Skip to main content

IP Blocker in cPanel: Blocking IP Addresses

Hosting & cPanel · 29.09.2026

What IP Blocker Does in cPanel

IP Blocker is a cPanel tool that denies selected addresses or subnets access to a site at the web server level. The rule fires before a WordPress or Laravel script can process the request: the server drops the connection before any data reaches PHP. That sets IP Blocker apart from security plugins, which filter traffic only inside the application.

The module helps when the same address keeps showing up in the error log, when a bot is brute-forcing a login form, or when a competitor is scanning the site for vulnerabilities. For a one-off block of a few IPs, the built-in interface is enough, no separate firewall required.

How to Open IP Blocker and Add an Address

In cPanel, go to the "Security" section and open "IP Blocker". In the "Add an IP Address or Range" field, enter the address in one of the formats below and click "Add". The rule applies immediately, with no web server restart.

  • Single address: 203.0.113.45
  • Range with a hyphen: 203.0.113.1-203.0.113.50
  • Subnet mask: 203.0.113.0/24
  • Short dotted form: 203.0.113. — blocks the whole /24 subnet

The list of active rules is visible in the same window. To remove a block, click "Delete" next to the entry — the change also applies instantly.

Address and Range Formats: an Example Table

FormatExampleWhat It Blocks
Single IPv4198.51.100.7One specific address
Range198.51.100.1-198.51.100.2020 consecutive addresses
CIDR198.51.100.0/24256 subnet addresses
Shorthand mask198.51.100.The entire class C subnet
IPv62001:db8::/32An IPv6 address block

CIDR notation is more compact than a range: a /24 mask covers the same 256 addresses as an explicit list from .0 to .255, but takes one rule line instead of a long enumeration.

How to Find the Address You Need to Block

Before banning an IP, make sure it is not your office address or a mail service address. The source is the Error Log and the "Raw Access" tab under "Metrics": it shows the IP, request time, response code, and path. Frequent requests to wp-login.php, xmlrpc.php, or nonexistent admin panels with a 401/403 code are a reliable sign of password brute-forcing.

If the same address makes dozens of requests per minute and the account's Resource Usage limits are being hit, blocking through IP Blocker relieves the load faster than optimizing the code.

IP Blocker Limitations and Alternatives

IP Blocker works well against bots with a static address but is powerless against a botnet with thousands of different IPs or an attack through a CDN, where the real address is hidden. In those cases, rules in .htaccess that check the User-Agent, a captcha on the login form, or a DDoS protection service in front of the server work better.

One more nuance: IP Blocker rules are stored in the account root's .htaccess file as deny from directives. If the site uses its own .htaccess with an explicit order allow,deny, check that the IP Blocker block does not end up below a general allow from all — otherwise the rule will not fire.

Summary: When to Turn on IP-Based Blocking

  • The same address is systematically attacking a login form or an API — block it right away.
  • Before blocking, check the address in the Error Log and Raw Access so you do not ban a payment gateway or a search bot.
  • For a subnet, use CIDR /24 instead of listing hundreds of separate IPs.
  • IP Blocker will not help against distributed attacks — you need .htaccess rules or external protection.
  • Review the list of active blocks once a month and remove outdated entries.
← Back to Knowledge Base Ask Support