What IP Blocker Does in cPanel
IP Blocker is a cPanel tool that denies selected addresses or subnets access to a site at the web server level. The rule fires before a WordPress or Laravel script can process the request: the server drops the connection before any data reaches PHP. That sets IP Blocker apart from security plugins, which filter traffic only inside the application.
The module helps when the same address keeps showing up in the error log, when a bot is brute-forcing a login form, or when a competitor is scanning the site for vulnerabilities. For a one-off block of a few IPs, the built-in interface is enough, no separate firewall required.
How to Open IP Blocker and Add an Address
In cPanel, go to the "Security" section and open "IP Blocker". In the "Add an IP Address or Range" field, enter the address in one of the formats below and click "Add". The rule applies immediately, with no web server restart.
- Single address: 203.0.113.45
- Range with a hyphen: 203.0.113.1-203.0.113.50
- Subnet mask: 203.0.113.0/24
- Short dotted form: 203.0.113. — blocks the whole /24 subnet
The list of active rules is visible in the same window. To remove a block, click "Delete" next to the entry — the change also applies instantly.
Address and Range Formats: an Example Table
| Format | Example | What It Blocks |
|---|---|---|
| Single IPv4 | 198.51.100.7 | One specific address |
| Range | 198.51.100.1-198.51.100.20 | 20 consecutive addresses |
| CIDR | 198.51.100.0/24 | 256 subnet addresses |
| Shorthand mask | 198.51.100. | The entire class C subnet |
| IPv6 | 2001:db8::/32 | An IPv6 address block |
CIDR notation is more compact than a range: a /24 mask covers the same 256 addresses as an explicit list from .0 to .255, but takes one rule line instead of a long enumeration.
How to Find the Address You Need to Block
Before banning an IP, make sure it is not your office address or a mail service address. The source is the Error Log and the "Raw Access" tab under "Metrics": it shows the IP, request time, response code, and path. Frequent requests to wp-login.php, xmlrpc.php, or nonexistent admin panels with a 401/403 code are a reliable sign of password brute-forcing.
If the same address makes dozens of requests per minute and the account's Resource Usage limits are being hit, blocking through IP Blocker relieves the load faster than optimizing the code.
IP Blocker Limitations and Alternatives
IP Blocker works well against bots with a static address but is powerless against a botnet with thousands of different IPs or an attack through a CDN, where the real address is hidden. In those cases, rules in .htaccess that check the User-Agent, a captcha on the login form, or a DDoS protection service in front of the server work better.
One more nuance: IP Blocker rules are stored in the account root's .htaccess file as deny from directives. If the site uses its own .htaccess with an explicit order allow,deny, check that the IP Blocker block does not end up below a general allow from all — otherwise the rule will not fire.
Summary: When to Turn on IP-Based Blocking
- The same address is systematically attacking a login form or an API — block it right away.
- Before blocking, check the address in the Error Log and Raw Access so you do not ban a payment gateway or a search bot.
- For a subnet, use CIDR /24 instead of listing hundreds of separate IPs.
- IP Blocker will not help against distributed attacks — you need .htaccess rules or external protection.
- Review the list of active blocks once a month and remove outdated entries.