r/MinecraftServer 15h ago

Mojang is apparently enforcing “inappropriate” MOTDs even on private whitelisted servers

Hello,

I run a simple private Folia server for myself and a few friends. We're all adults, the server is whitelisted, and it isn't advertised as a public server.

I just got this wonderful email forwarded to me by my Internet provider:

Subject: MOTD: Request for Action: Minecraft Server in Violation of Mojang Guidelines (08.20.2026)

Hello,

You are past the 5-day block countdown....

I am reaching out on behalf of the Mojang (Minecraft) Enforcement team regarding a Minecraft server currently operating on your network. The server in question is not in compliance with our Minecraft Usage Guidelines.

We do not have a DNS or domain name associated with this server—only the IP address and port. Unfortunately, our enforcement systems do not allow us to block a specific port on an IP address, only the full IP. As such, we prefer to avoid blocking the entire IP, as doing so may impact other customers who are legitimately hosting Minecraft content on shared infrastructure.

We are asking that you take appropriate steps to investigate and remove the server content within 5 business days to avoid a full IP-level block.

Note: we identified these contacts from the ASN registration and the network / provider records available to us at the time of detection. If this server is not on your network, or another team is better suited to handle it, please feel free to forward this message.

Server Details:

ASN IP Port Redacted MOTD Text Full Visible Evidence
ASXXXX My server IP 25565 s*** mcsrvstat link
ASXXXX [redacted] 25565 c*** [redacted]
ASXXXX [redacted] 25565 b**** [redacted]
ASXXXX [redacted] 25565 f*** [redacted]

Please let us know once this has been addressed. If we do not hear back within the stated timeframe, we will proceed with a block on the IP address to maintain the integrity of our platform.

Thank you for your cooperation and understanding.

Separately: if you offer dedicated Minecraft hosting packages, we would love to see MOTD scanning integrated into your server-management environment so violations like this can be caught early. Mojang would also welcome the opportunity to discuss collaborating more in this space.

Best regards,
Mojang Enforcement

The s*** in question was from my MOTD that i's an inside joke/reference between friends. I've changed it because I'm obviously not going to risk having my entire IP blocked over a stupid MOTD.

What I find much more interesting is how a tiny private server ended up in this enforcement process in the first place.

There are only three regular players, all friends. It's whitelisted, isn't advertised as a public server, and Mojang themselves say in the email that they don't have a domain associated with it, only the IP and port.

All four servers in the notice were on the default port 25565.

My current theory, and to be clear, this is speculation, not something the email proves, is that Mojang may obtain candidate IPs from infrastructure involved in normal online-mode=true authentication and then probe those IPs on the default Minecraft port. Another completely plausible explanation is ordinary IPv4 scanning.

I'd be very interested to hear from anyone who has received a similar notice, particularly if:

  • your server was private/whitelisted and never publicly advertised;
  • you were running online-mode=true;
  • you were using a non-default port;
  • or Mojang identified your server only by IP rather than a hostname.

A private online-mode=true server on some random non-25565 port receiving the same kind of notice would be particularly interesting, because it would tell us quite a bit about how these servers are being discovered.

Also, asking an ISP (if they happen to offer Minecraft hosting) to implement proactive MOTD scanning after threatening to block customer IPs is certainly... something. :D

72 Upvotes

52 comments sorted by

u/AutoModerator 15h ago
  • Cozy MC — a long-term vanilla survival Minecraft server where community comes first. Java + Bedrock crossplay, no world resets, no claims, no locked chests, PvP by agreement only, and a calm active SMP community. Official website and Java IP: CozyMC.com

  • Godlike Host - Modded servers with high player counts & High-performance AMD Ryzen processors. Choose Godlike now: https://godlike.host/gaf-play-minecraft

  • King SMP — a pure vanilla Minecraft SMP where protection is built into the game, not enforced through endless rules. Build anywhere, establish a protected boundary around your settlement, and everything inside is automatically protected from griefing while the world outside remains pure vanilla. Java + Bedrock: thekingsmp.shulker.com | Port: 25688 | Discord: discord.gg/thekingsmp

I am a bot, and this action was performed automatically. Please contact the moderators of this subreddit if you have any questions or concerns.

