Does a Minecraft server need DDoS protection?
A Minecraft server needs DDoS protection from the day its address is public, because 1 attacker with access to a flood of traffic can take it offline for every player at once, and nothing inside Minecraft can stop that. A DDoS attack does not log in or break anything on the server. It fills the connection in front of it with junk traffic until real players can no longer get through, and it lasts as long as the attacker keeps it going.
A private server for a few friends is a smaller target, but its address travels with everyone who has it. Since all three hosts we compare include protection on every plan, the question is less whether you get it than what it covers: both editions, voice chat, and the attacks that come in as fake players instead of raw traffic.
Minecraft server DDoS protection at each host
Minecraft server DDoS protection is included on every plan at all 3 hosts we compare, with nothing to switch on. Each describes it in its own words:
- Astroworld Hosting filters attacks on layers 3, 4 and 7 upstream, before the traffic reaches your server, on every plan and in every location, and sells no protection add-on.
- Lodehost puts DDoS filtering in front of every address on every plan, so that traffic which is not a player trying to join never reaches your world.
- Cheapest Minecraft Hosting includes network protection in every plan and filters attack traffic before it reaches the world, on port 25565 for Java and port 19132 for Bedrock.
At any other host, ask 3 questions before you pay: is protection included or an add-on, does it cover UDP for Bedrock and voice chat, and what happens to your server during a large attack.
Can a plugin stop a DDoS attack?
No plugin can stop a DDoS flood, because 1 thing has to happen before any plugin runs: the traffic has to reach the server, and a flood clogs the connection on the way there. What plugins can stop is the other kind of attack, where hundreds of fake players connect and try to log in. That traffic looks like players to a network filter, so it gets through, and it hits the server itself.
Sonar is an anti-bot plugin for exactly that, version 2.1.52 from 27 September 2026, for Velocity, BungeeCord, Paper and Folia. It sends each new player to a light fake server once, checks that they fall with gravity, collide with blocks and send the packets a real game sends, and queues new connections so a wave of bots cannot join at the same moment. On a network it belongs on the proxy, where players arrive first.
Minecraft has one setting of its own in this area. rate-limit in server.properties kicks a player who sends more packets per second than the number you set, with Kicked for exceeding packet rate limit. It is 0, switched off, by default, and it deals with a single misbehaving client, not with a flood.
TCPShield and Cloudflare Spectrum for Minecraft
TCPShield and Cloudflare Spectrum put their own network in front of your server: players connect to 1 address of theirs, the service filters the traffic, and your server's real address stays out of sight. On 10 October 2026 their offers for Minecraft looked like this:
| Service | Price a month | What it adds |
|---|---|---|
| TCPShield Free | $0 | 1.0 TB of traffic, 1 network, 3 domains; meant for servers of 20 to 30 players |
| TCPShield Pro | $25 | 5.0 TB of traffic, and support for Simple Voice Chat and Plasmo Voice |
| TCPShield Premium | $100 | Unlimited traffic, custom mitigation settings, and Geyser support for Bedrock players |
| TCPShield Enterprise | $250 | Geo routing, uptime monitoring and up to 10 networks |
| Cloudflare Spectrum | A paid add-on to Cloudflare Pro or Business | 1 Minecraft Java app; not on the free plan, and no Bedrock |
Two things decide whether such a service helps. Your server has to refuse connections that do not come through it, or an attacker who knows the real address simply goes around it. And the server sees the service's addresses instead of the players' unless the service passes them on, for example with the proxy protocol that Cloudflare Spectrum offers and Velocity accepts with haproxy-protocol, which is off by default. On a host that already filters attacks, the main thing a service adds is the hidden address, and for a crossplay or voice chat server that hidden address costs money.
How to hide your Minecraft server IP
You can hide your Minecraft server IP in only 1 way that holds: send players to an address that belongs to something else, such as a proxy service. A domain name does not hide anything, because anyone can look up the IP behind it, and the SRV record that lets Java players leave out the port is just as public.
A domain still helps. If the address leaks and the attacks keep coming, a server behind a name can move to a new IP, while a server known by its numbers has to tell every player a new one. Our guide to Minecraft server domains sets it up, including the grey cloud a Cloudflare record needs. On a Velocity network, only the proxy's address should ever be public: the servers behind it accept nobody but the proxy.
DDoS protection for Bedrock and crossplay servers
DDoS protection for a crossplay server has 2 doors to cover: port 25565 over TCP for Java players and port 19132 over UDP for Bedrock players through Geyser. Filtering that sits in front of the whole address, as at the hosts we compare, covers both. Proxy services are where the gaps are: Cloudflare Spectrum carries Java only, and TCPShield adds Geyser support from its $100 Premium plan.
Voice chat is a third door. Simple Voice Chat talks over its own UDP port, 24454 unless you change it, and DDoS filtering that does not expect that traffic can drop it, so players join fine but stay silent. Our Simple Voice Chat server guide covers the fix, and on TCPShield voice support starts with the $25 Pro plan. The crossplay hosting page has the rest of Geyser.
What to do during a DDoS attack on a Minecraft server
During a DDoS attack on a Minecraft server, 3 steps help more than anything you can do in the game:
- Check that it is an attack. When every player times out at once while the server still reports 20 TPS, the problem is the network. Low TPS with players still connected is lag, which our guide to Minecraft server lag covers.
- Tell your host, with the times it started and stopped and what players saw. Filtering is theirs to adjust, and restarting the server does nothing against traffic that never reaches it.
- Tell your players on Discord or your website, so they know it is not their connection and do not give up on the server.
Afterwards, look at how the attacker found the address. If it came from a server list, that is the price of being public. If it came from a player, a moved address behind a domain name or a proxy service is the lasting fix.

