{"id":618,"date":"2026-07-01T03:30:56","date_gmt":"2026-07-01T03:30:56","guid":{"rendered":"https:\/\/brutefort.com\/blog\/wordpress-ip-whitelist-admin\/"},"modified":"2026-07-15T13:46:36","modified_gmt":"2026-07-15T13:46:36","slug":"wordpress-ip-whitelist-admin","status":"publish","type":"post","link":"https:\/\/brutefort.com\/blog\/wordpress-ip-whitelist-admin\/","title":{"rendered":"How to Whitelist Trusted IPs for WordPress Admin Access"},"content":{"rendered":"\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1125\" height=\"750\" src=\"https:\/\/brutefort.com\/blog\/wp-content\/uploads\/2026\/07\/pexels-photo-374074.jpeg\" alt=\"Person securely accessing WordPress admin from a trusted location using IP whitelist\" class=\"wp-image-617\" srcset=\"https:\/\/brutefort.com\/blog\/wp-content\/uploads\/2026\/07\/pexels-photo-374074.jpeg 1125w, https:\/\/brutefort.com\/blog\/wp-content\/uploads\/2026\/07\/pexels-photo-374074-300x200.jpeg 300w, https:\/\/brutefort.com\/blog\/wp-content\/uploads\/2026\/07\/pexels-photo-374074-1024x683.jpeg 1024w, https:\/\/brutefort.com\/blog\/wp-content\/uploads\/2026\/07\/pexels-photo-374074-768x512.jpeg 768w\" sizes=\"auto, (max-width: 1125px) 100vw, 1125px\" \/><figcaption>Photo by Pixabay from Pexels<\/figcaption><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">Locked yourself out of your own WordPress admin because your rate limiting was too strict? It happens more than you&#8217;d think. Most site owners focus entirely on blocking bad traffic and forget to protect their own access first.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">An IP whitelist flips that equation. Instead of only chasing attackers, you define exactly which IPs should always get in \u2014 no matter how strict everything else is. This guide covers how to whitelist your trusted IPs in BruteFort and keep the list useful without over-relying on it.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Quick Answer:<\/strong> Go to <strong>BruteFort \u2192 Settings \u2192 IP Settings<\/strong>, choose <strong>WhiteList<\/strong> from the dropdown, enter your IP, and click <strong>Add<\/strong>. Whitelisted IPs skip rate limiting, lockouts, and geo blocking entirely.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">What an IP Whitelist Does in WordPress<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">A whitelisted IP is exempt from every login protection rule \u2014 rate limiting, lockout after failed logins, geo blocking, and blacklist checks. If your IP is on the whitelist, BruteFort skips all its restrictions for you. You can mistype your password ten times without triggering a lockout. You can be in a geo-blocked country and still reach the login page.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">That matters because tight security settings can occasionally catch legitimate users. Whitelist your own IP \u2014 and any trusted team members or clients \u2014 before enabling aggressive protection. Then you can set those protections as strict as you need, without fear of locking yourself out.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">How to Whitelist an IP in BruteFort<\/h2>\n\n\n\n<ol class=\"wp-block-list\"><li>Go to <strong>BruteFort \u2192 Settings \u2192 IP Settings<\/strong><\/li><li>In the <strong>Choose Option<\/strong> dropdown, select <strong>WhiteList<\/strong><\/li><li>Enter the IP address in the <strong>IP Address<\/strong> field<\/li><li>Click <strong>Add<\/strong><\/li><\/ol>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"589\" src=\"https:\/\/brutefort.com\/blog\/wp-content\/uploads\/2026\/07\/brutefort-ip-settings.webp\" alt=\"BruteFort IP Settings screen showing the whitelist and blacklist manager with IP table\" class=\"wp-image-669\" srcset=\"https:\/\/brutefort.com\/blog\/wp-content\/uploads\/2026\/07\/brutefort-ip-settings.webp 1024w, https:\/\/brutefort.com\/blog\/wp-content\/uploads\/2026\/07\/brutefort-ip-settings-300x173.webp 300w, https:\/\/brutefort.com\/blog\/wp-content\/uploads\/2026\/07\/brutefort-ip-settings-768x442.webp 768w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">The whitelisted IP appears immediately in the table with its type, address, and the date added. Search and filter the table, and remove entries any time. Add one entry per address to cover every location you or your team regularly works from.