{"id":616,"date":"2026-07-07T11:01:38","date_gmt":"2026-07-01T03:29:29","guid":{"rendered":"https:\/\/brutefort.com\/blog\/wordpress-geo-blocking-login\/"},"modified":"2026-09-03T09:04:19","modified_gmt":"2026-09-03T09:04:19","slug":"wordpress-geo-blocking-login","status":"publish","type":"post","link":"https:\/\/brutefort.com\/blog\/wordpress-geo-blocking-login\/","title":{"rendered":"How to Restrict WordPress Login Access by Country"},"content":{"rendered":"\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"563\" height=\"750\" src=\"https:\/\/brutefort.com\/blog\/wp-content\/uploads\/2026\/07\/pexels-photo-1005638.jpeg\" alt=\"World map with location pins representing WordPress geo blocking by country\" class=\"wp-image-615\" srcset=\"https:\/\/brutefort.com\/blog\/wp-content\/uploads\/2026\/07\/pexels-photo-1005638.jpeg 563w, https:\/\/brutefort.com\/blog\/wp-content\/uploads\/2026\/07\/pexels-photo-1005638-225x300.jpeg 225w\" sizes=\"auto, (max-width: 563px) 100vw, 563px\" \/><figcaption>Photo by Pixabay from Pexels<\/figcaption><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">Checking your login logs and seeing hundreds of attempts from countries none of your users are ever in? That&#8217;s normal, and it&#8217;s also fixable in a couple of clicks. A large share of WordPress login attack traffic \u2014 brute force attempts, credential stuffing, automated bot scans \u2014 comes from a small handful of countries.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Geo blocking restricts access to your login page based on the visitor&#8217;s country, as determined by their IP. It&#8217;s not a replacement for rate limiting or a custom login URL \u2014 it&#8217;s an extra layer that filters out a large chunk of attack traffic before it ever reaches the login form.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Quick Answer:<\/strong> Go to <strong>BruteFort \u2192 Settings \u2192 Geo Blocking<\/strong>, toggle it on, choose Blacklist or Whitelist mode, select your countries, and save. Whitelist mode gives the tightest protection if your users are all in a few known countries.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Blacklist Mode vs. Whitelist Mode<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">BruteFort&#8217;s Geo Blocking feature offers two modes. Which one you pick depends on where your users actually are.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Blacklist mode<\/strong> blocks selected countries and allows everyone else. Choose this if your user base is global and you only want to cut off specific high-risk regions. Select the countries to block and save \u2014 anyone from those countries is denied access to the login page, while the rest of the world can still reach it.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Whitelist mode<\/strong> allows only selected countries and blocks everyone else. This is the stronger option for sites with a defined geographic audience \u2014 a local business, a region-specific membership site, or anywhere you know exactly which countries your admins and users are in. Select only those countries, and every other country is blocked by default.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">For most sites, whitelist mode is the tighter fit. If you can say &#8220;my admins are in the US and UK and my users are never from anywhere else,&#8221; whitelist mode eliminates login attack traffic from the entire rest of the world in one setting.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">How to Set Up Geo Blocking in BruteFort<\/h2>\n\n\n\n<ol class=\"wp-block-list\"><li>Go to <strong>BruteFort \u2192 Settings \u2192 Geo Blocking<\/strong><\/li><li>Toggle <strong>Enable Geo Blocking<\/strong> on<\/li><li>Select your <strong>Mode<\/strong> \u2014 Blacklist (block selected) or Whitelist (allow only selected)<\/li><li>Open the <strong>Select Countries<\/strong> dropdown and choose the countries to block or allow<\/li><li>Click <strong>Save<\/strong><\/li><\/ol>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"589\" src=\"https:\/\/brutefort.com\/blog\/wp-content\/uploads\/2026\/07\/brutefort-geo-blocking.webp\" alt=\"BruteFort Geo Blocking panel with enable toggle, blacklist\/whitelist mode, and country select\" class=\"wp-image-670\" srcset=\"https:\/\/brutefort.com\/blog\/wp-content\/uploads\/2026\/07\/brutefort-geo-blocking.webp 1024w, https:\/\/brutefort.com\/blog\/wp-content\/uploads\/2026\/07\/brutefort-geo-blocking-300x173.webp 300w, https:\/\/brutefort.com\/blog\/wp-content\/uploads\/2026\/07\/brutefort-geo-blocking-768x442.webp 768w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">The restriction is active right away. Visitors from blocked countries trying to reach your login page \u2014 whether at the default <code>\/wp-login.php<\/code> or your custom login URL \u2014 are denied access.