When you host at home, every player connects to your home internet connection. Anyone who knows the IP can take your whole household offline, even when the server isn't running.
Never share your home IP. Protection in front hides it, and if it leaks anyway, many connections give you a new one when you restart the router.
Contents
Why it's riskier than a rented server
- It hits everyone at home: a DDoS on your home IP clogs your entire connection. Streaming, work from home and phones on Wi-Fi go down with it.
- No protection at your ISP: datacenters filter at least roughly. Your home internet provider usually doesn't.
- The IP reveals more: a home IP can be roughly matched to your region. No reason to panic, but one more reason not to share it.
The most important rules
- Never share the IP
Not even with friends “just to join quickly”. Share a domain instead, e.g.
play.yourserver.com, that points to protection and not directly to you. - Forward only the one port
In your router, forward only the Minecraft port (usually
25565), and only to the computer running the server. Never the whole computer (“DMZ” or “exposed host”). How: Minecraft port forwarding. - Put protection in front
With BlackProtect, players connect to our filter servers and only we connect to you. You can use a dynamic DNS name as the target, so it keeps working when your home IP changes.
- If the IP leaks anyway: reconnect
On many connections, restarting the router gives you a new IP. The attacker loses their target. On cable and fibre the IP often stays the same for longer.
Many cable, fibre and mobile connections share one public IPv4 address between many customers (“CGNAT” or “DS-Lite”). Then IPv4 port forwarding doesn't work at all, whatever you set in the router. In that case you need a tunnel service or a small rented server.
The honest alternative: a small rented server
For a server with friends, a cheap rented server (VPS) with 4–8 GB RAM is often enough. Advantages: your home connection is out of the picture, the server runs around the clock without your PC being on, and a firewall that only lets the protection through is easy to set up. How: Hide your server IP.
Frequently asked questions
Am I even allowed to run a server at home?
On most private internet plans, hosting for private use is fine. If in doubt, check your provider's terms; some exclude permanently running servers.
Isn't changing the port enough?
No. The port doesn't hide your IP, and scanners try other ports too. What matters is that nobody knows your home IP.
What is dynamic DNS?
A name like myserver.ddns.net that always points to your current home IP. Many routers can keep it updated themselves. You enter the name as the target at BlackProtect, never on server lists.
