RE:NODE

Security11 min read

IP leaks and doxxing for server owners

Your server's address is meant to be public; your home address and real name are not. Where owners leak them - DNS history, payments, usernames - and how to stop it.

0 readers

As a game server owner, the address of your server is supposed to be public; the things to protect are your home IP address, your real name, where you live, and the accounts that lead back to them. Running the server in a datacentre rather than at home removes the biggest leak at once, because the only address players ever see belongs to the host. What remains is a handful of quieter leaks that catch people for years afterwards: a domain that once pointed at your house and is still in DNS history, your legal name on a payment page, the same username on your server and on your personal accounts, a screenshot with your Windows user folder in it, and links you click that log your address. Close those and a bad-tempered banned player has nothing to work with.

This is a post about your own exposure as the person running things. Protecting your players' data is a related but separate subject, covered in game server privacy and player data.

What is actually at risk#

Not every piece of information is equally dangerous. Rank them before you worry about all of them at once.

WhatHow it usually leaksWhat someone can do with it
Home IP addressHosting at home, old DNS records, clicked linksAttack your home connection, approximate location
Real namePayments, domain records, reused accounts, Git commitsFind your social media, workplace, family
Home addressDomain records, combining the aboveHarassment, threats, worse
Personal accountsReused usernames and email addressesTakeover attempts, more information
Your server's addressNowhere - it is public by designAttack the server, which the host absorbs

The bottom line is the reassuring one. A server's IP address in a datacentre tells an attacker nothing about you. Attacks against it land on infrastructure built to take them, not on your home router - DDoS attacks on game servers explained covers what that looks like and what filtering can and cannot do.

Doxxing is rarely one big leak. It is usually several small ones combined: a username leads to an old forum profile, which has an email address, which appears in a domain registration, which has a name, which leads to a social media account with a photo of a recognisable street. Each step is innocent on its own. Your goal is to break the chain at as many points as you can.

Hosting at home is the biggest single leak#

A server hosted on your home connection publishes your home IP address to every player who joins, and to every server list, query tool and scanner on the internet. There is no configuration that hides it, because players have to connect to something.

What that exposes:

  • Your approximate location. IP geolocation is often accurate to a city, sometimes to a district.
  • Your home connection to attacks. A banned player with a cheap "booter" service can take your whole household offline, including your work calls and everyone else's streaming. Residential connections have no filtering in front of them.
  • Your ISP. Which, combined with social engineering, is occasionally used to try to get more information about the account holder.

The options, roughly in order of how well they protect you:

  1. Rent the server. The address players see belongs to the host, in a datacentre. This is the simplest fix and the reason most communities stop hosting at home after their first attack. Hosting at home vs renting covers the costs on both sides honestly.
  2. Put a relay in front of the home server. A tunnel or a small rented server that forwards traffic, so players see the relay's address. It costs some latency and some complexity - tunnels and proxies for game servers covers the trade-offs.
  3. Keep a home server private. A server for friends only, joined over a private network such as a VPN mesh, never listed publicly and never given to strangers. Fine for a small trusted group.

If you have hosted at home before and moved, remember that your old address may already be recorded: in server list histories, in screenshots, in old messages. Restarting your router may give you a new address on many residential connections, and your ISP can sometimes issue one on request.

Other ways your home IP leaks#

Even with the server in a datacentre, your home address can leak from your own activity.

  • Links you click. Any website you visit sees your IP address. "IP logger" services exist specifically to wrap a normal-looking link and record who opened it. A banned player sending you "proof" as a link, or a "ban appeal" on an odd-looking site, may be doing exactly this. Open links from people you are in dispute with in a browser behind a VPN, or not at all.
  • Peer-to-peer games and listen servers. When you host a match from your own game client, or join a game that connects players directly, other players can see your address. Using a dedicated server for your community games avoids this for those games.
  • Self-hosted voice servers. A TeamSpeak or Mumble server run at home is the same exposure as a game server at home. Discord voice, by contrast, connects you to Discord's servers rather than to other users, so it does not reveal your address to the people you talk to. Voice servers for communities covers hosting voice properly.
  • Admin tools and RCON from home. Your home IP appears in the server's own logs whenever you connect to RCON or join as a player. That is fine as long as those logs stay private - which is a reason not to give log access to everyone on the staff team.
  • Email. Some email providers and clients include the sender's IP address in message headers. Large webmail services generally do not, but a desktop mail client sending through your own server might. Send community email from a webmail account.

Domains, DNS history and the records that outlive you#

A domain makes a server easy to find, and it is also one of the most common sources of doxxing information, because the internet remembers DNS.

DNS history. Several services record what every domain has resolved to over time. If play.example.com pointed at your home address for a year before you moved to a rented server, that address is still visible in those histories, sometimes years later. You cannot delete it. What you can do is make sure the address no longer leads anywhere useful - which, if you have since moved home or your ISP has changed your address, it may not.

Forgotten subdomains and records. A home.example.com record pointing at your NAS, an MX record pointing at a mail server in your house, a TXT record mentioning a personal email. Audit the whole zone, not just the record for the game. DNS records explained covers what each type exposes.

