Skip to content
Connection Guard
Download

VPN and Tor lists, checked on your server.

Connection Guard Intel is a signed set of VPN, Tor, relay and proxy lists. Your server downloads them once a day and checks every login against them itself: no API key, no daily quota, and checking a list sends no player's IP anywhere. Connection Guard 0.6 reads the VPN, Tor and relay lists; the proxy list follows in 0.6.1.

4.5 MB JAR for every platform, from ModrinthOther download options

  • In Connection Guard 0.6, on for new installs
  • Signed, rebuilt daily
  • Every source named, with its terms
Detection services, measured on their own
692 addresses ยท 7 October 2026
Top 6 of 16 detection services by score, with the 95 % range of each score
RankServiceScore ยท range
1Connection Guard Intel349/382 caught ยท 0/310 refused91.485โ€“94
2Blackbox379/382 caught ยท 12/310 refused87.077โ€“93
3zowi339/382 caught ยท 2/310 refused ยท earlier run, 7 Oct85.477โ€“90
4ip-check.net372/382 caught ยท 12/310 refused83.974โ€“90
5IP-API312/382 caught ยท 2/310 refused79.670โ€“85
6funkemunky (KauriVPN)310/382 caught ยท 11/310 refused70.158โ€“78

Score = 100 ร— (share caught โˆ’ 3 ร— share of home players refused) โˆ’ 5 per second of answer time. Intel leads, but its range overlaps Blackbox and zowi and others: leading, not clearly best.

Intel is our own project, and its VPN and Tor lists come from the same sources that label those addresses. The score includes the proxy list, which Connection Guard reads from 0.6.1; 0.6.0 uses the VPN, Tor, relay and hosting lists. What that means

Why a list on your server beats a lookup.

A detection service sees every player's address, limits how often you may ask, and sometimes doesn't answer. A list on your server has none of those problems.

Checking a list sends nothing.
The daily download sends no player IP, UUID or name, and every login is checked in memory against the lists already on your server. A listed address is decided right there; only addresses on no list go on to the detection services you chose.How the download works โ†’
No key, no quota.
Free detection services answer 100 to 1,000 lookups a day; after that, new players go unchecked or wait for another service. A list has no limit: the thousandth new player of the day is checked like the first.
Keeps refusing VPNs when services fail.
In the benchmark, every detection service was made to time out, rate-limit and return broken answers. Connection Guard 0.6 still refused the VPN and the Tor exit in 4 of 4 cases, without a single lookup. If a list download fails, the last good lists stay active.Failure results โ†’
Answers in under 0.1 ms.
An online detection service took 27 ms to 368 ms per answer in the same benchmark. A list lookup is a memory read, so a listed VPN adds no waiting to the login.

Five lists, five answers.

Each list has its own job. A privacy relay is not a VPN, and a hosting network alone is not a reason to refuse anyone.

Current build: ยท signed

  • VPN serversRefused

    10,939 networks

    Servers from 14 VPN operators' own server lists, and the 12 networks those operators run themselves.

  • Tor exitsRefused

    1,432 exits

    Exit relays from the Tor Project, kept 3 days after they were last listed.

  • Open proxiesRefusedFrom 0.6.1

    32,208 addresses

    Addresses that public proxy lists of at least two of 13 independent maintainers name, kept 7 days.

  • Privacy relaysLet in

    11,933 networks

    Apple iCloud Private Relay and Cloudflare WARP. Ordinary players use them without choosing a VPN.

  • Hosting networksEvidence only

    23,568 networks

    Cloud and hosting ranges: AWS, Google Cloud, Oracle, Hetzner, OVH and more. A hint, never a verdict on its own.

A network is an address range. An address on no list is unknown, never clean: Connection Guard then asks the detection services you chose. Privacy relays are let in by default; relay: VPN treats them like a VPN. Lists older than 72 hours stop deciding. The files and their signature are at intel.connectionguard.net.

How it's measured.

The open benchmark mc-antivpn-bench sends the same 692 labelled addresses to 16 detection services and reads Intel's lists the way the plugin does.

Connection Guard Intel per address group
GroupOn Intel's lists
Should be caught
Commercial VPNs125 / 125
Newly added VPN servers37 / 37
VPNs over IPv640 / 40
Tor exits80 / 80
Public proxies67 / 100
Should get in
Home connections0 / 150
Home connections, IPv60 / 60
Mobile networks0 / 100

Provider run of 7 October 2026, Intel lists as they were that day.

Read it with these in mind.