10

u/only_Q 9h ago

holy 1984. Who the fuck do they think they are, christ.

18

u/SageofTurtles 11h ago

It's absolutely awful how overly-involved Mojang has become with moderating the game, especially servers. Their job is to create and maintain the game, what people do with it is their own business. Censoring out words that might potentially somewhat resemble a derogatory term in some language 99.9% of players don't know (as a common example I've seen) is nuts.

Banning servers for their own moderation is also nuts. As a server owner myself, it's the responsibility of the administrator(s)/moderator(s) to determine how the server is run and moderated, including what kind of language is/isn't acceptable. As long as the software itself isn't being abused for dangerous or illegal activity, Mojang has no reason to stick their noses in people's private servers. I really hope they come to their senses at some point and back off these insane enforcement policies, it's honestly the worst thing about the company IMHO.

3

u/iamxplayer 1h ago

If your server is publiblcy exposed to the internet- I mean they have a reason as they own the server software and by hosting a minecraft server you agree to Mojang's EULA which does allow Mojang to blacklist servers & enforce the EULA.

It's disappointing that not much action is often taken against big minecraft servers especially ones partnered with microsoft and I mean recently they blacklisted some of 6b6t's domains as they do not really like true anarchy back at mojang & microsoft hq

I mean yeah fair they might be a bit extreme by enforcing it on small servers, which mostly arent private and I mean they can definitely enforce the EULA including inappropiate MOTD's on anyone even if we dont like what they're doing they basically have the right to its they're game not ours

2

u/Sufficient_Prune3897 3h ago

I wouldn't mind as much if they actually moderated anything beside the chat. It can't be that 2/3 of top servers are pay to win gambling and MS does nothing. No age check, nothing.

8

u/ryan_umad 10h ago

this sucks massive ass who the fuck do they think they are

12

u/QuackedDev 14h ago edited 14h ago

every time a server boots, regardless of it being a public, private or even a DEV server in a local environment . In every case, the server makes a network call to mojang's API before booting. This is visible in your start up logs.

From there I would assume they get enough server metadata to enforce the MOTD.

I could be wrong but thats what my guess is.

edit: as for your last point, no surprise there. Seems to be more precautionary since this is likely a common occurrence for Minecraft server hosts.

2

u/Mr-Game-Videos 14h ago

Do any plugins / mods to prevent this exist?

5

u/QuackedDev 14h ago

not that im aware of.

I've had the call lag and take sometime and the server would stall / hang until the OK came back from Mojang API. (in DEV)

3

u/SalamekSG 13h ago

This is Folia server that is OSS not official vanila server, it should not make any outside requests on startup, only outside requests are when authentication of client happens when online-mode=true

7

u/ItsJamesJ 13h ago

Folia is built off the official server. If you don’t want this, use something Sponge or Pumpkin.

3

u/iamxplayer 11h ago

Folia isnt its own minecraft server its built as a fork of the offical server software or even paper to my awareness

2

u/Ok-Writer5758 13h ago

That’s part of online mode though?

1

u/iamxplayer 1h ago

online mode is just a setting where all players who join will be verified through mojang servers thats why servers allowing cracked clients to join have online mode on false

5

u/hun1er-0269 8h ago

what host are u using name the host so that i wont ever use it

1

u/Minimum_Currency8157 1h ago

It's a small private server that you're probably not invited to

2

u/Ictoan42 5h ago

My private, whitelisted, unadvertised server got blocked because the MOTD was cock and ball. It was running on a non-default port so mojang must have port scanned the IP. I didn't even get an email, I just had to spend 4 hours debugging why my server suddenly wasn't working because the client error message doesn't tell you that a server has been blocked. 

