XDP-Powered Kernel Filtering (L3/L4)
Malicious packets are dropped at the kernel level via eXpress Data Path (XDP/eBPF). L3/L4 SYN and UDP floods and botnet traffic are gone before they cost you a single CPU cycle — sub-1ms filtering overhead.
Block DDoS floods and bot swarms directly at the kernel using XDP/eBPF — before a single packet reaches your server. EU-hosted and fully Geyser cross-play ready.
Filtering nodes in Frankfurt and Hamburg (Germany), with more locations across Europe and North America added based on demand.
* New locations added based on demand.
Every module is built around real Minecraft traffic and the actual attack patterns we've seen hit our own servers.
Malicious packets are dropped at the kernel level via eXpress Data Path (XDP/eBPF). L3/L4 SYN and UDP floods and botnet traffic are gone before they cost you a single CPU cycle — sub-1ms filtering overhead.
Full Java Edition and Bedrock cross-play support, sitting in front of your BungeeCord, Velocity, Paper or Spigot backend. Your players feel no difference.
BlackProtect understands the Minecraft protocol, filtering bot swarms, botnet joins and spoofed sessions in real time with true Layer 7 anti-bot mitigation.
Block VPN and proxy connections before they reach your server, while our edge keeps your origin IP hidden from attackers. PROXY protocol v2 forwards the real player IP to your backend.
Kernel-level filtering is our foundation. Four reasons serious infrastructure teams move their edge to BlackProtect.
Request Pilot AccessDedicated infrastructure in Frankfurt and Hamburg. Zero data flow to US entities.
Direct packet drops at the NIC layer, with sub-1ms latency overhead.
Talk to the people who built the filter. No first-level scripts, no queue — mitigation happens in the same chat.
Discord SLA · Direct Engineer AccessLive L7 attack history, custom filter rules, and real-time TPS monitoring out of the box.
BlackProtect didn't start in a boardroom — it started because our own Minecraft server kept getting knocked offline, and every 'enterprise' DDoS solution we found either didn't understand Minecraft or cost more per month than our entire server budget. So we built our own kernel-level filter instead. Today we run it for our own network, and we're opening it up to yours: transparent, fast, and priced like something a solo admin could actually afford.
Under 5 minutes. Connect your domain, point a CNAME record to 'front-fra.blackprotect.net' (set Cloudflare to 'DNS only / grey cloud') — done. No plugin installation on your backend servers whatsoever.
Sub-1ms filtering overhead. Because malicious packets are dropped at the kernel via XDP/eBPF, legitimate players see no measurable ping increase compared to a direct connection to your backend.
Yes. Traffic routes through our edge nodes, so your origin IP is never exposed to players or attackers. PROXY protocol v2 forwards the real client IP to your backend for correct player addressing.
Yes. Full support for Geyser and Bedrock cross-play. Java and Bedrock players connect through the same protected edge with no difference in experience.
100% in the EU. Filtering nodes run in Frankfurt and Hamburg, Germany, with GDPR-native data handling — a compliance factor US-based proxies cannot match.
BlackProtect is currently in an invite-only pilot phase for selected networks. Apply through the pilot card above or reach out directly via Discord. Once approved, you'll receive an invite token to activate your account. Free during the pilot.
Deploy BlackProtect on your own network or route your game traffic through our edge.