IP lists and exemptions
Allow, ban, and suspend inspection on a specific path.
4 minUpdated
These settings live under Tools → Rules. They apply per site: a rule created from one site does not affect the others unless you explicitly extend it to all.
Block list and allow list
| List | Effect | When to use it |
|---|---|---|
| Block list | The address can no longer reach your site at all. | An identified source of abuse, a persistent scanner. |
| Allow list | The address is always allowed and never inspected. | Your office, a contractor, a testing tool. |
The allow list short-circuits everything
An allow-listed address is no longer inspected at all. Useful for a tool sending attack-like payloads, but it also means a compromised machine on that network would pass unchecked. Only add what you control.
Automatic banning
Switch it on under Tools → Protection: past a threshold of detections over 24 hours, the address is added automatically to that site's block list for the duration you set. An allow-listed address is never counted, since it is not inspected.
Exempting a URL
Suspends all inspection on a path. Keep it for technical integrations that legitimately send unusual content — payment notifications, third-party API entry points.
A URL exemption opens the whole page, across every attack family. For a false positive on one specific rule, reporting it is the right tool: it neutralises one rule and leaves the thousands of others active.
This page did not answer your question?
Contact us