CDN and edge bandwidth limits in 2026
CDN and edge bandwidth limits compared through HostScout data: provider coverage, package samples, request caveats and DDoS checks.
Cloud hosting bills and agency operations
She reviews cloud hosting, managed panels, staging workflows, and monthly bills for agency teams.
Compare CDN and edge offers by bandwidth basis, request treatment and DDoS scope before you compare logos. HostScout data shows many providers label CDN as a vertical, but fewer expose clear CDN packages, traffic rules or edge-security pricing in comparable records.
What the data says
The current HostScout sample marks 61 providers with a CDN vertical. Only 12 of those providers expose CDN-specific plans or plan-like packages in the comparable data. That gap matters because a CDN line on the menu is not the same as a usable edge contract.
The practical question is narrower: what happens when cache traffic grows, when origin misses rise, and when hostile traffic reaches the edge? A provider page can say CDN, but the invoice tells the truth through bandwidth basis, request rules, purge behaviour, logs and DDoS scope.
For the English market, the SERP pattern leans hard on architecture explainers: origin, edge server, PoP, Anycast and cache hit. That is useful background. It still rarely answers the buying question. A data note should separate CDN availability from measurable limits.
Provider samples worth checking
These are not rankings. They are comparable samples from the current HostScout data set, useful for reading the small print before you move production traffic.
| Provider | What is visible in the data | Buyer check |
|---|---|---|
| Cloudflare | CDN vertical, English traffic rank 1, and a location label of 337 cities across 8 regions | Check whether your plan includes the security, logs and rules you need |
| DigitalOcean | Spaces Object Storage base bucket at $5.00 per month with 250 GB storage | Check transfer, request and bucket policy costs around your origin design |
| Krystal | 50GB CDN at $6.68 per month and 500GB CDN at $46.73 per month | Check whether your traffic curve fits a fixed package |
| Spaceship | Basic CDN at $4.91 per month and Advanced CDN at $19.91 per month | Check what the package includes before treating it as a generic edge layer |
| Bunny | Volume Network mentions first 500 TB, while Shield Premium for WAF/DDoS is $9.50 per month | Check egress region, request billing and whether security is separate |
| HyperHost | CDN packages at $12.00 and $20.00 per month | Check whether the package is resale, managed setup or a raw CDN tariff |
| Yandex Cloud | CDN traffic package at $1.23, origin shielding at $31.50 and log export at $45.00 per month | Check add-on costs before enabling observability and shielding |
| Imperva | Pro at $59.00 and Business at $299.00 per month in the sample | Check DDoS and WAF scope before assuming edge security is included |
The table deliberately mixes global CDN platforms, hosting bundles and edge-security products. That is how buyers usually meet CDN offers in the wild. The label CDN does not tell you whether bandwidth, requests and DDoS are one product or three separate bills.
Bandwidth is the first cost trap
Bandwidth looks simple until you ask what the unit actually buys. Bunny exposes CDN network entries with a GB egress basis. Krystal presents fixed packages such as 50GB CDN and 500GB CDN. DigitalOcean ties the visible sample to object storage, not a standalone edge plan.
Those are three different buying models. Metered egress scales with traffic. Fixed packages are tidy for predictable sites and awkward for spikes. Storage-linked CDN usage needs a closer look at bucket traffic, cache misses and origin pulls.
If your workload is mostly static assets, bandwidth usually dominates the bill. If it is API-heavy, request handling and cache misses become more important. If video is involved, regional egress and cache-fill behaviour matter more than the headline monthly fee.
Requests and cache misses are rarely shown cleanly
The comparable sample does not give a universal request-per-second field, request price or cache-miss allowance across providers. That absence is a decision signal. If a sales page hides request treatment, assume you need to verify it before launch.
Ask four questions before moving traffic:
- Does the provider bill HTTP requests separately from bandwidth?
- Are purge requests, log delivery or image optimization priced as add-ons?