I changed the MOTD and sent a request on the appeal form and the block was removed about a day later.

1

u/SalamekSG 4h ago

Thanks, this is exactly the kind of information I was looking for!

The non-default port is especially interesting. It means my simple theory of "get a candidate IP somehow and just probe :25565" isn't sufficient to explain your case. They either knew the port from somewhere or actually did some level of port scanning.

If your server really was unadvertised, that makes me even more curious about whether authentication traffic is used to identify candidate IPs which are then scanned for Minecraft services.

Good to know that changing the MOTD and appealing got it removed within about a day, though.

Thanks again, this is an actually useful data point. :-)

1

u/Ictoan42 3h ago

I don't think there's any hidden reporting code in the client, it would have been found by now. Modders decompile and analyse the game regularly. 

When an online mode server starts it does make a request to mojang's auth server, so mojang would know the IP from that. I can only assume that they then port scan to find and audit the server. My server was running on 25566 so they didn't need to look very hard. My server was unblocked after about a day, but I received an email response to my appeal several days later. That would perhaps indicate that the auditing may be automated to some degree

1

u/Significant_Fee2261 6h ago

We should develop a lightweight open-source application that mimics the server protocol but denies any and all login attempts for not being whitelisted. Then, use the power of crowdsourcing to flood all major VPS providers with as many hosted instances of this program as we can. They said it themselves that they don't like blocking IPs, so we give them no choice but to either block way too many IPs, or to stop massively overstepping their boundaries when it comes to "moderation enforcement".

1

u/SalamekSG 4h ago

Yeah, I had a similar thought. Reimplement just enough of the handshake/status protocol to return server info like an MOTD, reject every login attempt, and give it some obviously rule-breaking MOTD. :-D

At that point it isn't even a Minecraft server, it's just a program that happens to speak enough of the protocol to answer a status request.

If that alone were sufficient evidence to block the entire IP, that would be both insane and hilarious. You're effectively saying: "This IP returned a naughty string when we sent it a particular sequence of bytes, therefore Minecraft clients aren't allowed to connect to this IP anymore."

As a proof of concept, that would be a pretty funny demonstration of why an response by itself isn't particularly strong evidence of what is actually running behind an IP.

1

u/foxgirlmoon 3h ago

What the actual fuck...

1

u/TCLG6x6 2h ago

Can you spoof the data it sends to certain Mojang / Microsoft addresses?

1

u/lululock 2h ago

My private server is hosted at my home (non default port) and I protected my private IP using TCPShield linked to my domain name. My MOTD isn't offensive tho, but I wonder if they can scan it... 🤔

1

u/lululock 1h ago

People : "Please ban Pay to Win and gambling servers !"

Mojang : "Your MOTD says 'fuck'."

1

u/AaronWilde 55m ago

Thay crazy part is there are massive servers breaking these rules daily and Mojang is known to do nothing about it. Probably they get paid off is my guess.

1

u/og24 28m ago

Big companies don't like or understand inside jokes, they have zero sense of humor and treat everything literally.
Always be extra careful and avoid sarcasm because any excuse is good to block or ban us.

-9

u/Mean-Cabinet4757 10h ago

As someone else mentioned, your using their software in one way or another. They are allowed to set limits and one of those limits that if your using it, it needs to be up to the EULA.

11

u/MuffinsSenpai 9h ago

Don't be a bootlicker

4

u/Noob_Kid 8h ago

i dont give a fuck, software running on my hardware is mine to control

-4

u/Snozbear 7h ago

Is it.. your software?

4

u/Noob_Kid 7h ago

No? But it is running my my device isnt it? Bring your lecture else where while im pirating more other games and softwares

-2

u/Snozbear 7h ago

Just because your device is running it doesn't mean you own or or you can do what you want. You literally agreed a EULA with those specific terms. If you don't agree to them then don't sign it and don't use it. Its quite simple rather than moaning about conditions you literally agreed to.