Registration details. Domain registrations used to publish the owner's name, address, email and phone number in WHOIS. Since the GDPR, most registrars redact personal details for individuals by default, and most offer a privacy or proxy service for free. Check your own domain's public record with any WHOIS lookup and make sure it shows the registrar's privacy details, not yours. Some country-code domains have their own rules, so check before you register one.

Cloudflare and other proxies. Putting a domain behind Cloudflare hides the origin address of a website, but it does not proxy game traffic on the normal plans, so the game server's address is still visible to anyone who connects. That is fine for a server in a datacentre; it is not a way to hide a home server. Cloudflare for websites and game servers explains why.

code
# What a careful zone for a community looks likeplay.example.com.     A      203.0.113.10    ; game server at the hostexample.com.          A      198.51.100.20   ; website at the host_minecraft._tcp.play  SRV    0 5 25565 play.example.com.# No records pointing at a home connection, no personal email in TXT

Your name, your accounts and the things you post#

The rest of the chain is identity rather than addresses.

  • Use a separate identity for the community. A username you do not use for your personal accounts, and an email address created for the community. If your community name and your gaming handle are the same as your old personal accounts, someone will find the connection in minutes.
  • Payments show names. Donation pages and payment providers can show your legal name to the person paying, depending on the service and account type. Store platforms that act as the seller put their own name in front of yours. Check what a payer sees by making a small test payment to yourself.
  • Git commits carry an email address. If you publish plugins or configs on GitHub, configure the private no-reply address GitHub provides, or every commit shows your personal email. Old commits keep whatever was set at the time.
  • Screenshots show more than you think. A Windows user folder path such as C:\Users\JohnSmith\, a taskbar with personal notifications, a browser with your real-name account logged in, a file manager showing your documents. Crop tightly, or take screenshots from a separate user account.
  • Photos can carry location data. Phone photos often contain GPS coordinates in their metadata. Strip metadata before posting images outside platforms you know remove it, or turn off location tagging in the camera.
  • Streams and voice. Real names said out loud by family members, a window visible behind you, a parcel label on the desk. Streaming the server is a good way to grow it; just look at what is in the frame.

Staff, support and social engineering#

People are a leak as well as files.

  • Staff do not need your personal details. Share what they need to run the server and nothing else. If someone needs to reach you urgently, the community email or Discord is enough.
  • Staff access to logs is access to players' addresses - and to yours, if you join the server or connect to RCON. Limit log access to the people who need it; on a panel with subusers, moderators can have console access without file access.
  • Attackers impersonate you. Someone may contact your host, your domain registrar or your Discord's members claiming to be you. Two-factor on every account that matters - panel, registrar, email, Discord - stops most of it. Two-factor on your panel account covers the panel; do the same for the email address everything else resets to.
  • Keep personal information out of support tickets beyond what is needed to verify the account. A ticket system is not where your home address belongs.

If it happens anyway#

If someone publishes your personal details or threatens you:

  1. Do not engage. Responding publicly gives them attention and often more information.
  2. Document everything. Screenshots with dates, links, usernames, message IDs. Save copies off the platform.
  3. Report to the platform. Discord, social networks and forums prohibit posting personal information and act on reports, especially with evidence.
  4. Contact the police if there are threats, or if you are worried about someone acting on your address. Some places offer a way to flag an address as at risk of hoax emergency calls; ask.
  5. Change what can be changed. A new home IP address (from your ISP or a router restart on a dynamic connection), new passwords, two-factor everywhere, privacy settings on social accounts.
  6. Tell your staff what happened so they do not accidentally confirm anything when the attacker contacts them.

It is also worth telling your community, briefly and calmly, that doxxing gets an immediate permanent ban and a report to the platform. Making it clear the behaviour is taken seriously discourages the next person.

Protect your players the same way#

Everything above applies to your players too, and you are the one holding their addresses.

  • Do not post console output publicly. Minecraft join lines include IP addresses, and a Discord console channel that mirrors the console shows them to everyone who can read the channel. Keep console bridges in staff-only channels and filter join lines if you can.
  • Do not put addresses in public ban lists, web maps or statistics pages.
  • Treat leaking a player's address as one of your most serious rules, for staff as much as players.

FAQ#

Is it dangerous that players can see my server's IP address?

Not if the server is hosted in a datacentre. That address belongs to the host, and attacks against it hit infrastructure built for them. It is only a personal risk when the server runs on your home connection.

Does a domain name hide my server's IP?

No. A domain is just a name that resolves to the address, and anyone can look it up. It makes the server easier to move and remember, but it does not hide anything.

Can someone find my home address from my IP?

Usually only a city or region from geolocation alone. The danger comes from combining an IP address with other information, or from social engineering an ISP, which is why the other leaks in this post matter more.

Should I use a VPN as a server owner?

It helps for one specific job: opening links and websites from people you do not trust, so they do not see your home address. It does nothing for a server hosted at home, and it is not a substitute for keeping your identity separate.

I hosted at home before. Is my old address still out there?

Probably, in DNS history and old server listings. If your ISP gives you a dynamic address, it may have changed since. If not, many ISPs will issue a new address on request, which makes the old records useless.


Comments

Completely anonymous: no account, no email, no cookie. We store the name you type, the text and the time - nothing else. Links are limited and markup is not rendered.

0/2000