Do you want to block specific IP addresses from accessing your WordPress site?
Blocking IP addresses is used as a solution to block spam and hacking attacks on your website.
In this article, we will show you how to block IP addresses in WordPress, and we will also show you how to find out which IP addresses need to be blocked.
What Is an IP Address?
Each computer connected to the internet has an IP address assigned to them by their internet service provider.
If the internet was a physical world, then think of IP addresses as country, street, and house numbers. They are 4 sets of numbers from 0-255 separated by dots and look like this:
172.16.254.1
All visitors to your WordPress website have an IP address that is stored in your website’s access log files. This means that all websites that you visit also store your IP address.
If you want to hide your real IP address and other personal information when using the internet, then you can use a VPN service.
Why & When Do You Need to Block IP Addresses?
Blocking an IP address from accessing your website is an effective way to deal with unwanted visitors, comment spam, email spam, hacking attempts, and DDoS (denial of service) attacks.
The most common sign that your website is under a DDoS attack is that your website will frequently become inaccessible or your pages will take forever to load.
The other attacks are more obvious such as when you start getting spam comments or a lot of spam emails from your contact form. We have a list of ways to fight spam comments, but the last solution is to block IP addresses.
Finding Out IP Addresses You Want to Block in WordPress
WordPress stores IP addresses for users that leave a comment on your website. You can see their IP address by visiting the Comments page in your WordPress admin area.
If your website is under a DDoS attack, then the best way to locate the IP addresses is by checking your server’s access log.
To see those logs, you will need to log in to the cPanel dashboard of your WordPress hosting account. Next, locate the ‘Logs’ section and click on the ‘Raw Access Logs’ icon.
This will take you to the access logs page.
You will need to click on your domain name to download the access logs file.
Your access log file will be inside a .gz archive file. Go ahead and extract the file by clicking on it.
If your computer does not have a program to handle .gz archive files, then you will need to install one. Winzip and 7-zip are two popular choices among Windows users.
Inside the archive, you will see your access log file, which you can open in a plain text editor like Notepad or TextEdit.
The access log file contains raw data of all requests made to your website. Each line begins with the IP address making that request.
You need to make sure that you don’t end up blocking yourself, legit users, or search engines from accessing your website. Copy a suspicious-looking IP address and use online IP lookup tools to find out more about it.
You will have to carefully look at your access logs for an unusually high number of requests from a particular IP address. We share a way to automate this at the bottom of this article.
Once you have located those IP addresses, you need to copy and paste them into a separate text file.
Blocking IP Addresses in WordPress
If you just want to stop users with a specific IP address from leaving a comment on your site, then you can do that inside your WordPress admin area.
Head over to Settings » Discussion page and scroll down to the ‘Comment Blacklist’ text box.
You need to copy and paste the IP addresses that you want to block and then click on the ‘Save Changes’ button.
WordPress will now block users with these IP addresses from leaving a comment on your website. These users will still be able to visit your website, but they will see an error message when they try to submit a comment.
Blocking an IP Address Using cPanel
This method completely blocks an IP address from accessing or viewing your website. You should use this method when you want to protect your WordPress site from hacking attempts and DDoS attacks.
First, you need to log in to the cPanel dashboard of your hosting account. Now scroll down to the Security section and click on the ‘IP Blocker’ icon.
This will take you to the IP Blocker tool.
Here, you can add the IP addresses you want to block. You can add a single IP address or an IP range and then click the ‘Add’ button.
You can come back to the same page again if you ever need to unblock those IP addresses.
When IP Address Blocking Doesn’t Work – Automate It!
Blocking an IP address will work if you are just blocking some basic hacking attempts, specific users, or users from specific regions or countries.
However, many hacking attempts and attacks are made using a wide range of random IP addresses from all over the world. It is impossible for you to keep up with all those random IP addresses.
That’s when you need a Web Application Firewall (WAF) such as Sucuri our Cloudflare. These website security services protect your website against such attacks using a website application firewall.
Basically, all your website traffic goes through their servers, where it is examined for suspicious activity. It automatically blocks suspicious IP addresses from reaching your website altogether. See how Sucuri helped us block 450,000 WordPress attacks in 3 months.
We hope this article helped you learn how to easily block IP addresses in WordPress.
If you liked this article, then please subscribe to our YouTube Channel for WordPress video tutorials. You can also find us on Twitter and Facebook.