Server protection

What your Minecraft server needs protecting from

Not every threat is a DDoS. This guide walks through the attacks Minecraft servers actually face at the network level, and how Infinity-Filter covers each one.

Threat by threat

Six things worth protecting against

Each section covers one threat: what it is, and the feature that handles it. Follow the links for the full detail.

DDoS attacks

Floods of junk traffic aimed at saturating your server's connection so real players can't get through. The most brutal and most common attack on Minecraft servers, and the one nothing on your own machine can stop.

Every Infinity-Filter plan, including the free one, routes your traffic through our filtering network first. Floods are absorbed at our edge; your players never see them.

Bot and join floods

Waves of fake players spamming your login screen: they fill slots, trigger plugins, and lag your server without ever being real connections you'd want.

The anti-bot layer analyses connection rates and protocol fingerprints at the filter, before the fake join reaches your server. Three modes, from off to hardcore, switchable in the dashboard.

A leaked real IP

If attackers learn your backend's real address, they can aim attacks straight at it and bypass any filter in front. Old DNS records, status sites and careless screenshots are the usual leaks.

Behind Infinity-Filter your real IP stays out of DNS entirely, and you firewall your machine so only our filtering ranges can reach it. Leaked or guessed, a direct hit finds a closed door.

VPNs and throwaway accounts

Banned players coming straight back through a VPN, or grief crews joining from disposable connections. Bans on IPs stop meaning anything.

The anti-VPN filter checks connections against a database of known VPN and proxy networks and turns them away at login, before they ever appear in your player list.

Unwanted countries and networks

If your community is French, connections from a datacenter on another continent are rarely players. A wide-open server is a wider attack surface than it needs to be.

Country filtering allows or denies connections by country at login, and ASN filtering blocks whole networks (datacenters, known abuse sources) by their network number.

Trusted IPs and private access

Staff members, monitoring bots and partner services sometimes trip the same filters aimed at attackers: a VPN-using admin shouldn't be locked out with the griefers.

The whitelist lets trusted IPs and networks bypass the anti-bot, anti-VPN and country filters while still enjoying full DDoS mitigation. Your rules stay strict for everyone else.

Running crossplay with Geyser?

Bedrock traffic works differently from Java (UDP instead of TCP) and most protection setups don't cover it. We do, with a dedicated filtered entry point for your Bedrock players.

FAQ

Minecraft server security, asked and answered

The questions server owners actually search for. Short, honest answers.

How do I protect my Minecraft server from DDoS attacks?

Put a filtering layer between players and your machine. Players connect to a protected address, attack traffic gets absorbed there, and only clean connections are forwarded to your server. On Infinity-Filter that takes one DNS change, and the Free plan covers small servers. Firewalling your backend so only our network can reach it closes the last gap.

How do I know if my server is under attack or just lagging?

Typical attack signs: every player times out at once, the server process itself looks healthy, and your logs show a flood of connection attempts from many different IPs. Plugin lag and host issues can look similar, so check your traffic graphs before concluding. Behind a filter you don't have to diagnose it live: mitigation kicks in automatically.

Does a custom domain or SRV record hide my server IP?

No, and this is a very common misconception. A domain is just a public pointer: anyone can look up the address it resolves to, SRV record included. Domains add convenience, not protection. The only way to keep your real IP out of DNS is to point the domain at a filtering proxy and keep the backend address private.

Is a whitelist enough to secure my server?

A player whitelist controls who can log in, and every private server should use one. But the port stays open behind it: a whitelist stops nobody from flooding your connection, scanning it, or probing it, and it doesn't hide your IP. Pair it with network-level protection; our whitelist complements it at the IP level, letting trusted addresses skip the strict filters.

Is it safe to host a Minecraft server from home?

Opening a port at home exposes your personal IP to every player and to the scanners that sweep the internet for open Minecraft ports. A single attack can knock your whole household offline. If you self-host, put a filtering proxy in front so players only ever see the protected address, and configure your firewall so only that proxy can reach your machine.

Should I block VPN connections on my server?

If you deal with ban evasion or bot waves, yes: an IP ban means little when reconnecting through a VPN takes seconds. Some legitimate players use VPNs too, so the pragmatic approach is to enable the anti-VPN filter when abuse is real rather than by default, and whitelist the trusted players who need one.

Are cracked (offline-mode) servers more exposed?

Yes, significantly. Without Mojang authentication, bots can join with any username at zero cost, so offline-mode servers attract far more join floods and name-spoofing attempts. If you run one, connection-level bot filtering plus a strong auth plugin are essential, not optional.

My server is being attacked right now. What can I do?

Once a flood is hitting an unprotected address, there is little you can filter yourself: the pipe saturates before your machine sees the traffic. The playbook is to enable protection, point your domain at it, get a fresh IP from your host so the leaked one goes dark, and firewall the new IP to accept only the filtering network. Most attacks stop within hours; those steps stop the next one.

Is Infinity-Filter compatible with anti-cheat clients like Badlion?

Yes, fully compatible, no special configuration needed. If anything comes up, our support team can help on Discord.

Cover all of it in one place

DDoS filtering, anti-bot, VPN and country filters, whitelist: one dashboard, one DNS change to get started. The free plan is a real free plan.