Protection & security

Hide your Minecraft server IP: find and fix leaks

Quele, Founder of BlackProtectUpdated 6 October 20267 min read
In short

If an attacker knows your server's real IP, they attack it directly and bypass any protection. The most common leaks are old DNS records, other subdomains on the same server, and server lists.

The fix: close the leaks, get a new IP if needed, and use a firewall to only allow the protection's filter servers on port 25565.

Contents
  1. Why the real IP matters so much
  2. Where your IP typically leaks
  3. How to check whether your IP is visible
  4. How to lock it down
  5. Firewall setup (Linux with ufw)
  6. Frequently asked questions

Why the real IP matters so much

DDoS protection works like a bouncer: every player walks past it and only real ones get in. But if someone knows the back door – your real server IP – they simply walk around the bouncer. So every protection setup needs two things: the real IP must not be public, and the back door must be locked.

Where your IP typically leaks

  • Old DNS records: if play.yourserver.com used to point straight at your server, DNS history services often still show it years later. Only a new IP helps here.
  • Other subdomains on the same server: panel., map., mc2. or mail. often point straight at the real IP. Attackers try such names on purpose.
  • SRV records: an _minecraft._tcp SRV record pointing directly at your server reveals the IP just like an A record.
  • Server lists and websites: if you listed your server somewhere with its IP instead of the domain, the IP is public there.
  • Web maps and extra services: Dynmap, BlueMap, Votifier or the query port run on the same IP and are reachable from outside.
  • Screenshots, logs, Discord: a console on stream, a shared log or a “just join via the IP” in chat is enough.
  • Emails from your own server: if your server sends emails itself (e.g. for a forum), its IP is often in every email's headers.

How to check whether your IP is visible

Look at where your domains point. On Windows, Mac and Linux you can do that in a terminal with nslookup:

Terminal
nslookup play.yourserver.com
nslookup panel.yourserver.com
nslookup map.yourserver.com

If your server's real IP shows up anywhere, that is a leak. Also check: is your server listed on server lists with its IP? Does a web map run on the same IP? Have you ever posted the IP publicly?

Rule of thumb

If the IP was ever public, assume attackers have it. A new IP is worth more than any search.

How to lock it down

  1. Set up protection first

    The next steps only make sense once every player comes through the protection. Otherwise the new IP is public again right away.

  2. Get a new IP if needed

    Most hosts give you a new IP on request, sometimes for a small fee. Enter the new IP only as the target in the protection, nowhere else.

  3. Separate other services

    Web map, panel or website don't belong on the same IP as the Minecraft server – or they also run behind protection (e.g. websites behind Cloudflare).

  4. Firewall: only allow the protection

    Allow port 25565 only for the protection's filter servers. A direct attack on the IP then bounces off the firewall, and nobody can reach your server around the protection.

Firewall setup (Linux with ufw)

If your server runs on your own Linux machine (VPS or dedicated server), ufw does the job. Below are the current addresses of our filter servers and the matching commands. Both load live, so they are always up to date.

  • Frankfurt194.62.248.59
  • Nuremberg185.217.124.16
Terminal
# Allow SSH first, or you will lock yourself out!
# (If SSH runs on a different port, use that instead of 22.)
sudo ufw allow 22/tcp

# Minecraft only for the BlackProtect filter servers
sudo ufw allow from 194.62.248.59 to any port 25565 proto tcp
sudo ufw allow from 185.217.124.16 to any port 25565 proto tcp

# Remove an old rule that allowed everyone (if there is one)
sudo ufw delete allow 25565/tcp

sudo ufw enable
sudo ufw status
Server in Docker or Pterodactyl?

Docker bypasses ufw: ports a container publishes stay reachable despite these rules. If you use Docker or a panel like Pterodactyl, set the rule in your host's firewall or ask us on Discord – we'll help.

If you use Bedrock through our protection, the same applies to your Geyser UDP port (usually 19132/udp). With a host that only gives you a panel instead of your own Linux server, the firewall is usually in the customer area, or support sets it up for you.

Addresses rarely change, but they do

When a new location is added, it appears automatically in the list and the commands above, and we announce it on Discord beforehand. Check back here now and then.

Frequently asked questions

Is it enough to point the domain at the protection?

Only if the real IP was never public. Otherwise an attacker can keep attacking the server directly. A new IP plus a firewall that only lets the protection through solves that.

I only have a host panel and no root access. What can I do?

Check your customer area for a firewall. If there isn't one, ask your host's support whether they can restrict connections to your port to certain addresses. Closing the leaks and keeping the IP private already helps a lot, even without a firewall.

Will I still see my players' real IPs behind the protection?

Yes, if you enable PROXY protocol: in your route settings at BlackProtect and in your Velocity, BungeeCord or Paper. Then bans and logs work with real player IPs again.