Skip to content

Network diagnostics

DNS, ports, proxy architecture and origin exposure.

DNS

The hostname needs an A (IPv4) or AAAA (IPv6) record. Tickhound checks that it resolves and lists the addresses.

Minecraft port

We open one TCP connection to the public port and send a standard status request. If it answers, you also see the version and player count the server reports.

SRV records

If you do not use port 25565, publish a _minecraft._tcp SRV record so players do not have to type the port.

Multiple origins

Several A records mean several machines. Every one must be protected identically.

Proxy architecture

Backends should be addressed over 127.0.0.1 or a private network. Tickhound reads the proxy configuration and flags backends that use public addresses.

Backend ports

List your backend ports on the server so exposure can be checked. Without them, exposure checks are skipped.

UDP (Bedrock/Geyser)

UDP is connectionless, so a TCP check cannot confirm it. Test from a Bedrock client or check your firewall rule for UDP 19132.

Latency

Connection time from the probe location is only a hint; it depends on where the probe runs.

DDoS-protection posture

Tickhound looks for known protection providers in your DNS CNAME. This is a heuristic: protection can also exist at the network level where DNS shows nothing. It never tests protection by generating attack traffic.