For Minecraft networks under attack

Kernel-Level DDoS Protection for Minecraft

Block DDoS floods and bot swarms directly at the kernel using XDP/eBPF — before a single packet reaches your server. EU-hosted and fully Geyser cross-play ready.

Active
System Status
99.9%
30D Uptime
< 1ms
Filter Latency
1.2+ Tbit/s
Of protected legitimate traffic
Points of Presence

Our filtering nodes.

Filtering nodes in Frankfurt and Hamburg (Germany), with more locations across Europe and North America added based on demand.

Frankfurt, DE

* New locations added based on demand.

Germany
Features

Built for Minecraft administrators

Every module is built around real Minecraft traffic and the actual attack patterns we've seen hit our own servers.

01

XDP-Powered Kernel Filtering (L3/L4)

Malicious packets are dropped at the kernel level via eXpress Data Path (XDP/eBPF). L3/L4 SYN and UDP floods and botnet traffic are gone before they cost you a single CPU cycle — sub-1ms filtering overhead.

02

Geyser & Bedrock Cross-Play Native

Full Java Edition and Bedrock cross-play support, sitting in front of your BungeeCord, Velocity, Paper or Spigot backend. Your players feel no difference.

03

Deep Packet Inspection — Minecraft-Aware Anti-Bot

BlackProtect understands the Minecraft protocol, filtering bot swarms, botnet joins and spoofed sessions in real time with true Layer 7 anti-bot mitigation.

04

VPN & Proxy Blocking with Origin-IP Protection

Block VPN and proxy connections before they reach your server, while our edge keeps your origin IP hidden from attackers. PROXY protocol v2 forwards the real player IP to your backend.

Why BlackProtect

Why networks pick us. Instead of US proxies.

Kernel-level filtering is our foundation. Four reasons serious infrastructure teams move their edge to BlackProtect.

Request Pilot Access
  1. 01

    100% EU-Hosted & GDPR Native

    Dedicated infrastructure in Frankfurt and Hamburg. Zero data flow to US entities.

  2. 02

    Kernel-Level XDP/eBPF Filtering

    Direct packet drops at the NIC layer, with sub-1ms latency overhead.

  3. 03

    Direct Engineer Access, No Ticket Queues

    Talk to the people who built the filter. No first-level scripts, no queue — mitigation happens in the same chat.

    Discord SLA · Direct Engineer Access
  4. 04

    Transparent Self-Service Console

    Live L7 attack history, custom filter rules, and real-time TPS monitoring out of the box.

Our Story

Built by Admins, For Admins

BlackProtect didn't start in a boardroom — it started because our own Minecraft server kept getting knocked offline, and every 'enterprise' DDoS solution we found either didn't understand Minecraft or cost more per month than our entire server budget. So we built our own kernel-level filter instead. Today we run it for our own network, and we're opening it up to yours: transparent, fast, and priced like something a solo admin could actually afford.

Under 5 minutes. Connect your domain, point a CNAME record to 'front-fra.blackprotect.net' (set Cloudflare to 'DNS only / grey cloud') — done. No plugin installation on your backend servers whatsoever.

Sub-1ms filtering overhead. Because malicious packets are dropped at the kernel via XDP/eBPF, legitimate players see no measurable ping increase compared to a direct connection to your backend.

Yes. Traffic routes through our edge nodes, so your origin IP is never exposed to players or attackers. PROXY protocol v2 forwards the real client IP to your backend for correct player addressing.

Yes. Full support for Geyser and Bedrock cross-play. Java and Bedrock players connect through the same protected edge with no difference in experience.

100% in the EU. Filtering nodes run in Frankfurt and Hamburg, Germany, with GDPR-native data handling — a compliance factor US-based proxies cannot match.

BlackProtect is currently in an invite-only pilot phase for selected networks. Apply through the pilot card above or reach out directly via Discord. Once approved, you'll receive an invite token to activate your account. Free during the pilot.

Ready to drop attacks at the kernel layer?

Deploy BlackProtect on your own network or route your game traffic through our edge.