Skip to content
Minecraft

Secure your Minecraft network: set up forwarding properly

Published on 3 October 2026

The servers behind your proxy run with online-mode off, because the proxy checks who’s logging in. That’s exactly where the risk sits: if someone can connect to one of those servers directly, they can pretend to be any player, including you. Modern forwarding with a secret key closes that gap. This guide assumes a network like the one in Set up a Minecraft network with Velocity.

Why is an open server behind a proxy dangerous?

Every server in your network has its own address. When a player connects, the proxy passes along who they are. If the server doesn’t check that this information really comes from your proxy, anyone who knows the address can skip the proxy and claim any name they like. On shared hosting you can’t set firewall rules per server yourself, so the protection has to live in the software.

How to set up modern forwarding

  1. Proxy: in velocity.toml, set player-info-forwarding-mode = "modern" and leave online-mode = true. The proxy then checks every player with Mojang.
  2. Secret: open forwarding.secret in your proxy’s main folder through File managers. That text is the key to your network. Don’t share it, and never show it in a screenshot.
  3. Every Paper server: in config/paper-global.yml, set enabled: true and online-mode: true under proxies and velocity, and paste the same key as the secret. You can also find this file under Configs.
  4. server.properties: set online-mode=false on every Paper server.
  5. spigot.yml: keep bungeecord set to false. That option belongs to the old style of forwarding.
  6. Restart the Paper servers first, then the proxy.

How do you test it?

In Minecraft, connect straight to the address of one of your Paper servers instead of the proxy. You should be refused. If you get in anyway, check that enabled is true and that the key matches exactly, without extra spaces or quotes.

What about BungeeCord?

BungeeCord’s forwarding passes player data along without a key. PaperMC calls that approach insecure unless a firewall blocks direct connections, and on shared hosting the firewall isn’t yours to set. If you stick with BungeeCord, install the BungeeGuard plugin on the proxy and on every server. Moving to Velocity is the better fix.

Does this protect against DDoS attacks?

No, forwarding is about who gets in. Attacks on your connection are handled by the network: Premium comes with DDoS protection through Cloudflare Magic Transit, and on Standard your server has standard DDoS protection from the data centre. On top of that, only share your proxy’s address and keep your servers’ addresses to yourself. Stuck? Open a ticket with the error from the console, but never include your key. The lines are compared on specifications, and you order on Minecraft server hosting.

This guide replaces a Dutch CakeHosting knowledge base article about BungeeCord from 2019.

Frequently asked questions

What do I see when I connect directly to a secured server?

You’re refused with a message saying you need to connect through the proxy. That’s the whole point.

Should online-mode be on or off on the proxy?

On. The proxy checks players with Mojang and forwards the result along with the key. On the Paper servers you switch online-mode off in server.properties.

What if my secret leaks?

Put a new key in forwarding.secret, paste it into config/paper-global.yml on every Paper server and restart everything. The old key stops working.

Does modern forwarding work with old Minecraft versions?

Modern forwarding works from Minecraft 1.13 onwards. For older servers, Velocity offers the bungeeguard mode together with the BungeeGuard plugin.

More questions? See all frequently asked questions

Related articles