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"913\" height=\"516\" src=\"https:\/\/brutefort.com\/blog\/wp-content\/uploads\/2026\/07\/brutefort-geo-blocking-in-login-page.webp\" alt=\"WordPress login page showing Access denied from your location message when geo-blocked\" class=\"wp-image-674\" srcset=\"https:\/\/brutefort.com\/blog\/wp-content\/uploads\/2026\/07\/brutefort-geo-blocking-in-login-page.webp 913w, https:\/\/brutefort.com\/blog\/wp-content\/uploads\/2026\/07\/brutefort-geo-blocking-in-login-page-300x170.webp 300w, https:\/\/brutefort.com\/blog\/wp-content\/uploads\/2026\/07\/brutefort-geo-blocking-in-login-page-768x434.webp 768w\" sizes=\"auto, (max-width: 913px) 100vw, 913px\" \/><\/figure>\n\n\n\n<div class=\"wp-block-stackable-button-group stk-block-button-group stk-block stk-2a9f4d6\" data-block-id=\"2a9f4d6\"><div class=\"stk-row stk-inner-blocks stk-block-content stk-button-group\">\n<div class=\"wp-block-stackable-button stk-block-button stk-block stk-8e3c7b0\" data-block-id=\"8e3c7b0\"><style>.stk-8e3c7b0 .stk-button{background:#f13434 !important;border-top-left-radius:var(--stk--preset--border-radius--small, 4px) !important;border-top-right-radius:var(--stk--preset--border-radius--small, 4px) !important;border-bottom-right-radius:var(--stk--preset--border-radius--small, 4px) !important;border-bottom-left-radius:var(--stk--preset--border-radius--small, 4px) !important;}.stk-8e3c7b0 .stk-button:before{border-color:#0f0e17 !important;}<\/style><a class=\"stk-link stk-button stk--hover-effect-darken\" href=\"https:\/\/brutefort.com\/brutefort-features\/\"><span class=\"stk-button__inner-text\">Get BruteFort Now!<\/span><\/a><\/div>\n<\/div><\/div>\n\n\n\n<h2 class=\"wp-block-heading\">How Geo Blocking Fits With Your Other Login Protections<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Geo blocking works best as part of a layered login security setup, not a standalone measure. Here&#8217;s how the layers interact:<\/p>\n\n\n\n<ul class=\"wp-block-list\"><li><strong>Custom login URL<\/strong> \u2014 hides the login page from bots scanning for <code>\/wp-login.php<\/code>, eliminating most automated discovery before geo blocking even fires<\/li><li><strong>Geo blocking<\/strong> \u2014 filters login access by country, removing attack traffic from regions outside your user base<\/li><li><strong>Rate limiting<\/strong> \u2014 caps failed attempts per IP within a time window, stopping brute force and credential stuffing from any IP that does reach the login page<\/li><li><strong>IP blacklisting<\/strong> \u2014 permanently blocks specific persistent offenders that slip through the other layers<\/li><\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">BruteFort handles all four from the same settings panel. Each layer catches what the previous one misses, and together they eliminate most WordPress login attack traffic with no ongoing management.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Frequently Asked Questions About WordPress Geo Blocking<\/h2>\n\n\n\n<h3 class=\"wp-block-heading\">How accurate is IP-based country detection?<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">BruteFort&#8217;s geo blocking relies on external geolocation APIs, which are generally accurate but not perfect. VPN users and some corporate networks may appear to be in a different country than they physically are. For most sites the accuracy is more than enough \u2014 the goal is reducing attack traffic, not 100% geographic precision. BruteFort notes this directly in the Geo Blocking settings.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">What if I need to log in from a country I&#8217;ve blocked?<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Add your IP to the whitelist in BruteFort&#8217;s IP Settings tab. Whitelisted IPs bypass geo blocking entirely, so you can log in from anywhere without adjusting your geo blocking settings. This is particularly useful for admins who travel internationally.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Does geo blocking affect the rest of my site or just the login page?<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Just the login page. Visitors from blocked countries can still browse your public content, read posts, shop on WooCommerce, and interact with anything on the front end. Only the login authentication endpoint is restricted.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Can I use geo blocking alongside rate limiting?<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Yes, and you should. They work independently and complement each other. Geo blocking filters by country before any credential attempt is made. Rate limiting fires on failed login attempts after access to the login page is granted. So a visitor from an allowed country who tries to brute force their way in still gets stopped by rate limiting. Both layers together is the strongest setup.<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<p class=\"wp-block-paragraph\">Geo blocking is a high-leverage filter \u2014 a few country selections can eliminate a large share of automated login attack traffic with no ongoing effort. <a href=\"https:\/\/wordpress.org\/plugins\/brutefort\/\" target=\"_blank\" rel=\"noopener\">BruteFort<\/a> handles it from the Geo Blocking tab alongside rate limiting, custom login URL, and IP management, so the full protection stack stays in one place.