Zyre Logo
Zyre

False positives

When a legitimate visit is blocked: how to spot it, report it, and what happens next.

4 minUpdated

A false positive is a legitimate request the firewall took for an attack. The typical case: a contact form whose message contains an apostrophe and a semicolon in the wrong place.

Spotting it

  • The triggered-rules table (Tools → Diagnostic) shows which rule acts on your traffic. A rule firing on your own pages is suspicious.
  • Your visitor calls you. The block page shows an incident reference: ask for it — it leads straight to the matching row in the threat centre.

Reporting it

  1. 1

    Open the row

    In Threats, open the detail of the request.

  2. 2

    Report

    The report carries the request, the rule triggered and the path targeted. Add a note if the context is not obvious.

  3. 3

    We review it

    A Zyre administrator reviews it with the request in front of them and can disable that exact rule, on that exact path. You get an email when it is done.

Why you cannot disable a rule yourself

This is deliberate. A "disable this rule" button on a statistics screen eventually gets clicked on the wrong rule, with no reason recorded and no confirmation, and nobody remembers three months later. Lowering protection goes through us; raising it stays in your hands — you can re-enable a rule at any time, even with a lapsed subscription.

If it is urgent

A broken form on a campaign day cannot wait. Two immediate levers, in order of preference: exempt the path (Tools → Rules), which suspends inspection on that URL only; or switch the site to observation, which suspends blocking everywhere.

Always prefer the URL exemption to observation mode: the first opens one page, the second opens the whole site. And remember to undo it once the rule is handled.

This page did not answer your question?

Contact us