Flash Sale:75% Off Hosting + Free DomainEnds in13h47m14sView Plans
Hostvento logoHostvento

How to Block an IP Address with .htaccess

Learn how to stop one visitor, or a group of visitors, from reaching your website by using the .htaccess file.

Files and FTP2 min read9 steps

What is .htaccess?

.htaccess is a small settings file for websites on Apache servers. Apache is the program that serves web pages. Your rules in this file tell Apache what to allow or refuse. The file name starts with a dot, so it is hidden by default.

What is an IP address?

An IP address is a number that identifies a device on the internet, like a house number. Example: 203.0.113.25. You can block a bad visitor by their IP address.

Warning: A wrong rule can break your site or lock you out. Download a copy of your current .htaccess file first. Do not block your own IP address.

Steps

  1. Log in to your hosting control panel. Your welcome email has the link. If you use cPanel, open File Manager.
  2. Open the folder of your website, often public_html.
  3. Click Settings at the top right and tick Show Hidden Files (dotfiles). Click Save.
  4. Find the file named .htaccess. If it does not exist, click + File and create it.
  5. Right-click it and choose Download to save a backup.
  6. Right-click it again and choose Edit.
  7. Add the rule at the bottom, as shown below.
  8. Click Save Changes.
  9. Reload your website to make sure it still works.

Rules to use

Block one IP address:

<RequireAll>
Require all granted
Require not ip 203.0.113.25
</RequireAll>

This lets everyone in except that one address. It works on newer Apache (2.4).

Block a whole range, for example every address starting with 203.0.113:

<RequireAll>
Require all granted
Require not ip 203.0.113
</RequireAll>

Older Apache (2.2) uses a different style:

Order Allow,Deny
Allow from all
Deny from 203.0.113.25

This does the same job on old servers. If you are not sure which version you have, ask Hostvento support.

How to undo it

Open the file again and delete the lines you added. Save the file.

Tip: If you see a 500 error after saving, restore your backup right away. A typing mistake is the usual cause.

Quick recap

  • .htaccess holds rules for Apache.
  • Back up the file before changing it.
  • Use Require not ip to block an address.
  • Do not block your own IP.
  • Remove the lines to unblock.