FiveM server under DDoS attack: what to do right now

Everyone timing out? Do these in order.

  1. Do not restart or post a new IP

    A restart does not stop traffic coming from outside, and an address posted in your Discord can reach the attacker.

  2. Confirm it is traffic, not a script

    Inbound spike on your host’s graph, CPU low, FXServer still running? That points at the network. Three checks

  3. Ask your host: scrubbed or null-routed?

    Open a ticket now with the start time, IP, port and a screenshot of the graph. Message to copy

A proxy in front of your server takes about five minutes: one block in server.cfg. If the attacker already has your real IP you also need a new one, told to no one. The order that works

$10 CAD free on your first server · No card needed · Cancel anytime

Updated

Is it really a DDoS? Three checks

No single symptom proves it: a stalled script, a firewall rule and a flood can all end with every player timing out. These three checks use evidence from outside the game.

1. Did traffic into the machine rise?

This is the check that matters, and it comes from your host or the machine, not from FiveM. Your host panel’s inbound graph is the quickest: compare it with a quiet day. A join wave after a restart tends to show up as outbound traffic (downloads), a flood as inbound.

On the machine, ten seconds of counters is enough. Look at received packets and kilobytes per second on the public interface.

Linux (sysstat)

sar -n DEV 1 10

Windows (PowerShell)

Get-Counter -Counter '\Network Interface(*)\Packets Received/sec' -Continuous

2. Is the process stalling, or still answering?

Read the FXServer console. server thread hitch warning lines mean a thread ran late. The usual reports are scripts, large net events and a weak CPU; on their own they are not evidence of an attack.

A txAdmin that says "online" proves less than it seems. Its health check is a request the machine makes to its own FXServer (as of txAdmin 8.1.1), so it can stay green while nobody outside can connect.

3. Is it everyone, or a few players?

Everyone at once, with a quiet console, points outside the machine. A few players on the same ISP point at their own route. Ask two or three affected players for the "Timeout info" line in the error dialog: comparing its game, recv and send values helps tell a stalled game from packets that stopped arriving.

Attack or look-alike? Match what you see

These are the situations most often confused with an attack. Each guide says what would change its verdict.

  • Console: "server thread hitch warning"

    A thread ran late: scripts, net events or CPU first.

  • Players: "Failed to get info from server (tried 3 times)"

    The UDP reply never came back. UDP forwarding and firewalls come before a flood.

  • Many players at once: "Client -> server connection timed out"

    A stall long enough to time everyone out, on the server or on the path.

  • Your host emails that traffic was rerouted through its anti-DDoS infrastructure

    An attack your host has detected.

  • A threat, or your server’s IP showing up somewhere public

    Not an attack yet. The question is whether your real IP is published.

Scrubbed or null-routed? Ask your host

Hosts typically deal with a large attack in one of two ways, and which one you got changes what happens next. Scrubbing reroutes the traffic through filtering equipment, and the clean part still reaches you. A null route drops all traffic to the IP: TransIP’s documentation says a nullrouted address is not reachable from the outside. Providers differ. Your host’s support can tell you which one you are in.

On OVHcloud, the Network Security Dashboard (Network, then Network Security Dashboard, in the control panel) lists detected attacks in its scrubbing centre log: detection time, end time, destination IP and attack vectors. Source addresses are not shown because they are usually spoofed, so banning them from your panel achieves nothing.

The message to send

Message for your host’s support

Hello,

Since [start time and timezone], the game server on [IP], UDP and TCP port [port], has been unreachable for most players. The machine is up and the process is running, but players time out.

Could you tell me:
1. Is this IP currently being scrubbed (traffic rerouted through your anti-DDoS infrastructure) or null-routed?
2. What attack type and volume do you see, and since when?
3. Is there anything I should change on my side, and how will I know when traffic is back to normal?

I have attached a screenshot of the inbound traffic graph. Please keep the logs for this IP: I may need them.

Thank you.

Replace the three [brackets], paste it into the ticket and attach the graph.

Save this before anything restarts

  • A screenshot of your host’s inbound and outbound traffic graphs, with the time range visible.
  • Any email or notice from your host, with its timestamp.
  • The FXServer console and the txAdmin log around the start time.
  • The "Timeout info" line from two or three affected players.
  • The start time, in your timezone and in UTC.

What a proxy can and cannot do mid-attack

What it can do

  • Filter traffic before it reaches your server: players connect to the proxy, and your machine only sees what the proxy forwards.
  • Replace the address you publish. The server listing shows a FiveShield hostname instead of the machine’s IP.
  • Be set up in about five minutes, without moving the server or changing DNS.

What it cannot do

  • End an attack aimed at an address the attacker already has, while that address still accepts traffic. That is why the next section has a step for the IP.
  • Fix a stalled script, a looping net event or a weak CPU. If the checks above found no traffic spike, a proxy is not your fix.
  • Guarantee protection against every attack type. Our Refund Policy says that no service can.

