FiveM server not showing in the server list: causes and fixes

Updated

Verified against FXServer build 35245 (recommended), 37150 (latest) and txAdmin v8.1.1, checked on 7 October 2026. Sources

VerdictNot evidence of a DDoS by itself

The causes the documentation lists are mostly configuration and reachability, not an attack.

FiveShield does not help with this

FiveShield does not fix this, and a proxy can even cause it when the listing overrides are missing.

The server list is fed by your own server. FXServer sends a heartbeat, an outbound HTTPS request, to the Cfx.re listing service every 3 minutes, and the proxy-setup page says the listing backend also queries your server. A server goes missing, or shows as private, when the heartbeat never leaves, when the config says private or LAN, when required settings are absent, or when the backend cannot reach the server.

Check, in order: how long ago the server started (the documentation allows 8 minutes), whether someone on another network can open http://IP:Port/info.json and use Direct Connect, what heartbeat prints, and five lines of server.cfg. The triage below takes two minutes.

Consider an attack only if the server was listed with players connected, your host or your inbound traffic graph shows an event at the moment it vanished, and Direct Connect fails for everyone. The official server-issues page lists no attack among the causes.

Messages you may see

  • Server list query returned an error: <reason>

    In the server console, in red, after a heartbeat. Not shown for the first successful response after startup

  • Error: Force indirect listing is enabled, but no host override is set. This is not supported!

    In the server console, in red, at each heartbeat, when sv_forceIndirectListing is true and sv_listingHostOverride is empty

  • no license key was specified

    Quoted by the vanilla setup page among its common issues

What it actually means

Listing works in two directions. In GameServer.cpp, FXServer posts a heartbeat to https://servers-frontend.fivem.net/api/serverlist/ingress, the default of sv_master1, at startup and every 3 minutes. A player connecting or dropping brings the next one forward to at most 15 seconds away, and the heartbeat command forces one. The body carries the port, a listing token, an optional IP override and a private flag.

The other direction is the listing service requesting your server: the proxy-setup page calls it the server list backend and says it can't guess the IP to query itself on some setups. When its answer to a heartbeat contains a lastError field, the server prints the first line in red as Server list query returned an error: <reason>. Neither the source nor the documentation says what produces it or lists the reasons. Our reading is a failed request to your server; take the text after the colon as a clue, not a diagnosis.

Check this first (two minutes)

Six checks, cheapest first. Each ends on the cause it points to.

  1. How long ago did the server start?

    The documentation says it can take up to 8 minutes.

  2. Can someone outside your network reach the server?

    Ask a player on another network to run the command below in the F8 console with your public IP and port. From a phone on mobile data, open http://IP:Port/info.json: it should return a JSON object. A test from your own network does not show what outside players see.

    connect IP:Port
  3. Run heartbeat twice in the server console

    Run it again after a few seconds: the first successful answer after startup is never reported, and a heartbeat that fails to send prints no red line.

    heartbeat
    • Red Error: Force indirect listing is enabled, but no host override is set. This is not supported!: Read cause 5: the proxy listing overrides

    • Red Server list query returned an error: <reason>: Keep the text after the colon for your forum post, then continue with step 4: step 2 already tested the port.

    • No red line appears: Continue with step 4.

  4. Read five settings in server.cfg

    Check server.cfg and every file it loads with exec for sv_master1, sv_lan, sets sv_projectName, sets sv_projectDesc and sv_licenseKey.

  5. Proxy in front, or outbound HTTPS blocked?

    Any reverse proxy or tunnel counts, as does a sv_forceIndirectListing or sv_listingHostOverride line. Test outbound HTTPS from the server machine to servers-frontend.fivem.net (commands in cause 7).

  6. Everything passes and the server is still missing

    Compare when it disappeared with what your host recorded.

Causes, ranked

The first three follow the server-issues page: port, sv_master1, project settings. The others run roughly from the cheapest check to the hardest. The order rests on the documentation and on cost, not on owner reports: no cause below is badged “Owners report”. Cause 9 is the attack case.

Ranked by what owners report most and how cheap each check is. That is an editorial order, not a statistic: nobody publishes a dataset of FiveM outage causes. Documented means official docs or the FXServer and txAdmin source. Owners report means forum threads and issue trackers. Our inference is our reasoning from documented facts, shown so you can check it.

  1. The game port (default 30120) is blocked or not forwarded

    Documented

    The server-issues page puts this first: a missing listing “is usually caused by bad port forwarding or firewall configuration problems”. Any layer can block it: OS firewall, router, host panel or a game firewall. OVH’s Game firewall guide recommends “Default Deny”, which blocks all traffic without a rule you created.

    How to confirm

    From another network, open http://IP:Port/info.json and try Direct Connect (step 2) with the public IP; 127.0.0.1 only proves the server answers locally. endpoint_add_tcp and endpoint_add_udp must share one ip:port, or txAdmin will not start the server. If the port worked until a moment you can name and nothing changed on your side, compare that moment with your host’s record (cause 9).

