Setup & configuration

Minecraft servers and Cloudflare: setting up DNS correctly

Quele, Founder of BlackProtectUpdated 6 October 20265 min read
In short

For Minecraft, the record on Cloudflare must be set to DNS only (grey cloud). The orange cloud only proxies websites; Minecraft players get a timeout.

For BlackProtect a single CNAME record is enough. You don't need SRV records, and old SRV records pointing at your real server should be deleted.

Contents
  1. Orange or grey cloud?
  2. Creating the record for BlackProtect
  3. Or automatically in one click
  4. The root domain without a subdomain
  5. SRV records: you don't need them
  6. Common mistakes
  7. Frequently asked questions

Orange or grey cloud?

Cloudflare shows a cloud next to every record. It decides how the record works:

  • Orange (Proxied): Cloudflare puts itself in between. That only works for websites. Minecraft connections don't get through, and the record no longer reveals where it really points.
  • Grey (DNS only): Cloudflare only answers “where does this name point?”. That's exactly what Minecraft needs.

Your website (e.g. www.yourserver.com) can stay orange. Only the name players join with has to be grey.

Creating the record for BlackProtect

  1. Copy the target from the dashboard

    When you set up your domain, BlackProtect shows a personal target ending in .front-fra.blackprotect.net.

  2. Create the record

    On Cloudflare: your domain → DNS → Records → Add record. Type CNAME, name e.g. play, target is your personal target.

  3. Proxy status: DNS only

    The cloud must be grey. TTL can stay on Auto. Save, done.

This one record routes your players through the protection and proves to us that the domain is yours. It is usually visible everywhere within a few minutes.

Or automatically in one click

If the setup wizard detects that your domain is on Cloudflare, it can set the record for you. You create an API token on Cloudflare that only covers your domain's DNS records (the link in the wizard pre-fills everything).

  • First we only set a verification record. Your players notice nothing.
  • Only once your protection is fully set up do we switch the record for your players – set to DNS only, of course. That means zero downtime.
  • We don't store the token. It's only used for the setup.

The root domain without a subdomain

Want players to join directly via yourserver.com (without play.)? Cloudflare does allow a CNAME there, but outwardly it only shows the addresses behind it. For the root domain, create the A records and the TXT verification record the wizard shows under No CNAME possible?, or use the automatic setup. A subdomain like play. is usually simpler.

SRV records: you don't need them

An SRV record (_minecraft._tcp) tells Java players which port your server runs on when it isn't the default. With BlackProtect, players always connect to our filter on the default port, so you don't need an SRV record.

Delete old SRV records

If an old SRV record still points directly at your server, players bypass the protection through it and your real IP is public. Delete it. Bedrock players ignore SRV records anyway.

Common mistakes

  • “Can't resolve hostname” / “Unknown host”: a typo in the name, or the record hasn't spread everywhere yet. Wait a few minutes.
  • “Timed out”: almost always the cloud is orange.
  • The wizard says “not verified”: check that the cloud is grey and the target matches exactly (no trailing space).

Frequently asked questions

Does my domain have to be on Cloudflare?

No. The CNAME works with any domain provider. Cloudflare only has the advantage that we can set the record automatically if you want.

What about Cloudflare Spectrum?

Spectrum is a paid Cloudflare add-on that can also proxy game connections. You don't need it for protection with BlackProtect.

How long until the record works?

On Cloudflare usually just a few minutes. With other providers it can take up to an hour.