP flood mitigation policy rules.

        • Supports up to 200 Layer 7 blacklist and whitelist policies.

      • Enhanced:

        • Supports enhanced application-layer protection to block non-HTTP/HTTPS application-layer attacks.

        • Supports 200 HTTP flood mitigation policy rules.

        • Supports up to 2,000 Layer 7 blacklist and whitelist policies.

        • Supports static page caching to accelerate website access.

        • Supports integration with Alibaba Cloud CDN for acceleration and DDoS protection.

    • Protected Domain Names: Maximum HTTP/HTTPS domains (up to 2000).

      • The associated first-level domains (sites) cannot exceed (Protected Domain Names/10).

      • When you configure domain forwarding, the total number of domain names (including root domain names, subdomains, and wildcard domain names) must not exceed the Protected Domain Names.

      Note

      Assume that the purchased Protected Domain Names is 50, and you have configured three domain names: www.abc.com, *.abc.com, and www.xyz.com.

      • Root domains (sites): 2 (abc.com and xyz.com), which meets the limit of 5 (50/10).

      • Total domain names: 3, which meets the limit of 50.

    • Ports: Number of protected TCP/UDP ports.

    • Resource Group: Resource group the instance belongs to. Default: Default Resource Group. For more information about resource groups, see Create a resource group.

    • Quantity: Select the number of instances to purchase.

    • Duration: Subscription period. If you select Auto-renewal, instances renew automatically. Auto-renewal cycles follow these rules. For more information, see Instance renewal.

      • Monthly purchase: 1-month auto-renewal cycle.

      • Yearly purchase: 1-year auto-renewal cycle.

View instance specifications and activate protection

Quotas and limits

  • ICP filing: Websites deployed in the Chinese mainland must have an ICP filing for their domain name.

  • IPv6 origin server limits: If you purchase an IPv6 Anti-DDoS Proxy instance and use domain-based website service, traffic is forwarded only to IPv4 origin servers.

  • Overseas access limits:

    • If you use the Anti-DDoS Proxy (Outside Chinese Mainland)- Insurance or Unlimited edition alone,  users in the Chinese mainland will experience significantly increased latency or even be unable to access the service.

      Note

      We recommend that you purchase both Anti-DDoS Proxy (Outside Chinese Mainland)Sec-CMA 2.0 to ensure smooth access for users in the Chinese mainland.

    • When you use Anti-DDoS Proxy (Outside Chinese Mainland)Sec-CMA 2.0 by itself, access from regions outside the Chinese mainland is not supported by default.

      Note

      If your services are accessed by clients from outside China, we recommend that you also purchase and use Anti-DDoS Proxy (Outside Chinese Mainland)Insurance or Unlimited.

    • Some protection nodes (such as Indonesia and Malaysia) are available only for instances with matching IP geolocations.

Billing

Fees for Anti-DDoS Proxy consist of subscription instance fees and pay-as-you-go burstable fees.

Cancel service

Refunds are not supported after purchase. Evaluate your service requirements before purchasing.

Appendix

QPS specifications and corresponding connection limits

Each QPS tier has corresponding connection limits. If burstable QPS is enabled, the burstable tier's limits apply.

QPS

New connections

Concurrent connections

0 < QPS ≤ 5,000

5,000

100,000

5,000 < QPS ≤ 10,000

10,000

200,000

10,000 < QPS ≤ 30,000

30,000

500,000

30,000 < QPS ≤ 50,000

50,000

1,000,000

50,000 < QPS ≤ 100,000

80,000

1,500,000

100,000 < QPS ≤ 150,000

100,000

2,000,000

150,000 < QPS ≤ 200,000

Note

Supported only by Anti-DDoS Proxy (Chinese Mainland).

150,000

3,000,000

200,000 < QPS ≤ 300,000

Note

Supported only by Anti-DDoS Proxy (Chinese Mainland).

200,000

4,000,000

Protection node details

Select a protection node based on mitigation capability and access latency. / indicates the node is not recommended for that origin server location.

Origin server location

Protection node

Default

North China

North China (Beijing)

China East 1 (Hangzhou)

China (Beijing)

Strong protection (1 Tbps+).

/

Low latency with mitigation capabilities of up to 600 Gbps.

/

China (Shanghai)

/

Strong protection (1 Tbps+).

/

Low latency with mitigation capacity of up to 600 Gbps.

China (Chengdu)

/

Strong protection (1 Tbps+).

Low latency with mitigation capabilities of 600 Gbps.

/

China (Guangzhou)

Strong protection (1 Tbps+).

/

/

Low latency and 600 Gbps mitigation capabilities.

China (Hangzhou)

Strong protection (1 Tbps+).

/

/

Low latency with 600 Gbps mitigation capacity.

China (Shenzhen)

Strong protection (1 Tbps+).

/

/

Low-latency protection with mitigation capacity of up to 600 Gbps.

FAQ

  • What is a root domain (site)?

    A root domain is the full domain name that a user registers. For example:

    • aliyun.com is a root domain.

    • Subdomains (such as www.aliyun.com and abc.aliyun.com) and wildcard domain names (such as *.aliyun.com) are not root domains. They all belong to the same root domain (site): aliyun.com.

  • How do Anti-DDoS Proxy and Anti-DDoS Native differ? Which should I choose?

    The core differences are the connection type and protection scope.

    • Anti-DDoS Proxy: Proxy-based traffic scrubbing. Protects services by diverting traffic. Supports servers on Alibaba Cloud and outside Alibaba Cloud (such as data centers or other clouds). Mitigates network-layer and application-layer (CC) attacks. Suitable for use cases requiring high mitigation capabilities and service availability.

    • Anti-DDoS Native: Enhancement model. Directly increases the default mitigation threshold for Alibaba Cloud assets such as ECS and SLB. Simple setup—no DNS changes required. Targets network-layer attacks primarily.

    Selection guidance:

    • Choose Anti-DDoS Proxy if your service is a website, needs CC attack defense, runs outside Alibaba Cloud, or requires high mitigation capability.

    • Choose Anti-DDoS Native if your service is a non-website service on Alibaba Cloud and you want simplified setup.