Game protection
Attacks on game servers do not knock on the front door. They arrive as thousands of connections that look exactly like players logging in — and a server spends real resources on every one of them. We screen each connection before it reaches you, and let the real players straight through.
How it works
Your server stays exactly as it is. You change where your address points, and connections start arriving at our network instead of your machine. Nothing to install, no plugin, no mod, no change to your server configuration.
Before a connection can cost your server anything — a slot, a world load, a single tick — it passes through us. Attacks are stopped here. They never reach your hardware, so they never turn into lag for the people who are actually playing.
A genuine player connects the way they always have, on an unmodified client, to the same address. No extra step, no account linking, no waiting on anything. The protection is invisible to the people you built the server for.
What it does
A game server is not a website. It holds long-lived connections, it spends real work on every join attempt, and the difference between a raid and a good evening can be the same number of connections. Protection has to understand that.
Two hundred joins in a second is a catastrophe for a small survival server and a quiet evening for a large network. A fixed threshold has to pick one of those and be wrong about the other. Ours learns what normal looks like for your server specifically and reacts when your traffic stops resembling itself — so a large server is never punished for being large, and a small one is never left undefended.
Blocking outright is the blunt instrument, and it costs you real members. A connection we are unsure about is instead asked to demonstrate that it belongs to a person with a real account: seconds for a human, ruinous for an automated tool running thousands of connections at once. Genuine players are never asked anything.
When a connection needs to prove more than account ownership, the player sees the challenge in Minecraft itself, drawn in the world in front of them. No browser tab, no third-party verification service, nothing outside the game. That last part matters more than it sounds: a challenge that depends on an outside provider inherits every outage that provider has, and it sits directly on the path players log in through.
We never log a player in on your behalf and hand you a finished session. Your server stays in online mode and authenticates every player itself, exactly as it does today. That also closes the hole that follows forwarding proxies around, where a leaked server address lets anybody connect under any username they like.
When your server is at its player limit, the next arrivals wait in an ordered line and are shown where they stand and roughly how long it will take — instead of receiving an error and going somewhere else. Slots free up, the line advances, players get in.
Ban somebody once and they stop reaching your server at all. They occupy no slot, open no connection to your machine, and get no further opportunity to do whatever got them banned in the first place. Bans that name an account are honoured only where that account has genuinely been verified, so nobody is ever banned because somebody else typed their name.
Server-list pings are trivially cheap to send and have always been a free way to hammer a server that is doing nothing wrong. We answer them ourselves from a recent snapshot, so a flood of them costs your server nothing — and your listing keeps showing the right player count and message instead of going dark exactly when people are trying to find you.
Attacks on game servers are overwhelmingly rented botnets, and the same addresses move from one server to the next. An address that has already proven hostile against another server on our network arrives at yours carrying that history. It never blocks anyone on its own — the worst a reputation can do is ask somebody to prove they are a real player.
A large share of genuine players connect through a VPN or a hosting provider’s network, and blocking that category outright quietly throws away members of your community. We raise the bar for them instead: prove you are a player, then go and play.
A player who is turned away sees a branded screen with a real reason on it — not a silent timeout that makes your server look broken and sends them to ask you why. The words on their screen and the reason in your log are the same words, so support conversations start from the same fact.
Every join attempt is recorded: what arrived, what was allowed through, what was stopped and why it was stopped. When a community member asks whether the server was attacked last night, the answer is something you can point at rather than something you have to remember.
Game protection runs on the same edge network and the same dashboard as your websites and APIs. There is no second vendor to wire in, no second invoice, and no separate console to learn.
Two experiences
Java Edition servers, vanilla and modded. Bedrock Edition is not supported today. The first time a player is asked to verify, clients older than 1.20.5 reconnect once; newer clients are sent back automatically and never notice it happened.
Pricing
Game protection is not a separate product or a paid add-on. Every plan — including the free one — comes with protected Minecraft servers and a concurrent-player allowance, and the numbers scale with the plan.
FAQ
Connections are relayed through the point of presence closest to your players, and once somebody is in the game their connection is a straight pipe. The screening work happens while a player is connecting, not while they are playing.
No. No mod, no plugin, no launcher change and no account linking. They connect to the same address on an unmodified client.
No. Your server keeps its own settings and keeps authenticating players itself. The only thing that changes is where your address points.
Yes — Java Edition servers are supported whether they are vanilla or modded. Bedrock Edition is not supported today.
Arriving players are held in an ordered queue and shown their position, rather than being rejected outright. As slots free up the queue advances and they are let in.
The design goal is that they are not. Anything we are unsure about is asked to prove it is a player rather than being refused, which costs a genuine person a few seconds at most. Connections from VPNs and hosting networks are challenged rather than blocked precisely because so many real players use them.
Players connect to us rather than to your machine, so your server’s own address is not what your community passes around. Anything already published stays published, so it is still worth changing if it has been leaked.
No. It is included in every plan, free tier included. Plans differ in how many servers you can protect and how many players can be connected at once.
Point your server address at us and let the attacks arrive somewhere that is built to absorb them.