Block Direct IP Access to Your Server

Answer only on your own hostnames

Answer only on your own hostnames

Direct IP Access Blocking makes your server refuse every visit that does not use one of your sites' hostnames, for example a visit to its bare IP address. Use it when your sites sit behind Cloudflare or another CDN and the server itself should not be reachable directly.

Where: Servers › My Servers › your server › Services › Security Settings › Direct IP Access Blocking

01 · Turn it on

  1. Click Block Direct IP Access.
  2. Confirm. The line next to the button now reads Direct IP access is blocked.

To undo it, click Disable IP Blocking; the line reads Direct IP access is allowed again.

02 · What changes

  • A request whose hostname matches none of your sites, over HTTP or HTTPS, gets 403 Forbidden with the text Direct IP access is not allowed.
  • Requests to your sites' hostnames work as before.
Every name a site answers to must be its project's Hostname or one of its Server Aliases (project page › Edit Settings). A name that is in neither is refused too.

To limit which addresses can reach the server at all, use the firewall.

Services tab