Blocking an IP address means denying a specific address or address range access to your website, email, or server. This is useful in cases of hacking attempts, spam, scraping, or excessive traffic from a single source. You can manage this via Plesk, an .htaccess file, or your server’s firewall. In this article, you’ll learn step by step how to block an IP address and what to watch out for.
Why would you block an IP address
There are several situations in which blocking an IP address makes sense. Think of repeated login attempts on your admin panel, a bot draining your website with requests, spam through your contact form, or a single visitor generating so much traffic that your hosting slows down. By blocking the relevant IP address, you prevent further load and risks without affecting other visitors.
It’s important to first check whether the suspicious traffic really comes from one fixed IP address. In larger attacks, addresses often change, making individual blocks less effective. In that case, a broader security measure, such as a firewall rule per range or a security module, is more effective than blocking individual IPs.
Blocking an IP address via Plesk
With web hosting using Plesk, you can block IP addresses without needing command line knowledge. Plesk usually has an IP Access Management or firewall module for this, depending on your hosting package’s configuration.
Log in to Plesk
Go to your Plesk panel and log in with your admin account.
Open IP Access Management
Navigate to your domain or website settings and look for the IP access management option.
Add the IP address
Enter the IP address to block and choose ‘deny’ instead of ‘allow’.
Save the change
Confirm the change so the block becomes active immediately for that domain.
Blocking an IP address via .htaccess
If you don’t have access to Plesk but do have access to your website’s files, you can also block an IP address via the .htaccess file in your website’s root directory. This works on servers running Apache or on LiteSpeed servers that support .htaccess.
Add the following rules to your .htaccess file to deny a specific IP address:
order allow,deny
deny from 123.123.123.123
allow from all
If you want to block an entire range, for example a whole subnet, you can omit part of the IP address, such as deny from 123.123.123. Make sure to test the change after saving, so you know for certain the rest of the website remains accessible to other visitors.
Note that an incorrectly placed rule can make your website completely inaccessible. Therefore, always make a copy of the file first before making changes.
Blocking at server and firewall level
For structural protection, for example against repeated login attempts on your email accounts or admin panel, blocking at the server level via a firewall is more effective than individual rules per website. A firewall can automatically and temporarily block suspicious addresses based on behavior, such as too many failed login attempts within a short time.
This kind of protection is usually centrally managed by the hosting provider and is not always something you can configure yourself. With a well-secured hosting package, this protection runs by default, alongside things like free SSL and daily backups. If you’re unsure whether your hosting offers this level of protection, check out the options for web hosting with built-in security, or check the knowledge base for more background information on security.
This is also relevant for email: unwanted IP addresses attempting to log in to mailboxes can be blocked via the same firewall, contributing to a reliable business email environment.
Frequently Asked Questions
How do I find the IP address I want to block?
You can usually find suspicious IP addresses in your website’s log files or in your hosting panel’s login attempts log. Repeated failed attempts from the same address are often a signal.
Can I block an entire country?
Yes, this is possible with geo-blocking, which blocks ranges of IP addresses associated with a country. This usually requires a separate module or firewall rule and is less precise than blocking individual addresses.
Is an IP block permanent?
That depends on how you set up the block. Via .htaccess or Plesk, a block is permanent until you remove it yourself. Firewalls often use temporary blocks that automatically lift after a certain time.
What if I accidentally block myself?
Remove the rule from the .htaccess file via FTP or the file manager in your panel, or adjust the setting in Plesk. Make sure you always retain access to your files outside the blocked connection.
Conclusion
Blocking an IP address is a direct way to prevent abuse, spam, or excessive load on your website. You can quickly arrange this yourself via Plesk or .htaccess, while structural protection against attacks is best handled at the server and firewall level. If you’re unsure about the security of your current hosting, switching to Tandata is an option to set this up properly right away.