A proxy in front, mid-attack: the order that works

Nothing has to be migrated, which is why this is possible mid-attack. The order is what makes it work.

  1. Set up the proxy. Create your server in the dashboard, paste the block it gives you at the very top of server.cfg, and restart. This is the one restart worth doing.
  2. Replace the IP if the attacker has it. A proxy cannot protect an address attackers already know, so ask your host for a new IP for the machine. On OVHcloud, the Edge Network Firewall described in the install guide can make a new IP unnecessary once its rules are correct, but an Allow rule with an empty source IP cancels the whole firewall, so read the guide’s warning. If the attack continues against the old address, ask your host for a new IP.
  3. Update the address in Settings. Enter the new IP in your server’s Settings in the dashboard, and tell nobody else: not your Discord, not a screenshot, not a ticket other people can read.
  4. Close the origin. Only the proxy and your own IP should be able to reach the machine; the OVH Edge Firewall section of the install guide has the rules.
  5. Check what you publish. Run the CFX Finder on your join code: it should show a FiveShield hostname, not an IP and port.

What to tell your players

Say what you know, and keep every address out of it.

Message to post
The server is having connection problems and we are working on it with our host. Please do not post or ask for server addresses, here or in DMs. We will announce here when it is back.

Do not name anyone: your host has to confirm an attack first, and even then the source addresses are usually spoofed.

After it stops: close the leaks

The attacker found the address somewhere. Until you know where, the next attack lands in the same place.

  • Run the CFX Finder on your join code. A raw IP and port in the listing means the address is public.
  • Check your domain’s DNS records, old ones included. Any that point at the machine running FXServer give the address away, and so does a website on that machine.
  • Look for hard-coded addresses in your resources, and for the endpoint in Discord webhooks and log channels.
  • Put txAdmin behind the same protection, or restrict its port (40120 by default) to your own IPs.
  • Lock the origin so only the proxy and your own IP can reach it.

Already protected and still being hit?

Test whether the origin still answers. From another network, a request to your origin IP on the game port should get nothing back. If it does answer, the proxy is being bypassed and the leaks above are where to look. If it does not, tell us on Discord when it started.

Frequently asked questions

Should I restart my FiveM server during a DDoS attack?

Not as a fix. A restart does nothing about traffic that arrives from outside, and it disconnects everyone still online. Restart when a step tells you to, such as after pasting a proxy block, or once your host says the traffic is gone.

Can I stop a DDoS attack myself?

Not a flood that fills the link in front of your machine. OVHcloud’s FAQ notes that most of these cannot be filtered on your own for that reason, so the filtering has to happen upstream, at your host or at a proxy. What you control is the evidence you collect and what you publish.

How long will the attack last?

Nobody can tell from outside, and we have no figure we could stand behind. Your host sees more than you do: OVHcloud’s dashboard, for one, lists a detection time and an end time for each event. Ask your host what it sees.

Will changing my server’s IP stop it?

It helps only if the attacker has the old address and the new one stays private. A new IP that is published the way the old one was becomes the next target. Do it after a proxy is in place, and tell nobody the new address.

Does FiveShield stop an attack that is already happening?

Once your server is behind it, the proxy filters traffic before it reaches the machine, and your listing shows the proxy’s hostname. It cannot end an attack aimed at an address the attacker already has while that address still answers, and no service can guarantee protection against every attack type. That is why the steps above include the IP.

I am already protected and still down. Why?

Check whether the origin still answers directly: from another network, a request to your origin IP on the game port should get nothing back. If it answers, look for the leak: DNS records, a website on the same machine, a hard-coded address, an exposed txAdmin. If it does not answer, tell us on Discord when it started and what you see.

Can I find out who is attacking me?

Usually not from network data: OVHcloud’s guide says source addresses of detected events are not shown because they are usually spoofed. Keep the timeline, your host’s notices and your logs.

How fast can I be protected?

Setup takes about five minutes: sign in with Discord, add your server, paste one block at the top of server.cfg and restart. If the attacker already has your IP, add the time your host needs to give you a new one. How long the attack takes to stop afterwards is not something anyone can promise.

Can I try FiveShield before paying?

Your first server gets $10 CAD of free trial credit on eligible accounts, no credit card required: about four days of protection for up to 50 players. If the account is not eligible, the dashboard offers a $10 CAD deposit instead, which goes entirely to your server balance.

Can I get help during an attack?

Our Discord answers 24/7. Give the server name and when the problem started.

Not under attack today? Close the gap before the next one

Setup takes about five minutes and the server stays with your current host. From $2.25 CAD/day for up to 50 players, billed on the daily peak, no subscription.

$10 CAD free on your first server · No card needed · Cancel anytime

Related reading

Sources

Checked on 7 October 2026. Hosting providers change their documentation; if yours differs, trust yours.

Sources from companies that compete with FiveShield are named, with their domain, but not linked.