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Pro Tip:<\/strong> To find your current IP, search &#8220;what is my IP&#8221; in any browser. The result is your public IP as seen by external servers \u2014 the same one BruteFort sees when you access your site.<\/p>\n\n\n\n<div class=\"wp-block-stackable-button-group stk-block-button-group stk-block stk-5f8a2c1\" data-block-id=\"5f8a2c1\"><div class=\"stk-row stk-inner-blocks stk-block-content stk-button-group\">\n<div class=\"wp-block-stackable-button stk-block-button stk-block stk-7b1d9e4\" data-block-id=\"7b1d9e4\"><style>.stk-7b1d9e4 .stk-button{background:#f13434 !important;border-top-left-radius:var(--stk--preset--border-radius--small, 4px) !important;border-top-right-radius:var(--stk--preset--border-radius--small, 4px) !important;border-bottom-right-radius:var(--stk--preset--border-radius--small, 4px) !important;border-bottom-left-radius:var(--stk--preset--border-radius--small, 4px) !important;}.stk-7b1d9e4 .stk-button:before{border-color:#0f0e17 !important;}<\/style><a class=\"stk-link stk-button stk--hover-effect-darken\" href=\"https:\/\/brutefort.com\/blog\/best-security-plugins-wordpress\/\"><span class=\"stk-button__inner-text\">Get BruteFort Now!<\/span><\/a><\/div>\n<\/div><\/div>\n\n\n\n<h2 class=\"wp-block-heading\">When to Use an IP Whitelist vs. When Not To<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Add to the whitelist:<\/strong> your home IP, your office IP, IPs for trusted agency clients who need admin access, and IPs of remote developers or editors who log in regularly. Travel often and need to log in from countries that may be geo-blocked? Whitelist your hotel or VPN IP, or plan to adjust your settings before you leave.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Don&#8217;t over-whitelist:<\/strong> the value of a whitelist comes from its selectivity. Whitelisting a wide range of IPs \u2014 or every IP a client&#8217;s ever used \u2014 dilutes the protection. Keep the list to IPs that need permanent, reliable access. For one-off access needs, temporarily adjusting your rate limiting threshold is cleaner than adding an IP you&#8217;ll forget to remove.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"589\" src=\"https:\/\/brutefort.com\/blog\/wp-content\/uploads\/2026\/07\/brutefort-rate-limiting-settings.webp\" alt=\"BruteFort Rate Limit Settings tab showing rate limits and lockout settings together\" class=\"wp-image-672\" srcset=\"https:\/\/brutefort.com\/blog\/wp-content\/uploads\/2026\/07\/brutefort-rate-limiting-settings.webp 1024w, https:\/\/brutefort.com\/blog\/wp-content\/uploads\/2026\/07\/brutefort-rate-limiting-settings-300x173.webp 300w, https:\/\/brutefort.com\/blog\/wp-content\/uploads\/2026\/07\/brutefort-rate-limiting-settings-768x442.webp 768w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<h2 class=\"wp-block-heading\">Dynamic IPs: What to Do If Your IP Changes<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Most residential internet connections use dynamic IPs that change periodically. This is the most common complication with whitelisting. A few practical approaches:<\/p>\n\n\n\n<ul class=\"wp-block-list\"><li><strong>Use a VPN with a static IP<\/strong> \u2014 many business VPNs assign a fixed IP, which you add to the whitelist once and it stays valid regardless of where you physically are<\/li><li><strong>Check and update when your IP changes<\/strong> \u2014 if you notice more login friction than usual, check your current IP and update the whitelist entry<\/li><li><strong>Rely on the custom login URL instead<\/strong> \u2014 if dynamic IPs make whitelisting impractical, BruteFort&#8217;s Custom Login URL combined with rate limiting protects you without depending on a stable IP<\/li><\/ul>\n\n\n\n<h2 class=\"wp-block-heading\">Frequently Asked Questions About WordPress IP Whitelisting<\/h2>\n\n\n\n<h3 class=\"wp-block-heading\">Does whitelisting bypass geo blocking too?<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Yes. A whitelisted IP bypasses every BruteFort restriction, including geo blocking. Traveling to a country your own geo blocking settings have blocked? Add your IP to the whitelist and log in without touching the geo blocking configuration. That&#8217;s the recommended approach for admins who travel to blocked regions, rather than disabling geo blocking entirely.