    What to do

    Open the port for TCP and UDP at every layer, then repeat the outside test.
  2. sv_master1 "" is active, or sv_lan is true

    Documented

    The documentation says sv_master1 sets a server as “private”, which disables its connect button, and “cannot be used to de-list a server”. In GameServer.cpp the heartbeat’s private flag stays true unless sv_master1, sv_master2 or sv_master3 holds the default ingress address, so an active blank value marks the server private. sv_lan true is separate: the server “will not appear in the public server list”.

    How to confirm

    Search server.cfg and every file it loads with exec. Safe forms: #sv_master1 "" or no line, and no sv_lan true. With your cfx.re/join/ code, CFX Finder shows “Listed as private” when cfx.re marks the listing private.

    What to do

    Comment out or delete the sv_master1 line (the documentation says you need not add it back), remove sv_lan or set it to false, and restart.
  3. sets sv_projectName or sets sv_projectDesc is missing

    Documented

    If either variable is missing, “the server will display an error upon startup and may not appear on the list”. The name should be a name, not a list or tags: a non-compliant one “will be cut off in the server list”. sv_hostname is not a substitute; the example config calls it “not usually shown anywhere in listings”.

    How to confirm

    Search server.cfg for both lines, written with sets as in the documentation, and read the first console lines after a restart for the startup error.

    What to do

    Add sets sv_projectName "Your Project" and sets sv_projectDesc "One sentence about it.", then restart.
  4. sv_licenseKey is missing or invalid, or server.cfg never ran

    Our inference

    The setup guide requires sv_licenseKey (keys come from portal.cfx.re; the example file ships changeme) and says no license key was specified may mean FXServer ran outside the folder holding server.cfg, or without +exec server.cfg. In GameServer.cpp the heartbeat block runs only when an internal sv_licenseKeyToken is non-empty; the sources listed below do not say how it is produced, so tying a bad key to a missing listing is our reading.

    How to confirm

    Look for no license key was specified at startup, and confirm the launch runs from the folder holding server.cfg with +exec server.cfg.

    What to do

    Set your own key from portal.cfx.re and restart. Never post it.
  5. Behind a proxy: the listing overrides are missing, or the override host does not answer

    Documented

    sv_forceIndirectListing true keeps the server from being advertised with its real IP and, in GameServer.cpp, goes with sv_listingHostOverride: without it the console prints the red error shown at the top of this page and the heartbeat is sent without the override fields. With an override, the proxy-setup page says the listing backend requests that host instead of the default, and a comment in GameServer.cpp warns that forced indirect listing “will break listings if the proxy host can not be reached”. The same page says sv_listingIpOverride is needed when the backend cannot guess the IP to query, as with a server firewalled off for every host except its proxy.

    How to confirm

    Open /info.json, /players.json, /dynamic.json and /client on your override host: a working setup serves the first three and /client shows /client is POST only.

    What to do

    Set sv_listingHostOverride to the hostname the proxy serves and make it forward to the server, with sv_proxyIPRanges and sv_endpoints as the proxy-setup page shows. Add sv_listingIpOverride only if the backend cannot guess the IP to query.
  6. The server only just started

    Documented

    The documentation says up to 8 minutes after launch “if no other heartbeats are sent”. The source sends one every 3 minutes and brings the next forward when a player connects or drops.

    How to confirm

    Note the start time, run heartbeat once and search again after a few minutes.

    What to do

    Wait the full 8 minutes. A restart is a new launch and resets the wait.
  7. Outbound HTTPS from the server machine is blocked

    Our inference

    The heartbeat is an outbound HTTPS POST to servers-frontend.fivem.net with the ipv4 option set, so a blocked outbound route, a DNS failure or a missing IPv4 route stops it. A POST that the HTTP client reports as failed goes only to a separate debug print (error submitting to ingress), so the red line cannot appear. No document describes outbound requirements: this is our reading of the source.

    How to confirm

    On Windows, run Test-NetConnection -ComputerName servers-frontend.fivem.net -Port 443 and look for TcpTestSucceeded : True. On Linux, curl -4 -I https://servers-frontend.fivem.net/ should print an HTTP status line; any status, even an error one, shows the connection works.

    What to do

    Allow outbound TCP 443 and check DNS from the machine; ask your host whether it filters outbound traffic.
  8. Other causes the documentation names: a NAT that masks UDP source ports, or the listing service itself

    Documented

    The server-issues page says a server “behind a NAT or gateway that masks UDP source ports” may not show up, and that “There may be an issue with the server listing service itself. Be patient”. It does not say which listing step depends on the source port, and names no status page.

    How to confirm

    Suspect them only when the outside tests pass, the config is right, no proxy is involved and more than 8 minutes have passed. A red Server list query returned an error: <reason> that keeps coming back fits here too: keep its text.