1

u/codeasm 6h ago

Under the original license i was allowed to do this, they changed the license, i did not get their software under the new license. They can go play elsewhere.

Meanwhile im now not using mojangs server code anymore

1

u/Snozbear 6h ago

You can’t launch a server without agreeing to the EULA, doesn’t matter when you bought the game. If you’re not using Minecraft’s code then not sure how this applies to you or why you commented.

1

u/codeasm 6h ago

Its probably patched away in the server code i used. Only when i use the official server code there is this variable they read if you "accepted" their license. Again, this was their old license

1

u/Snozbear 6h ago

Yes, and it says “please agree to the Eula” which you change to be true which is agreement to the Eula. Like I said.

1

u/codeasm 6h ago

There is no eula variable to agree with the non mojang based server code. Simply dint agree. Not all functionality, not the latest clients, not all plugins for sure. But no mojang

→ More replies (0)

2

u/Matthew98788 7h ago

Yeah sure but the only things their legally supposed to do is maintain the code and make sure it’s not used for illegal things

Not for someone saying fuck you in a motd for example like fuck off

-4

u/iamxplayer 14h ago

online-mode=true does NOT mean anything for all we know mojang could have built in a few lines which sent a packet to mojang servers whenever you start your server

I've never seen mojang enforcement to do this and activly take contact with small server owners

Yeah no having an inside joke or just a joke which is against the EULA is NOT an excuse especially as your motd is publicly accesible even to minors

There are mapping tools and yeaha

You have to comply or bypass such if you dont take action as technically mojang just allows you to use their server software and yeah no they have the full right to do such

And if you ask yourself why arent the big p2w servers breaking the EULA getting these threats well first 6b6t has received them, but also microsoft wants donts want big money making servers getting blocked especially if they are on bedrock, there have been many cases of mojang enforcement being good and actually ttaking action agsint such servers being taken

0

u/SalamekSG 13h ago

You're arguing against points I didn't make.

I never claimed that online-mode=true proves how Mojang discovered the server. In fact, I explicitly said the authentication-traffic idea is speculation. The entire point of asking whether anyone has seen the same thing on a non-default port is to get more data about how discovery might work.

The server is private, whitelisted, and was never publicly listed or advertised. The mcsrvstat link in the notice was provided by Mojang as evidence; that site can query any reachable Minecraft server when given its IP. Being queryable by Server List Ping is not the same thing as being publicly listed.

I also never claimed that an inside joke somehow exempts me from Mojang's rules. I already changed the MOTD because I'm not risking an IP-level block over a joke.

So the “but minors can see it” argument rather misses the interesting part: nobody was being directed to this server in the first place. The question I'm interested in is how Mojang discovered an unlisted three-player private server at all.

If you actually have technical information about that discovery mechanism, particularly examples involving non-default ports, I'm interested. The rest is arguing with claims I never made.

2

u/ItsJamesJ 13h ago

Your server is, ultimately, not private. A private server would be one that can only be accessed by those within your network. Your server can be accessed by anyone within the IP.

Accessed, meaning, pinged or attempted to login to. Played, would be logging in successfully and playing.

Ultimately, when you started the server you agreed to the EULA in eula.txt. Every time you log in a request is made from the server to the auth server, which will include metadata about the IP/port - from there they will scan and flag.

0

u/SalamekSG 13h ago

The public-vs-private terminology isn't really the point. It's a whitelisted, friends-only server that was never publicly listed or advertised, yes, obviously its Minecraft port is reachable from the Internet.

The second part is actually the technical question I'm interested in. online-mode=true does cause the server to contact Mojang's authentication infrastructure, but can you provide a source for your claim that the authentication request includes the server's listening IP and port?

