DDoS attacks are difficult to prevent because attackers can spoof IP addresses. This document proposes an interdomain packet filter (IDPF) architecture that can mitigate IP spoofing without requiring global routing information. The IDPFs are constructed from Border Gateway Protocol route updates and deployed in border routers. Simulation studies show IDPFs can limit spoofing by attackers and help localize the origin of attack packets to a small number of networks.