Minecraft

Protecting Your Minecraft Server From DDoS and Bot Attacks

How Minecraft servers get attacked — network floods, handshake and ping floods, bot joins and crash exploits — and the layered defences that keep them online.

On this page
  1. The attacks you’ll actually see
  2. Layer 1: Network-level DDoS protection
  3. Layer 2: Protect your IP address
  4. Layer 3: Harden the server itself
  5. Layer 4: Moderation tools
  6. During an attack
  7. Summary

Minecraft servers are among the most frequently attacked services on the internet. Attacks are cheap to launch, rivalries between servers are common, and a single disgruntled player can cause hours of downtime. The good news: with the right layers of protection, most attacks become non-events. This article explains the kinds of attacks you’ll face and how to defend against each.

The attacks you’ll actually see

Volumetric network floods (Layer 3/4)

Massive amounts of junk traffic — UDP floods, SYN floods, amplification attacks — aimed at your server’s IP address to saturate its network connection. Nothing running on the server can stop these; by the time traffic reaches your machine, the pipe is already full. They must be absorbed upstream, by the network.

Connection and handshake floods

Thousands of TCP connections that start the Minecraft handshake and then stall, or complete it repeatedly, to exhaust the server’s connection handling. These look more like real Minecraft traffic, so generic network filtering alone doesn’t always catch them.

Server list ping floods

Floods of status requests — the packets your server answers when a client refreshes the server list. Each is small, but huge volumes waste CPU and bandwidth.

Bot join attacks

Scripts that connect many fake players at once — often on offline-mode servers or through proxies — to spam chat, fill player slots, trigger expensive login logic or simply cause chaos.

Crash and lag exploits

Specially crafted packets or in-game actions (malformed books, certain item data, entity abuse) that crash or freeze a server. These target bugs rather than capacity.

Layer 1: Network-level DDoS protection

Volumetric attacks can only be stopped by a network with enough capacity to absorb them and scrubbing infrastructure to filter them. This is why hosting matters more than any plugin.

Kerit Cloud’s Minecraft hosting sits behind:

  • OVH TCP Shield with more than 17 Tbps of scrubbing capacity for UDP, SYN and ICMP floods.
  • Application-layer filtering, with custom payload rules for Minecraft: handshake validation and filtering of bot-join and query floods.
  • AS203446 anycast routing, sending traffic to the nearest scrubbing point.
  • Automatic mitigation that triggers within about 10 milliseconds, with no ticket or manual action needed.

It’s always on for every server. More detail in how Kerit Cloud DDoS protection works.

Layer 2: Protect your IP address

Network protection only helps if attackers go through it. If your server’s real IP leaks — and it’s unprotected — attackers can bypass everything.

  • Don’t run a Minecraft server from your home IP. Attacks on a home connection take your whole household offline, and home routers can’t absorb floods. See self-hosting at home vs paid hosting.
  • Keep backends private on a network. With a proxy, only the proxy should be reachable; backends should listen on localhost or be firewalled. See setting up a Velocity or BungeeCord proxy network.
  • Watch for leaks through other services on the same IP: websites, voice servers, plugin web panels. Hiding your origin IP lists common ones.

Layer 3: Harden the server itself

Keep online mode on

online-mode=true makes every player authenticate with Mojang, which blocks most simple bot scripts. Only disable it on backends behind a correctly configured proxy with modern forwarding.

Whitelist private servers

For friends-only or application-based servers, a whitelist stops nearly all bot joins outright.

Rate-limit logins

Velocity has a built-in login rate limit (login-ratelimit in velocity.toml), and Paper and Spigot have connection throttling (connection-throttle in bukkit.yml). These slow down rapid reconnects from the same address.

Use an anti-bot plugin on the proxy

On public networks, an anti-bot plugin on the proxy — for example Sonar for Velocity — can verify new connections (with checks that real clients pass and simple bots fail) before they reach your backends. Tune it so legitimate players aren’t caught during busy times.

Use Paper’s packet limiter

Paper includes a configurable packet limiter (in paper-global.yml) that kicks clients sending abusive numbers of packets — a defence against several lag and crash techniques.

Keep software updated

Many crash exploits target bugs that have since been fixed. Running current Paper builds and plugin versions is one of the most effective protections you have. Download plugins only from trusted sources.

Close what you don’t use

  • Disable query (enable-query=false) unless you need it.
  • Keep RCON disabled, or bind it locally with a strong password.
  • Don’t expose plugin web panels publicly without authentication.

Layer 4: Moderation tools

Some “attacks” are really abuse through normal gameplay — alts, griefers, chat spam. Keep CoreProtect for rollbacks, a chat filter or anti-spam plugin, and clear moderator permissions through LuckPerms. See essential plugins for a new survival server.

During an attack

  1. Check whether it’s network or server. If players can’t connect at all and your server’s CPU is idle, the attack is probably being handled upstream or is network-level. If CPU spikes and the console fills with connections, it’s reaching the server — check bot and connection floods.
  2. Enable the whitelist temporarily on a public server if bots are flooding in.
  3. Tighten anti-bot and rate-limit settings on the proxy.
  4. Contact your host with timestamps and what you see. On Kerit Cloud, 24/7 Discord support can check mitigation on the network side.
  5. Communicate with your community through Discord so players know you’re on it.

More in what to do during a DDoS attack.

Summary

Minecraft servers face volumetric floods, connection and ping floods, bot joins and crash exploits. Stop floods with network-level protection — on Kerit Cloud, 17+ Tbps OVH TCP Shield, Cloudflare Magic Transit, Minecraft-specific payload rules and anycast routing, always on. Keep your real IP private, leave online mode on, whitelist where you can, rate-limit logins, run an anti-bot plugin on public proxies, use Paper’s packet limiter, keep software updated, and close unused ports.