You're right. I fixed the copy to clarify its functionality. The blackhole feed doesn't actually sit in your traffic path; it tells your own router what to drop by creating longer CIDRs. Traffic still reaches you over your real ISP connection same as always - your router just can't send an ACK reply back, so it kills the handshake and prevents brute force attacks. If you also set up uRPF (covered in our setup docs), it goes a step further and drops their packets on arrival instead of just failing your reply. In this case, since we're not a transit provider, preventing volumetric attacks can be a little bit tricky since we're not actually in your upstream. However, it is possible to ETL chain data and generate a filter list. I figured at this price point, volumetric protection is a little bit hard to implement.