Anti-VPN for Paper and Spigot
Drop one JAR into your server's plugins folder and new players are checked for VPNs, proxies and country rules at login. Free, open source, no account.
- Install on
- Your Paper or Spigot server
- Java
- 8 or newer
- Built against
- Spigot API 1.8.8
- Checked
- At login
Single server or network?
- On a single Paper or Spigot server, install Connection Guard in that server's plugins folder.
- Running a network behind BungeeCord or Velocity? Install it on the proxy instead. The proxy sees the real player address and one installation covers every backend.
- The plugin builds against the Spigot 1.8.8 API and the current release was tested on Paper 1.21.11. Build targets don't prove every version was tested, and Folia support is unverified.
Set up on Paper and Spigot
Download the JAR
The same file runs on every platform: Modrinth, Hangar, SpigotMC or GitHub.
Put it into the server's plugins folder
Remove older Connection Guard JARs first.
Start the server and review config.yml
The shipped config already refuses VPN and proxy hits and blocks CN and RU. Change it now if that isn't your policy.
Watch before you block (optional)
Turn kicks off and staff alerts on for a few days, as shown here, then set kick-player back to true.
Check an address
Run the command below to see what each service reports for an address.
/cg info 203.0.113.7
# plugins/…/config.yml: warn staff first, block later behavior: vpn: kick-player: false notify-staff: true geo: kick-player: false notify-staff: true type: 'BLACKLIST' list: []
New to anti-VPN plugins? Read how to block VPNs on a Minecraft server and how country rules work.
What you control
- VPN and proxy checks
- ProxyCheck, IP-API, IPHub, VPNAPI or your own REST API. With several services, choose how many must agree.
- Country rules
- A blocklist or an allowlist of countries, with its own action and message.
- Your response
- Refuse the connection, alert staff in chat, post to a Discord webhook or run a console command.
- Caching
- Answers are kept in SQLite or Redis, so repeat logins from the same address don't spend your lookup quota.
- Exemptions
- Let trusted players or addresses through by UUID, IP or LuckPerms permission.
- Inspect any address
- /cg info shows what each service reported, so you can see why a player was flagged.
Paper and Spigot questions
Which Minecraft versions are supported?
The Spigot adapter builds against the Spigot 1.8.8 API, and release 0.4.11 was tested on Paper 1.21.11 with Java 21. That doesn't prove every version in between was tested, so check on a test server first.
Does it work on Folia?
Folia support is unverified. Test carefully before relying on it.
Is Connection Guard free?
Yes. The plugin is free and open source under the MIT license, and no Connection Guard account is needed. The detection services you choose have their own free plans and limits.
Will it slow down logins?
A new IP address is checked once during login with the services you enabled. The answer is cached (VPN results for 24 hours and country results for 72 hours by default), so the next login from the same address needs no lookup.
Can I warn staff instead of kicking players?
Yes. Set kick-player to false and notify-staff to true for VPN or country rules. Staff with connectionguard.notify.vpn or connectionguard.notify.geo then see an alert, and you can also post to a Discord webhook.
Can I let specific players through?
Yes. Add their UUID or IP address under behavior.vpn.exemptions and behavior.geo.exemptions. Permission-based exemptions use LuckPerms and need the matching use-permission-exemption switch.