Blacklist Manager Premium / Advanced Protection August 3, 2026

Advanced Blocking: IP, Country, Browser, and Domain Rules

Configure advanced IP, country, browser, domain, TLD, proxy, hosting, radius, and REST API blocking in Blacklist Manager.

Applies to Core 2.2.11 / Premium 2.6.4+ Stable Verified August 3, 2026

Blocking rules control which customer details are prevented at checkout, registration, comments, reviews, forms, or site access.

Email, Phone, IP, and Domain Blocking

The core plugin can block common details such as email address, phone number, IP address, and email domain. Depending on settings, matching customers can be blocked at checkout, registration, comments, reviews, forms, or WooCommerce REST API order creation.

TLD Blocking

Premium can block email top-level domains such as specific country-code or generic TLDs. Use this only when you are sure the TLD is not used by legitimate customers on your store.

Country Access Prevention

Country access prevention can prevent visitors from selected countries or allow only selected countries, depending on your configuration. Use this when your store has clear country restrictions.

Browser Blocking

Browser blocking can prevent checkout or access from selected browser signatures. Use this carefully because user agents can be unreliable and may affect legitimate customers.

Proxy, VPN, TOR, and Hosting IP

These checks identify customers using anonymized or infrastructure-based connections. They are useful fraud signals, but many legitimate customers also use VPNs. Start with scoring or suspect actions before hard blocking.

IP Address Radius

IP radius checks compare the IP location with the billing or shipping address location. Because IP geolocation is approximate, use this as a risk signal rather than a single blocking reason.

REST API Protection

If external systems create WooCommerce orders through the REST API, enable REST API protection so blacklisted details can still be checked outside normal checkout.

  1. Block exact emails and phone numbers first.
  2. Add IP blocking if abuse comes from repeat IPs.
  3. Add domain/TLD rules only after reviewing legitimate customer domains.
  4. Use country/browser/proxy rules as score contributors before hard blocks.
  5. Enable REST API protection if integrations create orders directly.

Related Guides

Continue from Blacklist Manager Premium documentation to the complete product workflow.

Evaluate product scope on the money page, use the pillar Guide for decisions and trade-offs, and return here for exact configuration.

Need support?

Still stuck?

Open a support request and include this article title, your plugin version, and what you already tried.

Open Support