I have relays on Digital Ocean as well, and occasionally get the same emails. Notice the contradiction in the email:
"Once the attack subsides, networking will be automatically reestablished to your droplet. The networking restriction is in place for three hours and then removed."
Which one is it? Do you automatically reconnect my node when the attack subsides, or do you just wait three hours? (It's always the latter.)
"Please note that we take this measure only as a last resort when other filtering, routing, and network configuration changes have not been effective in routing around the DDoS attack."
That seems to be disingenuous as well. They have never, ever done anything other than shut of my node for 3 hours. Requests for more information about the nature of the attack go unanswered.