Secure your Minecraft network: set up forwarding properly
Published on 3 October 2026
The servers behind your proxy run with online-mode off, because the proxy checks who’s logging in. That’s exactly where the risk sits: if someone can connect to one of those servers directly, they can pretend to be any player, including you. Modern forwarding with a secret key closes that gap. This guide assumes a network like the one in Set up a Minecraft network with Velocity.
Why is an open server behind a proxy dangerous?
Every server in your network has its own address. When a player connects, the proxy passes along who they are. If the server doesn’t check that this information really comes from your proxy, anyone who knows the address can skip the proxy and claim any name they like. On shared hosting you can’t set firewall rules per server yourself, so the protection has to live in the software.
How to set up modern forwarding
- Proxy: in velocity.toml, set
player-info-forwarding-mode = "modern"and leaveonline-mode = true. The proxy then checks every player with Mojang. - Secret: open forwarding.secret in your proxy’s main folder through File managers. That text is the key to your network. Don’t share it, and never show it in a screenshot.
- Every Paper server: in config/paper-global.yml, set
enabled: trueandonline-mode: trueunderproxiesandvelocity, and paste the same key as thesecret. You can also find this file under Configs. - server.properties: set
online-mode=falseon every Paper server. - spigot.yml: keep
bungeecordset to false. That option belongs to the old style of forwarding. - Restart the Paper servers first, then the proxy.
How do you test it?
In Minecraft, connect straight to the address of one of your Paper servers instead of the proxy. You should be refused. If you get in anyway, check that enabled is true and that the key matches exactly, without extra spaces or quotes.
What about BungeeCord?
BungeeCord’s forwarding passes player data along without a key. PaperMC calls that approach insecure unless a firewall blocks direct connections, and on shared hosting the firewall isn’t yours to set. If you stick with BungeeCord, install the BungeeGuard plugin on the proxy and on every server. Moving to Velocity is the better fix.
Does this protect against DDoS attacks?
No, forwarding is about who gets in. Attacks on your connection are handled by the network: Premium comes with DDoS protection through Cloudflare Magic Transit, and on Standard your server has standard DDoS protection from the data centre. On top of that, only share your proxy’s address and keep your servers’ addresses to yourself. Stuck? Open a ticket with the error from the console, but never include your key. The lines are compared on specifications, and you order on Minecraft server hosting.
This guide replaces a Dutch CakeHosting knowledge base article about BungeeCord from 2019.