VPN and Tor lists, checked on your server.
Connection Guard Intel is a signed set of VPN, Tor, relay and proxy lists. Your server downloads them once a day and checks every login against them itself: no API key, no daily quota, and checking a list sends no player's IP anywhere. Connection Guard 0.6 reads the VPN, Tor and relay lists; the proxy list follows in 0.6.1.
4.5 MB JAR for every platform, from ModrinthOther download options
- In Connection Guard 0.6, on for new installs
- Signed, rebuilt daily
- Every source named, with its terms
| Rank | Service | Score ยท range | 95 % range60โ100 |
|---|---|---|---|
| 1 | Connection Guard Intel349/382 caught ยท 0/310 refused | 91.485โ94 | |
| 2 | Blackbox379/382 caught ยท 12/310 refused | 87.077โ93 | |
| 3 | zowi339/382 caught ยท 2/310 refused ยท earlier run, 7 Oct | 85.477โ90 | |
| 4 | ip-check.net372/382 caught ยท 12/310 refused | 83.974โ90 | |
| 5 | IP-API312/382 caught ยท 2/310 refused | 79.670โ85 | |
| 6 | funkemunky (KauriVPN)310/382 caught ยท 11/310 refused | 70.158โ78 |
Score = 100 ร (share caught โ 3 ร share of home players refused) โ 5 per second of answer time. Intel leads, but its range overlaps Blackbox and zowi and others: leading, not clearly best.
Intel is our own project, and its VPN and Tor lists come from the same sources that label those addresses. The score includes the proxy list, which Connection Guard reads from 0.6.1; 0.6.0 uses the VPN, Tor, relay and hosting lists. What that means
Why a list on your server beats a lookup.
A detection service sees every player's address, limits how often you may ask, and sometimes doesn't answer. A list on your server has none of those problems.
- Checking a list sends nothing.
- The daily download sends no player IP, UUID or name, and every login is checked in memory against the lists already on your server. A listed address is decided right there; only addresses on no list go on to the detection services you chose.How the download works โ
- No key, no quota.
- Free detection services answer 100 to 1,000 lookups a day; after that, new players go unchecked or wait for another service. A list has no limit: the thousandth new player of the day is checked like the first.
- Keeps refusing VPNs when services fail.
- In the benchmark, every detection service was made to time out, rate-limit and return broken answers. Connection Guard 0.6 still refused the VPN and the Tor exit in 4 of 4 cases, without a single lookup. If a list download fails, the last good lists stay active.Failure results โ
- Answers in under 0.1 ms.
- An online detection service took 27 ms to 368 ms per answer in the same benchmark. A list lookup is a memory read, so a listed VPN adds no waiting to the login.
Five lists, five answers.
Each list has its own job. A privacy relay is not a VPN, and a hosting network alone is not a reason to refuse anyone.
Current build: ยท signed
VPN serversRefused
10,939 networks
Servers from 14 VPN operators' own server lists, and the 12 networks those operators run themselves.
Tor exitsRefused
1,432 exits
Exit relays from the Tor Project, kept 3 days after they were last listed.
Open proxiesRefusedFrom 0.6.1
32,208 addresses
Addresses that public proxy lists of at least two of 13 independent maintainers name, kept 7 days.
Privacy relaysLet in
11,933 networks
Apple iCloud Private Relay and Cloudflare WARP. Ordinary players use them without choosing a VPN.
Hosting networksEvidence only
23,568 networks
Cloud and hosting ranges: AWS, Google Cloud, Oracle, Hetzner, OVH and more. A hint, never a verdict on its own.
A network is an address range. An address on no list is unknown, never clean: Connection Guard then asks the detection services you chose. Privacy relays are let in by default; relay: VPN treats them like a VPN. Lists older than 72 hours stop deciding. The files and their signature are at intel.connectionguard.net.
How it's measured.
The open benchmark mc-antivpn-bench sends the same 692 labelled addresses to 16 detection services and reads Intel's lists the way the plugin does.
| Group | On Intel's lists |
|---|---|
| Should be caught | |
| Commercial VPNs | 125 / 125 |
| Newly added VPN servers | 37 / 37 |
| VPNs over IPv6 | 40 / 40 |
| Tor exits | 80 / 80 |
| Public proxies | 67 / 100 |
| Should get in | |
| Home connections | 0 / 150 |
| Home connections, IPv6 | 0 / 60 |
| Mobile networks | 0 / 100 |
Provider run of 7 October 2026, Intel lists as they were that day.
Read it with these in mind.
- Intel and the benchmark are both built by Connection Guard's author. The method, the data and every log are public, and any service can contest its result.
- The VPN and Tor rows show coverage, not skill: Intel's VPN and Tor lists come from the same operator lists and Tor Project list that label those addresses. A new VPN server that no operator list names yet is a harder test.
- The proxy row is independent: Intel uses none of the three lists the proxy group was built from. It caught 67 of 100.
- None of the 310 home and mobile addresses was on a list. These are volunteers' RIPE Atlas probes, not every kind of home connection.