    What to do

    Check your router or firewall documentation for how it rewrites UDP source ports (the page points to pfSense’s guide), otherwise wait and ask on the forum or Discord, with the details under “what to post”.
  9. The address is flooded or cut off, so the service cannot query the server

    Our inferenceThe DDoS case

    The listing needs a request that reaches your server (cause 1). If the address is saturated, filtered or cut off upstream, that request fails along with every player’s connection. The documentation lists no attack among the causes. This ranks last because it needs outside evidence and the causes above are cheaper to check.

    How to confirm

    Compare when the server left the list with your host’s dashboard or notice and your inbound traffic graph; Direct Connect should fail for everyone in the same window.

    What to do

    Ask your host what it recorded and export it promptly. Do not restart repeatedly or publish a new IP.

What a DDoS looks like here

An attack explains a server that was listed and became unreachable, not one that never appeared or is marked private. Symptoms on the machine cannot prove it: you need evidence from outside.

What a DDoS looks like here

  • The server was listed with players connected, and disappeared at a time you can name.
  • In that window your host’s dashboard or notice reports an attack, or your inbound traffic graph shows a spike.
  • Direct Connect and info.json fail for everyone, from several networks, while the server process runs normally.

Evidence you can collect

  • Your host’s record of the event

    OVH’s Network Security Dashboard (Network > Network Security Dashboard) lists the attacks its scrubbing centre detected, with “Detection time”, “End time”, “Destination IP” and “Attack vectors”, kept for one year. An empty log is not conclusive: OVH says attacks that start inside its own network are not reported there. Source addresses are not shown because they are usually spoofed, so there is nothing to ban. The traffic chart is kept for less time: export it. Other hosts differ: ask yours for the same record.

  • Inbound traffic on the machine, against a quiet-day baseline

    Capture a baseline on a quiet day, then compare packets and data volume received per interface (rxpck/s, rxkB/s). On Windows, read \Network Interface(*)\Packets Received/sec with Get-Counter; counter names are localized on non-English Windows, and Get-Counter -ListSet * lists them. A flood dropped upstream will not show here: your host’s record is the stronger witness.

    sar -n DEV 1 10

What it does not look like

  • A server that never appeared, or shows as private: those are the settings in causes 2 to 5.
  • The red Server list query returned an error: <reason> line alone: it reports a failed query, and the documentation does not list the reasons.
  • A green txAdmin. With endpoint_add_tcp "0.0.0.0:30120" its health check requests /dynamic.json on 127.0.0.1, so it can show the server online while nobody outside reaches it.

When protection is, and is not, the answer

Protection is the answer when

  • The server was listed and busy, it left the list when your host or inbound graph reports an attack, and Direct Connect fails for everyone: then the DDoS guides apply.
  • You are putting a reverse proxy in front of the server and want the list to show its hostname, not your IP. Cause 5 is your checklist.

Protection is not the answer when

  • The server never appeared or shows as private: that is sv_master1, sv_lan, the project settings or the license key.
  • A port is closed, a rule is missing or outbound HTTPS is blocked: a proxy repairs none of them.
  • Wrong or missing listing overrides: a proxy adds this cause, it does not remove it.

How a FiveM anti-DDoS proxy works, and when it applies

Still stuck? What to post

Post these together, and leave out your license key, rcon_password and any token.

  • Your FXServer build number and your game (FiveM or RedM).
  • Whether http://IP:Port/info.json loads from a phone on mobile data and whether Direct Connect works from another network, with the exact error.
  • The red console lines after running heartbeat twice, as text.
  • The five server.cfg settings, with the key replaced by xxxx.
  • With a proxy: your listing overrides and what the override host returns for its four URLs.
  • When the server last appeared, how long it has been up, and any host event at that time.

Frequently asked questions

How long does it take for a FiveM server to appear in the list?

The documentation says up to 8 minutes after launch if no other heartbeats are sent. The server sends one every 3 minutes and heartbeat forces one. If it is still missing well after that, work through the causes instead of restarting.

Why does my server say private?

The documentation names sv_master1 as the variable that marks a server private and disables its connect button. An active sv_master1 "" in server.cfg does it: put # in front of the line, or delete it, and restart.

Does Server list query returned an error mean I am being attacked?

Not by itself. The line prints the lastError text the listing service returns to your heartbeat, and the documentation does not list the reasons. Test from another network first; an attack needs evidence from your host’s dashboard or notice.

Does setting sv_maxclients above 48 hide my server?

The documentation does not say so. Its server-issues page lists “My Server Can Only Use 48 Slots” as a related issue: more than 48 slots needs an Element Club Argentum subscription or higher. It describes a slot cap, not a missing listing.

Can a reverse proxy make my server disappear from the list?

It can. A comment in GameServer.cpp says forced indirect listing “will break listings if the proxy host can not be reached”, and the proxy-setup page says sv_listingIpOverride is needed when the listing backend cannot guess the IP to query. Cause 5 has the checks.

Verified against, and sources

Verified against FXServer build 35245 (recommended), 37150 (latest) and txAdmin v8.1.1, checked on 7 October 2026.

Sources from companies that compete with FiveShield are named, with their domain, but not linked.

Server behaviour changes between builds. If your build prints something different, the build numbers above tell you what this page was checked against.