Protection & security

List your server on server lists without leaking your IP

Quele, Founder of BlackProtectUpdated 6 October 20265 min read
In short

Always list your server with your domain, never the IP. Behind BlackProtect, lists still show player count, version and MOTD.

Watch out for Votifier: for votes to arrive, lists connect straight to your server. That reveals your IP unless you secure it.

Contents
  1. Why server lists?
  2. How to list your server correctly
  3. The Votifier trap
  4. If attacks start after listing
  5. Frequently asked questions

Why server lists?

Server lists are one of the best ways for a new server to find players. At the same time, people who like attacking servers browse them too. A listing with an IP is an invitation.

How to list your server correctly

  1. Domain, not IP

    Always enter play.yourserver.com as the address. No domain yet? Connect your server to a domain.

  2. Port only if needed

    Behind BlackProtect the port is always 25565. Leave the field empty or enter 25565.

  3. Bedrock separately

    For Bedrock, enter the Bedrock address and port BlackProtect shows under Bedrock ingress.

  4. A description with substance

    Game mode, version, Java/Bedrock, what makes you special, a Discord link. Stay honest: whoever writes “1000 players” and has 3 loses trust.

Server lists regularly query your server via the server list ping (player count, version, MOTD). Because they use your domain for that, it works normally behind our filter.

Show trust

With Show the protection in the server list in your route settings, server lists and scanners see “Protected by BlackProtect.net” instead of your server software. A small signal that attacks on you go nowhere.

The Votifier trap

For vote rewards, many servers use Votifier (or NuVotifier). You enter an address, a port (usually 8192) and a key on the server list. The list then connects directly to that port on every vote.

  • The problem: Votifier doesn't go through the Minecraft protection. The Votifier address points at your real server – so every list, and anyone who looks, knows your real IP.
  • Fix 1: run Votifier on a different machine, e.g. a small cheap server. NuVotifier can forward votes to your actual server.
  • Fix 2: use a firewall to open the Votifier port only to the list's servers, if the list publishes its addresses.
  • Fix 3: skip Votifier and reward votes another way, e.g. with a command players run themselves after voting.
Same for web maps and query

Dynmap, BlueMap or an open query port on the same IP reveal it just the same. More: Hide your server IP.

If attacks start after listing

New, visible servers get attacked more often – out of envy, boredom or because someone wants money. So plan protection before you list yourself everywhere, not after.

Frequently asked questions

Will the list show my server as online behind BlackProtect?

Yes. The list queries via your domain, our filter passes that on to your server, and the list sees player count, version and MOTD as usual.

What does the list show when my server is offline?

Instead of “unreachable”, our filter answers with your offline message, which you set in your route settings. Players see the server is just briefly down.

Do I have to give up Votifier?

No. What matters is that the Votifier port doesn't point at your actual Minecraft server or is secured. Otherwise protecting the Minecraft port is pointless, because the IP is public anyway.