New Customers: 50% OFF Your First Month on All VPS Servers & Web Hosting Plans!

How to ban any IP Address via .htaccess?

Learn to block unwanted IP addresses on your hosting using cPanel's built-in IP Blocker tool or by manually adding Require rules to your .htaccess file. The guide covers both methods, how to block ranges and subnets, and how to troubleshoot if blocking is not working.

HostworldWeb hosting & cPanel 3 min read Updated 23 Sep 2026

Block an IP on Hostworld cPanel hosting either with cPanel’s IP Blocker or by adding a Require-based rule to your site’s .htaccess that denies that IP while allowing everyone else.

Before you start

  • Have the exact address you want to block: a single IPv4 or IPv6, or a subnet in CIDR format.
  • Decide the scope. .htaccess applies to its folder and all subfolders. For the whole primary site, edit the file in public_html.
  • If your site is behind a CDN or reverse proxy, Apache will match the proxy’s IP. If you need real visitor IPs restored, open a support ticket.

Step 1: Block the IP in cPanel (writes .htaccess for you)

  1. Log in to cPanel and open IP Blocker (Security section).
  2. Enter what you want to block:
    • Single IP: for example 198.51.100.25
    • Range or subnet in CIDR: for example 203.0.113.0/24
  3. Click Add. The block takes effect immediately.
  4. To avoid over-blocking, do not use implied prefixes unless you mean them. For example entering 10. blocks the entire 10.0.0.0/8 range. Prefer CIDR when you need a range.

Step 2: Manually block an IP in .htaccess (Apache 2.4 syntax)

  1. In cPanel, open File Manager, go to your site’s document root (for the primary domain this is usually public_html), and show hidden files so you can see .htaccess.
  2. Edit .htaccess and add this block. It allows all visitors except the IP you name. The <RequireAll> container is essential so the rules are ANDed.
    <RequireAll>
      Require all granted
      Require not ip 198.51.100.25
    </RequireAll>
  3. Save. Changes apply straight away, no restart needed.
  4. To block more, add more Require not ip ... lines or put multiple addresses on one line. To block a range, use CIDR like 203.0.113.0/24 or a prefix like 203.0.113. Wildcards such as 1.2.3.* are not valid.

Step 3: Undo or adjust the block

  1. cPanel IP Blocker: open IP Blocker, find the entry, then click Delete. This unblocks immediately.
  2. Manual .htaccess: remove the <RequireAll> ... </RequireAll> lines you added, then save.
  3. If you have locked yourself out or cannot reach the file, use cPanel’s File Manager to edit .htaccess, or open a support ticket and we will help.

If it does not work

  • 500 error or unexpected behaviour: you likely used the old Apache 2.2 Order/Allow/Deny syntax or mixed it with Require. Remove the old directives and use Require only, as shown above.
  • No effect at all: .htaccess might be ignored if AllowOverride is disabled in that directory. Quick test: add a random word at the top of .htaccess. If you do not get a 500 error, Apache is not reading it there. Open a support ticket and we will check the server configuration for you.
  • The IP is not blocked: make sure you wrapped the rules in <RequireAll>. Without it, multiple Require lines are ORed and Require all granted will win. If you are behind a CDN or reverse proxy, Apache is seeing the proxy’s IP. Ask us to review real visitor IP configuration via a support ticket.

What next

If you run a VPS with us, you can put Require rules in the virtual host config instead of .htaccess for better performance and scope control. See our VPS guides for server-level administration. If you need a VPS in the UK with full control, our London VPS range is available. If you would like us to review a block before you apply it, please open a support ticket.

Common questions

How do I block an IP address on shared hosting?

You can block an IP using cPanel's IP Blocker tool in the Security section, or by adding a Require not ip rule to your .htaccess file in your site's document root. Both methods take effect immediately.

Can I block a range of IP addresses?

Yes. Use CIDR notation such as 203.0.113.0/24 or a prefix like 203.0.113. to block a range. Enter it in cPanel IP Blocker or in your .htaccess Require rule.

What syntax should I use in .htaccess?

Use Apache 2.4 Require syntax with a RequireAll container. The old Order/Allow/Deny syntax from Apache 2.2 no longer works and will cause a 500 error.

How do I unblock an IP address?

In cPanel IP Blocker, find the entry and click Delete. If you added it manually to .htaccess, remove the RequireAll block containing the Require not ip line and save the file.

What should I do if the IP block is not working?

Make sure you wrapped the rules in a RequireAll container. If you are behind a CDN or reverse proxy, Apache is seeing the proxy's IP instead. Open a support ticket so we can check your configuration.

Was this article helpful?