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">You might also like:<\/p>\n\n\n\n<ul class=\"wp-block-list\"><li><a href=\"https:\/\/brutefort.com\/blog\/how-to-block-ip-address-wordpress\/\">How to Block an IP Address in WordPress (And Whitelist Trusted Ones)<\/a><\/li><li><a href=\"https:\/\/brutefort.com\/blog\/how-to-limit-login-attempts-wordpress\/\">How to Limit Login Attempts in WordPress (Step by Step)<\/a><\/li><li><a href=\"https:\/\/brutefort.com\/blog\/how-bots-attack-wordpress\/\">How Bots Attack WordPress Sites (And How to Stop Them)<\/a><\/li><li><a href=\"https:\/\/brutefort.com\/blog\/layered-wordpress-login-protection-without-lockout\/\">How to Combine Rate Limiting, Geo-Blocking &amp; IP Rules Without Locking Yourself Out<\/a><\/li><\/ul>\n\n\n\n<script type=\"application\/ld+json\">\n{\n  \"@context\": \"https:\/\/schema.org\",\n  \"@graph\": [\n    {\n      \"@type\": \"BreadcrumbList\",\n      \"itemListElement\": [\n        {\n          \"@type\": \"ListItem\",\n          \"position\": 1,\n          \"name\": \"Home\",\n          \"item\": \"https:\/\/brutefort.com\/\"\n        },\n        {\n          \"@type\": \"ListItem\",\n          \"position\": 2,\n          \"name\": \"Blog\",\n          \"item\": \"https:\/\/brutefort.com\/blog\/\"\n        },\n        {\n          \"@type\": \"ListItem\",\n          \"position\": 3,\n          \"name\": \"How to Restrict WordPress Login Access by Country\",\n          \"item\": \"https:\/\/brutefort.com\/blog\/wordpress-geo-blocking-login\/\"\n        }\n      ]\n    },\n    {\n      \"@type\": \"FAQPage\",\n      \"mainEntity\": [\n        {\n          \"@type\": \"Question\",\n          \"name\": \"How accurate is IP-based country detection?\",\n          \"acceptedAnswer\": {\n            \"@type\": \"Answer\",\n            \"text\": \"BruteFort's geo blocking relies on external geolocation APIs, which are generally accurate but not perfect. VPN users and some corporate networks may appear to be in a different country than they physically are. For most sites the accuracy is more than enough \u2014 the goal is reducing attack traffic, not 100% geographic precision. BruteFort notes this directly in the Geo Blocking settings.\"\n          }\n        },\n        {\n          \"@type\": \"Question\",\n          \"name\": \"What if I need to log in from a country I've blocked?\",\n          \"acceptedAnswer\": {\n            \"@type\": \"Answer\",\n            \"text\": \"Add your IP to the whitelist in BruteFort's IP Settings tab. Whitelisted IPs bypass geo blocking entirely, so you can log in from anywhere without adjusting your geo blocking settings. This is particularly useful for admins who travel internationally.\"\n          }\n        },\n        {\n          \"@type\": \"Question\",\n          \"name\": \"Does geo blocking affect the rest of my site or just the login page?\",\n          \"acceptedAnswer\": {\n            \"@type\": \"Answer\",\n            \"text\": \"Just the login page. Visitors from blocked countries can still browse your public content, read posts, shop on WooCommerce, and interact with anything on the front end. Only the login authentication endpoint is restricted.\"\n          }\n        },\n        {\n          \"@type\": \"Question\",\n          \"name\": \"Can I use geo blocking alongside rate limiting?\",\n          \"acceptedAnswer\": {\n            \"@type\": \"Answer\",\n            \"text\": \"Yes, and you should. They work independently and complement each other. Geo blocking filters by country before any credential attempt is made. Rate limiting fires on failed login attempts after access to the login page is granted. So a visitor from an allowed country who tries to brute force their way in still gets stopped by rate limiting. Both layers together is the strongest setup. Geo blocking is a high-leverage filter \u2014 a few country selections can eliminate a large share of automated login attack traffic with no ongoing effort. BruteFort handles it from the Geo Blocking tab alongside rate limiting, custom login URL, and IP management, so the full protection stack stays in one place.\"\n          }\n        }\n      ]\n    }\n  ]\n}\n<\/script>\n\n","protected":false},"excerpt":{"rendered":"<p>Most WordPress login attack traffic originates from a small number of regions. Geo blocking filters it out at the country level before it ever reaches your login form.<\/p>\n","protected":false},"author":1,"featured_media":615,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[35],"tags":[],"class_list":["post-616","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-access-control"],"blocksy_meta":[],"_links":{"self":[{"href":"https:\/\/brutefort.com\/blog\/wp-json\/wp\/v2\/posts\/616","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/brutefort.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/brutefort.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/brutefort.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/brutefort.com\/blog\/wp-json\/wp\/v2\/comments?post=616"}],"version-history":[{"count":4,"href":"https:\/\/brutefort.com\/blog\/wp-json\/wp\/v2\/posts\/616\/revisions"}],"predecessor-version":[{"id":815,"href":"https:\/\/brutefort.com\/blog\/wp-json\/wp\/v2\/posts\/616\/revisions\/815"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/brutefort.com\/blog\/wp-json\/wp\/v2\/media\/615"}],"wp:attachment":[{"href":"https:\/\/brutefort.com\/blog\/wp-json\/wp\/v2\/media?parent=616"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/brutefort.com\/blog\/wp-json\/wp\/v2\/categories?post=616"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/brutefort.com\/blog\/wp-json\/wp\/v2\/tags?post=616"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}