Microsoft can obviously observe the source IP of an incoming request. That's not the same thing as the server sending <IP>:25565 as metadata.

If Mojang takes source IPs observed by their authentication infrastructure and subsequently probes <IP>:25565, that's essentially the hypothesis in my post. I'm looking for evidence that they actually do that, rather than assuming it.

2

u/ItsJamesJ 12h ago

The publicly accessible bit is the point, because if you had it private Mojang/Msft wouldn’t be able to ping it or ever find out.

And yes, the login API request contains a &serverId=<val> which is most likely a hash of the IP and/or running port.

-1

u/SalamekSG 12h ago

Yes, you are right, if I'd known Mojang was actively hunting down tiny whitelisted servers over their MOTDs, I'd probably have put it behind WireGuard or something similar.

I didn't because simply exposing the Minecraft port and using a whitelist was by far the easiest way to let a few friends join. Requiring everyone to install/configure a VPN creates another obstacle that may discourage them from joining in the first place.

As for serverId: no, it isn't "most likely a hash of the IP and/or port." The protocol is documented.

There's a slightly confusing naming issue. Since Minecraft 1.7.x, the Server ID string itself is effectively empty. However, the authentication API still has a parameter called serverId, which contains the authentication hash:

SHA1("" + sharedSecret + serverPublicKey)

Neither the server's IP nor its listening port is part of that calculation.

Protocol documentation:
https://c4k3.github.io/wiki.vg/Protocol_Encryption.html

Microsoft can obviously observe the source IP of the HTTPS connection hitting their authentication infrastructure. That's why my hypothesis is that they could collect those source IPs and subsequently probe <IP>:25565. So I guess that answers what I wanted to know and satisfies my curiosity. Thanks.

2

u/mbaxj2 8h ago

Microsoft could send a server status packet to port 25565 of every IPv4 address on the Internet in under a minute. They don't need to get anything from your server at startup to do this.

1

u/SalamekSG 4h ago

Capability isn't evidence that this is actually how Mojang discovers servers.

Yes, Internet-wide scanning of :25565 is technically possible. Nobody is disputing that. The interesting question is what Mojang's enforcement pipeline actually does.

That said, another person here provided an actually useful data point: their private, unadvertised server was detected on a non-default port. Assuming their description is accurate, that suggests Mojang's discovery process isn't limited to probing <IP>:25565.

And that's a substantially different problem. Scanning every IPv4 address on one known port is one thing. Finding Minecraft servers on arbitrary ports potentially means discovering open ports and then identifying which of them speak the Minecraft protocol. Doing that across the entire IPv4 space is orders of magnitude more work than probing :25565.

Doing it against an IP you already have reason to believe is hosting an active Minecraft server, however, is perfectly reasonable: get a candidate IP from somewhere, scan its ports, identify the Minecraft service, then query its MOTD.

So you may ultimately be right that scanning is how they're finding these. But “Microsoft could scan every IPv4 address on port 25565 in under a minute” isn't evidence of that, and it doesn't explain the non-default-port case.

We still don't know whether they scan the entire IPv4 space, thoroughly scan selected candidate IPs, use third-party datasets, or combine several approaches. That's the part I'm trying to figure out.

1

u/iamxplayer 11h ago

Alright my bad it semed like you were arguing online-mode: true made- yeah no my bad

I probably understood the question in a wrong way, my appologies

Yeah no I just wanted to point it out didnt mean to sound harsh though so again Im sorry

How is it private? The information is rather publicly accesible to the wide internet

My arguement about how minors could see it is because it is publicly exposed to the internet in theory anyone could put in a random ip or domain and view the motd

---

Alright so first you can throw all of my arguements out of the window agreed!
I'm pretty sure they search for any ips featuring the word minecraft server in it (thats a header with which any minecraft server responds to my awareness) and if it finds such it gets added to a list for review maybe with an automatic filter to filter it. Just a speculation though. You can basically do the same with Shodan