- The 9-point range comes from the sample size. Blackbox, zowi, ip-check.net, IP-API overlap with it, so Intel leads but is not clearly better. Blackbox catches more on its own, but also refuses more home players.
- The plugin reads the proxy list from Connection Guard 0.6.1; 0.6.0 uses the VPN, Tor, relay and hosting lists.
On for new installs. One line to change.
New Connection Guard 0.6 installs use Intel from the first start. A server upgraded from 0.5 keeps its old settings, so Intel stays off there until you add it.
/cg local statusshows the lists, their size and build date./cg explain <ip>shows which list matched a player./cg local update connectionguard-intelfetches a new build now.
# plugins/โฆ/config.yml provider: local: connectionguard-intel: enabled: true # false switches Intel off update-hours: 24 # 0: no automatic download max-age-hours: 72 # older lists stop deciding relay: ALLOW # VPN: treat iCloud Relay and WARP as VPN
Where the data comes from.
Only public sources, 116 of them in the current build, each named with its terms. Intel publishes its compilation under CC BY 4.0 and the code that builds it under MIT; each source keeps its own terms.
Maintain one of these lists?
Intel includes every source listed here, also 11 proxy lists that publish no licence, a GPL licence or their own terms. If you'd rather your list wasn't used, tell us and it leaves with the next daily build.
VPN servers 26 sources
The operators' public server lists and APIs, resolved by DNS where they publish host names, plus the networks registered to those operators (RIPEstat).
- AS209854 Cyberzone S.A. (Surfshark)RIPE NCC terms
- AS39351 31173 Services AB (Mullvad)RIPE NCC terms
- AS136787 PacketHub S.A. (Nord Security)RIPE NCC terms
- AS147049 PacketHub S.A. (Nord Security)RIPE NCC terms
- AS207137 PacketHub S.A. (Nord Security)RIPE NCC terms
- AS141039 PacketHub S.A. (Nord Security)RIPE NCC terms
- AS62651 Strong Technology (StrongVPN, IPVanish)RIPE NCC terms
- AS140952 Strong Technology (StrongVPN, IPVanish)RIPE NCC terms
- AS22781 Strong Technology (StrongVPN, IPVanish)RIPE NCC terms
- AS209103 ProtonVPN (Proton AG)RIPE NCC terms
- AS199218 ProtonVPN-2 (Proton AG)RIPE NCC terms
- AS208172 PV-HOSTED (Proton AG)RIPE NCC terms
- Mullvadnone published
- NordVPNnone published
- IVPNnone published
- Private Internet Accessnone published
- Surfsharknone published
- AirVPNnone published
- Windscribenone published
- IPVanishnone published
- PrivadoVPNnone published
- OVPNnone published
- AzireVPNnone published
- PrivateVPNnone published
- vpn.acnone published
- FastestVPNnone published
Tor exits 2 sources
Published by the Tor Project for exactly this use.
- Tor Project bulk exit listpublished for this use
- Tor Project CollecTor exit listspublished for this use
Open proxies 18 sources
Public proxy lists. An address goes in only when lists of two different maintainers name it on the same day. The three lists the benchmark's proxy group comes from (monosans, proxifly, vakhov) are deliberately not used.
- jetkai/proxy-listMIT
- clarketm/proxy-listMIT
- sunny9577/proxy-scraperMIT
- ErcinDedeoglu/proxiesMIT
- ErcinDedeoglu/proxiesMIT
- ErcinDedeoglu/proxiesMIT
- ErcinDedeoglu/proxiesMIT
- TheSpeedX/PROXY-Listnone published
- TheSpeedX/PROXY-Listnone published
- TheSpeedX/PROXY-Listnone published
- ShiftyTR/Proxy-Listnone published
- hookzof/socks5_listnone published
- roosterkid/openproxylistnone published
- mmpx12/proxy-listnone published
- zloi-user/hideip.menone published
- prxchk/proxy-listnone published
- MuRongPIG/Proxy-MasterGPL-3.0
- proxyscrape free APIservice terms not reviewed
Privacy relays 2 sources
Apple's published egress ranges, and Cloudflare's WARP prefixes from RIPEstat.
- Apple iCloud Private Relay egress rangesnone published
- AS13335 Cloudflare inside its WARP/Gateway egress blocksRIPE NCC terms
Hosting networks 68 sources
The providers' own published ranges and geofeeds, and the networks of hosting companies from RIPEstat.
