Dedicated Hosting

How to choose a dedicated server in 2026: a buyer’s checklist

How to choose a dedicated server in 2026: a buyer’s checklist

Most people buying a dedicated server overspend on the CPU and underspend on the network and backups. The processor is the big number on the spec sheet, so it gets the attention, but bad routes and a missing offsite copy are what actually cost you. Here’s the checklist I’d work through in 2026, in order.

1. CPU: match the generation to the job

Start with what the box will do all day, not what it might do someday.

A dual Xeon E5-2670 v2 makes a good test case. Intel launched that chip in September 2013 with 10 cores and 20 threads per socket, DDR3 memory and no AVX2 (spec table). For compute, it’s slow by 2026 standards. It also can’t run RHEL 10, which raised its baseline to x86-64-v3, a level that starts with Intel’s Haswell generation. AlmaLinux 10 still ships a build that runs on it.

For moving bytes, though, that chip is fine. Download mirrors, backup targets, CDN caches and video relays spend their day waiting on the network card, and the CPU mostly idles. That’s why our 10 Gbps unmetered packages run on exactly that processor. You’re paying for the port.

It’s the wrong buy for heavy database queries, CI builds, video encoding or anything that pins a single core. Pay for a newer generation there. Licensing is another reason: Windows Server is licensed per physical core with a 16-core minimum per server (Microsoft’s guidance), so a 20-core older box costs more to license than a faster 16-core one.

Our browse page lists Xeon E3-1200, E5-2600, Xeon D and Xeon Silver families. A family name can span several generations (the E5-2600 line ran from v1 to v4), so ask which version you’re getting, then check the model with lscpu once the server is live.

2. RAM: ECC, sized to the working set

Get ECC. Google’s study of its own fleet found more than 8% of DIMMs saw errors each year. ECC corrects single-bit errors and logs them, so you spot a failing stick before it corrupts data. DDR5’s on-die ECC doesn’t count; it fixes errors inside the chip and tells the OS nothing.

Then size memory to your working set, meaning the hot part of your database and cache. If that fits in RAM, the disks barely matter.

3. Storage: NVMe where latency counts

SATA tops out at 600 MB/s at the interface. NVMe drives on PCIe run several times faster and handle deep parallel queues, which is what databases and busy VM hosts need. For static files and backup targets, SATA SSDs or even spinning disks are fine.

Plan listings often just say “1 TB SSD.” Ask whether that’s NVMe or SATA.

4. RAID is not a backup

RAID 1 keeps you running when a disk dies. It also copies a bad rm -rf, a ransomware pass or a corrupted table to both disks within milliseconds, because mirroring is its job.

A backup is a separate copy you can roll back to. The 3-2-1 rule is still the floor: three copies, on two kinds of media, with one offsite. Then test a restore. An untested backup is a guess.

This is where most buyers underspend. Our dedicated servers page says new orders include free R1Soft backups up to 1 TB, stored on our own backup infrastructure, with Veeam and DRaaS available on top. Whatever your host provides, keep one copy somewhere your hosting account can’t delete.

5. Bandwidth: know which model you’re buying

This is the other big underspend, and the one people misread most.

ModelHow it’s billedGood fitWatch for
Metered transferSet TB per month, overage per GB or TBModest traffic that rarely growsOverage rates; 30 TB is only ~93 Mbps averaged 24/7
95th percentile5-minute samples, top 5% dropped (~36 hours a month), billed on the next-highest MbpsSteady traffic with short spikesSpikes lasting longer than ~36 hours get billed
Unmetered portFlat fee for a port speed, such as 1 or 10 GbpsHeavy output all dayOversold uplinks and fair-use caps; ask if the port is shared
Cloud egressPer GB; AWS charges $0.09/GB for the first 10 TB, then $0.085Small or bursty output30 TB a month out of AWS runs about $2,650

The 95th percentile details follow the standard burstable billing method. Every GigeNET dedicated plan includes 30 TB+ of public bandwidth, and our unmetered servers come with 10 Gbps full-duplex ports for traffic that never lets up. What a 10Gbps unmetered offer should include covers the traps: shared uplinks, fair-use clauses and 1G commits.

Wholesale transit keeps getting cheaper. TeleGeography’s Q2 2026 data puts the cheapest 10 GigE transit in competitive markets at $0.07 per Mbps per month. If a host’s overage rates look steep next to that, ask why.

6. Network quality: check it before you pay

A spec sheet won’t show you routing quality. These checks will.