- Does a cache miss count as edge traffic, origin egress, or both?
- Are bots, failed TLS handshakes and WAF-challenged requests counted toward limits?
For a small WordPress site, these details may stay invisible. For a SaaS dashboard, API, marketplace or media library, request accounting can become the actual limit long before bandwidth looks frightening.
DDoS protection is not the same product everywhere
DDoS language is especially easy to overread. A CDN can absorb traffic at the edge, but that does not prove that application-layer filtering, WAF rules, emergency support and clean traffic forwarding are included in your plan.
Bunny separates a Shield Premium entry with WAF/DDoS wording from its CDN network entries. Yandex Cloud lists origin shielding and log export as priced CDN items. Imperva appears as a security-oriented CDN sample with higher monthly tiers.
That pattern is the important takeaway. DDoS scope is a contract detail, not a checkbox. Check whether the provider covers volumetric attacks, HTTP floods, bot filtering, custom WAF rules, origin hiding and incident support in the plan you can actually buy.
When to choose, when to avoid
Choose a CDN plan when your users are geographically spread, your static assets are heavy, or your origin server should not see every request. Choose a provider with transparent egress and add-on pricing when traffic can spike after campaigns, launches or abuse.
Avoid a vague bundled CDN when the project already has expensive origin bandwidth, strict uptime needs or regulatory constraints around logs. Also avoid it when the provider cannot explain cache purge timing, request accounting, DDoS escalation and support coverage in writing.
Use the CDN provider directory to shortlist candidates, then open provider pages such as Cloudflare, DigitalOcean, Bunny, Krystal and Spaceship for the current provider context.
Checklist
- Check monthly egress and regional bandwidth basis against your traffic peaks, because overage risk can outrun cache-latency gains.
- Check request billing, purge limits and log delivery before launch, because hidden request costs can distort API-heavy workloads.
- Check DDoS and WAF scope at the exact plan level, because edge caching alone does not prove mitigation coverage.
- Check origin shielding and cache-miss treatment, because a CDN can still push cost and load back to your origin.
Data freshness and limits
This note uses HostScout provider and plan samples current to the checked dates behind the article. It treats CDN labels, package names, monthly prices, traffic signals and location labels as comparable data points, not as a complete contract.
The biggest limitation is deliberate: the data does not normalize every provider’s bandwidth price, request price or DDoS ceiling into one universal field. Where the comparable field is missing, the safer editorial answer is to say missing, then make the buyer verify the contract.
FAQ
Is CDN bandwidth always billed per GB?
Do CDN requests matter if bandwidth is cheap?
Does a CDN automatically include DDoS protection?
What should I compare before choosing a CDN?
Prepared by
Cloud hosting bills and agency operations
She reviews cloud hosting, managed panels, staging workflows, and monthly bills for agency teams.
Verified facts
HostScout editorialRelated articles
Fix Slow MySQL Queries Without Guessing
Fix slow MySQL queries with a measured workflow: find the real statement, read EXPLAIN safely, test one index or rewrite, and verify the workload.
Self-host n8n on a VPS: a safe setup plan
Self-host n8n on a VPS with persistent Docker storage, TLS, correct webhook URLs, credential protection, backups, and a tested update plan.
CDN providers compared for real selection
CDN providers compared with verified pricing signals, edge footprint limits, and practical checks for Cloudflare, Akamai, and Fastly.
Machine learning server requirements
Machine learning server requirements for training and inference: compare CPU, GPU, RAM, storage, provider fit, and operational risks.
What Is an IP Address? IPv4, IPv6, Public and Private
What is an IP address? Learn how IPv4, IPv6, public, private, static, and shared addresses affect hosting, DNS, security, and server choice.
Fix slow DNS lookup without guesswork
Slow DNS lookup fixes for hosting buyers: isolate resolver delay, clean bad records, tune TTLs, and use CDN prefetch without hiding risk.