When country rules make sense
Country rules decide who may join based on where their connection appears to come from. They fit when:
- Your community is regional, for example a German-speaking server that moderates only in German.
- Abuse keeps coming from the same places, such as repeated bot waves you can't moderate.
- Latency matters and you'd rather not accept players who'd play at 300 ms.
A country match is a policy decision, not proof that someone is malicious. Travelers, expats and players on unusual networks will be affected too, so decide what you want and tell players how to get help.
Blocklist or allowlist
| Mode | Who gets refused | Use it when |
|---|---|---|
BLACKLIST | Players from the listed countries | You want to keep out a few specific countries. |
WHITELIST | Players from every country not listed | Your server is for a small set of countries. |
Careful with an empty allowlist: it matches every country and refuses everyone.
Set it up with Connection Guard
Connection Guard handles VPN checks and country rules in one free plugin for Paper and Spigot, BungeeCord and Velocity. On a network, install it on the proxy.
1. Choose the countries
Country rules live under behavior.geo in the generated config.yml. Use two-letter ISO country codes. The shipped config blocks CN and RU; replace that list with your own policy:
behavior:
geo:
kick-player: true
notify-staff: true
type: 'BLACKLIST' # or 'WHITELIST'
list:
- CN
- RUThis is a partial example: keep the other generated settings. Want to watch first? Set kick-player: false and staff with connectionguard.notify.geo get an alert instead. You can also post matches to a Discord webhook under send-webhook.
2. Pick the country lookup service
The default country service is IP-API. Its free endpoint is for non-commercial use, uses HTTP and allows 45 requests per minute. For a commercial server or more traffic, switch to ProxyCheck:
provider:
geo:
service: 'ProxyCheck'Restart after changing the service. Country answers are cached for 72 hours by default, so returning players don't cost a lookup.
3. Test it
Run /cg info <IP or player> to see which country each service reports for an address. Then check one ordinary connection and one that should match before you rely on it.
How accurate is country detection?
IP geolocation is usually right about the country for home broadband, but it's an estimate built from registry data and network measurements. Expect mistakes with:
- Mobile networks, which can route traffic through another country.
- Company and school networks with a central internet exit.
- VPNs and proxies, which show the VPN server's country. Pair country rules with VPN checks so a rule can't be skipped with one click.
If a lookup fails, Connection Guard makes no country decision for that login rather than guessing.
Keep it fair for players
- Say why. Edit the geo kick message in
translation/en.ymlto name the rule and how to appeal. - Exempt people you trust. Add their UUID or IP under
behavior.geo.exemptions, or exempt by LuckPerms permission withuse-permission-exemption: true. - Review now and then. Abuse patterns change; a country you blocked last year may now be part of your community.