  • Upstreams. You want several transit providers, so one carrier’s bad day isn’t yours. Look up the host’s ASN on bgp.he.net or PeeringDB instead of trusting a logo wall. Our Chicago page names Cogent, GTT, PCCW and Zayo.
  • Looking glass. Run pings and traceroutes from the host’s network toward your users’ ISPs. Ours is at lg.gigenet.com.
  • Test IP. Ask for one, then run mtr and a big download from where your users actually sit. We publish ours: the looking glass lists a 1 GB test file for each location, like speedtest.chi.gigenet.com/1gb.img in Chicago, and you can mtr the same host.

7. DDoS protection: included, and what happens at the limit

Most attacks are small and short. Cloudflare’s H1 2026 report found 96.62% of network-layer attacks stayed under 500 Mbps and 90.60% ended within 10 minutes, and it notes that 100 Mbps is enough to knock over an unprotected server. The ceiling keeps rising too, with a record 31.4 Tbps attack in Cloudflare’s 2026 threat report.

So ask two things. Is protection always on and included in the price? And when an attack exceeds the included tier, does the host scrub it or null-route your IP until it stops?

Every GigeNET server includes baseline DDoS protection with always-on detection and filtering, per our DDoS mitigation page, and larger ProxyShield® tiers are quoted separately. Whoever you buy from, get two things in writing before you sign: how large an attack the included protection absorbs, and what happens to your IP when one goes past that. That goes for us too.

8. IPMI, KVM and provisioning time

Out-of-band access isn’t optional. When a kernel update won’t boot or a firewall rule locks you out, IPMI or KVM-over-IP gets you to the console without waiting on a ticket. Our Chicago page lists SSH, RDP, IPMI and KVM-over-IP, and the client portal handles OS reinstalls and remote reboots.

Just don’t leave IPMI open to the internet. CISA has warned about this since 2013: keep it on a management VLAN or behind a VPN. Ours sits on a private management network by default.

Stock builds should go live fast; custom builds take longer. With us, an in-stock configuration goes live the same day or the next. A custom build means ordering parts, so plan on a week or less.

9. SLA fine print

A 100% uptime SLA is a credit schedule, not a guarantee. If the network drops, you get a slice of that month’s fee back as credit. It’s typically capped at one month and only paid if you file a claim in time, and maintenance, upstream carrier failures and DDoS attacks are often carved out. No SLA pays for your lost sales.

Our SLA works the same way. Credits apply to future bills only, they’re capped at that month’s fee for the affected service, and you claim them by ticket within ten business days. It also sets tighter targets for managed plans: 99.5% network availability, a 30-minute ticket response and 2-hour hardware replacement unmanaged, versus 99.95%, 15 minutes and 1 hour with a management package. Check which tier you’re on. The numbers that matter day to day are hardware replacement and support response times, because they decide how long a failure actually lasts.

10. Managed or unmanaged

Unmanaged means you own the OS and everything above it while the host handles hardware and network. Managed means the host also patches and monitors the OS. My rule is simple. If nobody on your team will patch a kernel CVE on a Saturday, buy managed; if someone will, go unmanaged and spend the difference on backups.

11. Contract terms and price-lock

Monthly terms cost more but let you walk away. Longer terms usually come with a discount, and the catch is often the renewal. Check whether the renewal price matches the first term, whether setup fees apply, and what happens to “special” pricing after year one, then get the renewal price in writing.

Here’s our answer: no teaser rates. Your first-term price isn’t an intro discount that jumps to list price at renewal.

Questions to ask sales

  1. What exact CPU model and generation is in this build?
  2. Is the SSD NVMe or SATA, and is the RAID hardware or software?
  3. Which bandwidth billing model applies, and what’s the overage rate?
  4. Is the port dedicated, or shared with other servers?
  5. How much DDoS capacity is included, and what happens above it?
  6. Where are backups stored, and how do I run a restore?
  7. Is IPMI on a private network?
  8. What will I pay at renewal?

FAQ

How much data can a 1 Gbps unmetered port move in a month?

About 324 TB in one direction if you run it flat out for 30 days. Real traffic has peaks and troughs, so most busy servers use a fraction of that. Even a third of it is more than three times a 30 TB metered allowance.

How often should I test a restore?

Quarterly at minimum, and after any big change to the app or database. Restore onto a spare server, time it, and confirm the application actually starts. That time is your real recovery time, whatever the SLA says.

What’s the difference between IPMI and KVM-over-IP?

IPMI is the management controller built into the server board, handling power control, sensors and usually a remote console. KVM-over-IP is the remote keyboard, video and mouse view, delivered through that controller or a separate device. Either way, you get the console when the OS won’t answer.

You can see current builds and pricing on our dedicated servers page. If you’d rather have us spec it, send the workload through the custom quote form and we’ll size the whole thing, not only the CPU.