Block users from your website generator
Use htaccess to block certain IP addresses or domains from accessing your site - a full or partial IP address, or a domain name, then generate the code below to add to your .htaccess file. Note: this can lock out legitimate visitors too, so block the narrowest range that solves your problem.About blocking users with .htaccess
You can use a full IP address to block one specific visitor, or a partial IP to block a whole range - entering 203.156.187 blocks every address from 203.156.187.0 through 203.156.187.255, useful since visitors on a proxy or mobile network often get a different exact IP each time they connect. You can also block by domain name (e.g. bigpond.com), matched by reverse DNS.
Once you've generated the code: paste it into a plain text editor and save it as htaccess.txt, upload it in ASCII format to your website's root folder (or the specific folder you want to restrict), then rename it to .htaccess - remember the leading dot. Many FTP programs hide dot-files by default, so it may disappear from view even though it's still there. If you already have a .htaccess file, add these lines to the existing one instead of replacing it, and make sure there's a blank line after the last line of code.
Frequently asked questions
Can I block more than one IP or domain?
Yes - enter as many as you need, one per line, in the box above. There's no fixed limit.
Will this block visitors from a whole country or ISP?
You can block a range by entering a partial IP - e.g. 203.156.187 blocks every address from 203.156.187.0 to 203.156.187.255. For a domain-based ISP like bigpond.com, enter the domain name directly and it's matched by reverse DNS.
Could this accidentally block legitimate visitors?
Yes - people on shared or rotating IPs (mobile networks, VPNs, some ISPs, proxy users) can end up with an IP that was previously used by someone you meant to block, or lose access if you block too broad a range. Block the narrowest range that solves your problem.
Will this code work on my host?
Yes, if your host runs Apache (the vast majority of shared hosting does). This generator uses the modern <RequireAll> syntax that's been standard since Apache 2.4 - released in 2012 and universal on current hosting. The older Apache 2.2 module set reached end of life in 2017, so there's no practical need to support it any more.