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Should I whitelist my IP before enabling rate limiting?<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Yes \u2014 that&#8217;s the recommended order. Add your own IP to the whitelist first, then configure rate limiting and lockout settings. That way, even if you make a configuration mistake, or mistype your password while testing, you won&#8217;t accidentally lock yourself out of your own dashboard.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Can I whitelist a whole IP range instead of individual addresses?<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">BruteFort&#8217;s IP Settings handles individual IP addresses rather than CIDR ranges. For whitelisting a range at the server level \u2014 an office network block, for example \u2014 use server firewall rules or <code>.htaccess<\/code> instead of the plugin. Within BruteFort, add each specific IP individually.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">What happens if I accidentally blacklist a whitelisted IP?<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">The IP Settings table clearly labels each entry&#8217;s type \u2014 Whitelist or Blacklist. Delete the entry and re-add it with the correct type. If you blacklisted your own IP and are now locked out, deactivate BruteFort temporarily via FTP by renaming its folder in <code>\/wp-content\/plugins\/<\/code>. That restores login access while you fix the entry.<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<p class=\"wp-block-paragraph\">An IP whitelist is the foundation that makes aggressive login protection practical \u2014 set it up before enabling any other BruteFort protections. <a href=\"https:\/\/wordpress.org\/plugins\/brutefort\/\" target=\"_blank\" rel=\"noopener\">BruteFort<\/a> manages whitelist and blacklist entries from the same IP Settings tab, alongside rate limiting, geo blocking, and custom login URL.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">You might also like:<\/p>\n\n\n\n<ul class=\"wp-block-list\"><li><a href=\"https:\/\/brutefort.com\/blog\/how-to-block-ip-address-wordpress\/\">How to Block an IP Address in WordPress (And Whitelist Trusted Ones)<\/a><\/li><li><a href=\"https:\/\/brutefort.com\/blog\/wordpress-geo-blocking-login\/\">How to Restrict WordPress Login Access by Country<\/a><\/li><li><a href=\"https:\/\/brutefort.com\/blog\/how-to-limit-login-attempts-wordpress\/\">How to Limit Login Attempts in WordPress (Step by Step)<\/a><\/li><\/ul>\n","protected":false},"excerpt":{"rendered":"<p>Whitelisting trusted IPs for WordPress admin access lets you set aggressive login protections without ever risking your own lockout. Here&#8217;s how to set it up with BruteFort.<\/p>\n","protected":false},"author":1,"featured_media":617,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[35],"tags":[],"class_list":["post-618","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-access-control"],"blocksy_meta":[],"_links":{"self":[{"href":"https:\/\/brutefort.com\/blog\/wp-json\/wp\/v2\/posts\/618","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/brutefort.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/brutefort.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/brutefort.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/brutefort.com\/blog\/wp-json\/wp\/v2\/comments?post=618"}],"version-history":[{"count":1,"href":"https:\/\/brutefort.com\/blog\/wp-json\/wp\/v2\/posts\/618\/revisions"}],"predecessor-version":[{"id":709,"href":"https:\/\/brutefort.com\/blog\/wp-json\/wp\/v2\/posts\/618\/revisions\/709"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/brutefort.com\/blog\/wp-json\/wp\/v2\/media\/617"}],"wp:attachment":[{"href":"https:\/\/brutefort.com\/blog\/wp-json\/wp\/v2\/media?parent=618"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/brutefort.com\/blog\/wp-json\/wp\/v2\/categories?post=618"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/brutefort.com\/blog\/wp-json\/wp\/v2\/tags?post=618"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}