  • Intel and the benchmark are both built by Connection Guard's author. The method, the data and every log are public, and any service can contest its result.
  • The VPN and Tor rows show coverage, not skill: Intel's VPN and Tor lists come from the same operator lists and Tor Project list that label those addresses. A new VPN server that no operator list names yet is a harder test.
  • The proxy row is independent: Intel uses none of the three lists the proxy group was built from. It caught 67 of 100.
  • None of the 310 home and mobile addresses was on a list. These are volunteers' RIPE Atlas probes, not every kind of home connection.
  • The 9-point range comes from the sample size. Blackbox, zowi, ip-check.net, IP-API overlap with it, so Intel leads but is not clearly better. Blackbox catches more on its own, but also refuses more home players.
  • The plugin reads the proxy list from Connection Guard 0.6.1; 0.6.0 uses the VPN, Tor, relay and hosting lists.

Method and score ยท Plugin benchmark

On for new installs. One line to change.

New Connection Guard 0.6 installs use Intel from the first start. A server upgraded from 0.5 keeps its old settings, so Intel stays off there until you add it.

  • /cg local status shows the lists, their size and build date.
  • /cg explain <ip> shows which list matched a player.
  • /cg local update connectionguard-intel fetches a new build now.
# plugins/โ€ฆ/config.yml
provider:
  local:
    connectionguard-intel:
      enabled: true      # false switches Intel off
      update-hours: 24   # 0: no automatic download
      max-age-hours: 72  # older lists stop deciding
      relay: ALLOW       # VPN: treat iCloud Relay and WARP as VPN
The defaults of a new 0.6 install. The list address and the signing key are built into the plugin and can't be changed.

Where the data comes from.

Only public sources, 116 of them in the current build, each named with its terms. Intel publishes its compilation under CC BY 4.0 and the code that builds it under MIT; each source keeps its own terms.

Maintain one of these lists?

Intel includes every source listed here, also 11 proxy lists that publish no licence, a GPL licence or their own terms. If you'd rather your list wasn't used, tell us and it leaves with the next daily build.

legal@connectionguard.netOpen an issue

VPN servers 26 sources

The operators' public server lists and APIs, resolved by DNS where they publish host names, plus the networks registered to those operators (RIPEstat).

Tor exits 2 sources

Published by the Tor Project for exactly this use.

Open proxies 18 sources

Public proxy lists. An address goes in only when lists of two different maintainers name it on the same day. The three lists the benchmark's proxy group comes from (monosans, proxifly, vakhov) are deliberately not used.

Privacy relays 2 sources

Apple's published egress ranges, and Cloudflare's WARP prefixes from RIPEstat.

Hosting networks 68 sources

The providers' own published ranges and geofeeds, and the networks of hosting companies from RIPEstat.

Attribution: Tor Project; Apple; RIPE NCC (RIPEstat); Amazon Web Services, Google Cloud, Oracle, DigitalOcean, Akamai; the VPN operators and proxy list maintainers named above. Every source's exact terms are in the signed manifest and in SOURCES.md.

Questions about Intel.

Does Connection Guard Intel send my players' IP addresses anywhere?

No. Your server downloads the lists once a day and checks every login against them in memory. The download sends no player IP, UUID or name; the list server only sees your server's own download request, like any other file download.

Is it free?

Yes. No account, no key, no quota. It is on by default in new Connection Guard 0.6 installs. Intel publishes its compilation under CC BY 4.0, so other projects may use it with attribution; each source keeps its own terms, listed in SOURCES.md and the manifest.

How fresh are the lists?

A new build is published every day and Connection Guard checks for it every 24 hours. Tor exits stay listed 3 days and proxies 7 days after they were last seen. Lists older than 72 hours stop deciding, so stale data never refuses anyone.

A real player is on a list. What now?

Run /cg explain with their address to see which list matched, and let them in with an allow rule. Please also report the address on GitHub, so the next build can correct it for everyone.

Does it replace the detection services?

No, it goes first. A listed VPN, Tor exit or proxy is refused without any lookup, and a privacy relay is let in. An address on no list is unknown, never clean, so Connection Guard asks the detection services you chose, as before.

Which version do I need?

Connection Guard 0.6 uses the VPN, Tor, relay and hosting lists. The proxy list is read from 0.6.1 on; 0.6.0 ignores it safely.

Get it with Connection Guard.

Intel comes with the free plugin for Paper, Spigot, BungeeCord and Velocity. Nothing to sign up for.

4.5 MB JAR for every platform, from ModrinthOther download options