- Amazon Web Servicespublished for this use
- Google Cloudpublished for this use
- Oracle Cloudpublished for this use
- DigitalOcean geofeedpublic geofeed
- Akamai / Linode geofeedpublic geofeed
- AS24940 HetznerRIPE NCC terms
- AS16276 OVHRIPE NCC terms
- AS51167 ContaboRIPE NCC terms
- AS9009 M247RIPE NCC terms
- AS60068 Datacamp (CDN77)RIPE NCC terms
- AS60781 Leaseweb NLRIPE NCC terms
- AS28753 Leaseweb DERIPE NCC terms
- AS20473 Vultr (Choopa)RIPE NCC terms
- AS63949 Akamai LinodeRIPE NCC terms
- AS14061 DigitalOceanRIPE NCC terms
- AS12876 ScalewayRIPE NCC terms
- AS8560 IONOSRIPE NCC terms
- AS199524 G-Core LabsRIPE NCC terms
- AS21859 ZenlayerRIPE NCC terms
- AS62240 ClouviderRIPE NCC terms
- AS40676 PsychzRIPE NCC terms
- AS8100 QuadraNetRIPE NCC terms
- AS11878 tzuloRIPE NCC terms
- AS203020 HostRoyaleRIPE NCC terms
- AS206804 EstNOCRIPE NCC terms
- AS137409 GSL NetworksRIPE NCC terms
- AS42708 GleSYSRIPE NCC terms
- AS212238 DatacampRIPE NCC terms
- AS49981 WorldStreamRIPE NCC terms
- AS51396 PfcloudRIPE NCC terms
- AS206092 IPXORIPE NCC terms
- AS30633 Leaseweb USARIPE NCC terms
- AS46562 PerformiveRIPE NCC terms
- AS47583 HostingerRIPE NCC terms
- AS25369 Hydra CommunicationsRIPE NCC terms
- AS136557 Host UniversalRIPE NCC terms
- AS49453 Global LayerRIPE NCC terms
- AS396356 Latitude.shRIPE NCC terms
- AS262287 Latitude.sh LTDARIPE NCC terms
- AS36352 HostPapaRIPE NCC terms
- AS42201 PVDataNetRIPE NCC terms
- AS42675 ObehostingRIPE NCC terms
- AS34343 Eweka Internet ServicesRIPE NCC terms
- AS205467 Base IPRIPE NCC terms
- AS34305 Base IPRIPE NCC terms
- AS43357 Owl LimitedRIPE NCC terms
- AS32489 Amanah TechRIPE NCC terms
- AS6206 NetroutingRIPE NCC terms
- AS51852 Private LayerRIPE NCC terms
- AS13737 InterconnecxRIPE NCC terms
- AS51430 AltusHostRIPE NCC terms
- AS52048 RixHostRIPE NCC terms
- AS43350 NForce EntertainmentRIPE NCC terms
- AS63473 HostHatchRIPE NCC terms
- AS197706 KeminetRIPE NCC terms
- AS50304 Blix SolutionsRIPE NCC terms
- AS55720 Gigabit HostingRIPE NCC terms
- AS43289 TrabiaRIPE NCC terms
- AS53356 Free Range Cloud HostingRIPE NCC terms
- AS42831 UK Dedicated ServersRIPE NCC terms
- AS397423 Tier.NetRIPE NCC terms
- AS46664 VolumeDriveRIPE NCC terms
- AS400587 RyamerRIPE NCC terms
- AS41564 Orion NetworkRIPE NCC terms
- AS394256 Tech Futures InteractiveRIPE NCC terms
- AS133480 5G Network OperationsRIPE NCC terms
- AS4785 xTomRIPE NCC terms
- AS3258 xTom JapanRIPE NCC terms
Attribution: Tor Project; Apple; RIPE NCC (RIPEstat); Amazon Web Services, Google Cloud, Oracle, DigitalOcean, Akamai; the VPN operators and proxy list maintainers named above. Every source's exact terms are in the signed manifest and in SOURCES.md.
Questions about Intel.
Does Connection Guard Intel send my players' IP addresses anywhere?
No. Your server downloads the lists once a day and checks every login against them in memory. The download sends no player IP, UUID or name; the list server only sees your server's own download request, like any other file download.
Is it free?
Yes. No account, no key, no quota. It is on by default in new Connection Guard 0.6 installs. Intel publishes its compilation under CC BY 4.0, so other projects may use it with attribution; each source keeps its own terms, listed in SOURCES.md and the manifest.
How fresh are the lists?
A new build is published every day and Connection Guard checks for it every 24 hours. Tor exits stay listed 3 days and proxies 7 days after they were last seen. Lists older than 72 hours stop deciding, so stale data never refuses anyone.
A real player is on a list. What now?
Run /cg explain with their address to see which list matched, and let them in with an allow rule. Please also report the address on GitHub, so the next build can correct it for everyone.
Does it replace the detection services?
No, it goes first. A listed VPN, Tor exit or proxy is refused without any lookup, and a privacy relay is let in. An address on no list is unknown, never clean, so Connection Guard asks the detection services you chose, as before.
Which version do I need?
Connection Guard 0.6 uses the VPN, Tor, relay and hosting lists. The proxy list is read from 0.6.1 on; 0.6.0 ignores it safely.
Get it with Connection Guard.
Intel comes with the free plugin for Paper, Spigot, BungeeCord and Velocity. Nothing to sign up for.
4.5 MB JAR for every platform, from ModrinthOther download options