Block traffic from countriesyou don't serve.

Most requests to your site come from countries you've never sold to — bots probing logins, scrapers, spam. MalCare blocks whole countries in a few clicks, drops their requests before your server does any work, and reverses in one click.

400,000+ SITES · 18B+ REQUESTS / MO · 2B+ ATTACKS BLOCKED / MO
Trusted by 400,000+ sites · 120 countries
The gap

Customers in a few countries.
Requests from everywhere.

The difference is probes, password guesses, scrapers and spam — load you pay for and risk you carry, from places that will never buy anything.

90,000
— WordPress attacks per minute, globally

A worldwide target

The background noise is constant, even when your market is local.

Roughly half
— industry estimate of internet traffic that is bots, not people

Not every request is a visitor

CPU and network spikes often expose the difference.

2B+
— attacks the MalCare network blocks every month

Network evidence

Patterns are learned across 400,000+ sites.

The evidence

Your logs already show which countries to block.

Every request is logged with its origin country. Open View Firewall Logs and the block list writes itself — no guessing, no folklore.

  • 2.1Every request, with its originSee which countries send the most and whether the traffic is legitimate.
  • 2.2The login tellThousands of failed logins and no customers isn't an audience — it's a botnet.
  • 2.3Your list, from your dataBlock from evidence; no country is bad by default.
What the firewall logs
Two seven-day records read off the same firewall log. Origin A sent 12,884 requests and 4,312 login attempts against three usernames, and recorded no successful logins, no orders and no accounts created. Your market sent 3,202 requests and filled every one of the same six fields.

Origin A

Seven days · from your firewall log

requests
12,884
login attempts
4,312
usernames triedadmin · editor · support
3
successful logins
none recorded
orders
none recorded
accounts created
none recorded

Nothing in these three fields, all week

4,312 attempts · 0 successes · 0 customersBlock from evidence like this — not from a country's reputation.

Your market

Same record · same week

requests
3,202
login attempts
118
usernames tried
4
successful logins
109
orders
87
accounts created
41

Every field filled — this is what a market looks like.

Read it yourselfSites → your site→ View Firewall Logs

The switch

Block a country in three steps. Undo it in one.

Pick countries from a dropdown and click Block. Country-to-IP mapping is the firewall's job, kept current for you.

Step 1

Open GeoBlocking

Sites screen → pick your site → the globe icon.

Step 2

Pick countries

As many as you want — each joins the block list.

Step 3

Click Block countries

Requests drop at the edge from that moment; blocked visitors see a 403.

Step 4

Reverse any time

Remove a country from the list — traffic resumes immediately; nothing was edited, so nothing can break.

The manual way

Thousands of .htaccess lines

IP ranges updated monthly; one typo takes the site down.

The MalCare way

A dropdown

The firewall keeps the mapping current; you never touch a file.

A blocked request does no work.
Your server feels the difference.

Dropped requests never reach your site. What's left is your real traffic — and metrics that describe your market.

  • No PHP executed, no database queried
  • No bandwidth spent on bot traffic
  • Attack surface shrinks with every closed country
  • Analytics reflect your market, not the crowd
Done right

Geoblocking has known holes. Ours is built to cover them.

IP ranges drift, and a VPN can hop a border. That's why MalCare's geoblocking runs inside the firewall, not on its own.

From a blocked country: the border reads the origin, finds Country A on your block list and drops the request at the edge with a 403. The guard is never reached and your site is never touched.

Via a VPN: the origin now reads Country M, a permitted country, so the border lets the request through. The guard reads its behaviour instead — the same three usernames, the same six paths, the same 40 millisecond cadence — and matches it to a pattern the network already knows. Same actor, new origin, blocked anyway.

A real customer: a permitted origin, and a behaviour signature that is irregular and human rather than repeating. Both layers pass the request through and the page is served.

Incoming requestone request, three ways in
Origin

Country A

Country M · VPN exit node

Your market

Behaviour

repeating · machine cadence

irregular · human

The borderreads the origin

Country A is on your block list

Country M is not on your list

Your market is not on your list

Held · 403 at the edgePassed
The guardreads the behaviour

Never reached — the request ended at the border.

This requestPattern the network knows
Held · same actorPassed · no match
Your sitewhat actually arrived

Nothing arrived. No PHP, no query, no bandwidth.

Nothing arrived — new origin, same actor.

Page served. A real visitor, unbothered.

The border stops the region. The guard stops the actor.

Known hole

"VPNs hop the border."

True. VPN and proxy IPs get behavior analysis, and malicious ones are blocked anyway.

Known hole

"IP lists rot."

You never keep a list. Country mapping is the firewall's job, kept current.

Known risk

"I might block someone I need."

Decide from your own logs; unblocking is one click and nothing was edited, so nothing can break.

The honest split

"Blocking alone isn't security."

Correct. This layer shrinks the surface; the other layers guard what stays open.

The three doors

Geoblocking, bot protection, firewall. Which one blocks what.

Three blocking layers, one dashboard — here's the split.

LayerGeoblockingBot protectionFirewall
What it blocksWhole countries you pickAutomated non-human trafficAttack payloads inside requests
Who decidesYou — a dropdown and a buttonThe network, by behavior across 400,000+ sitesThe network's rules, learned from live attacks
When it actsBefore your server does any workAt the edge, request by requestOn every request
ReversalOne click — remove from the listAutomatic — nothing to manageAutomatic
IncludedWith the pluginWith the pluginWith the plugin

In their words. Blocked — and nothing broke.

Rated 5 out of 5
Best login protection ever! We handle hundreds of sites, and I'd heard bad stories about brute force attacks & password hacking… but thankfully we never had to worry about this because of MalCare. I'm sure this saved us from many sleepless nights!
Robert AbelaWP Activity Log
Rated 5 out of 5
I was on the beach with my family when MalCare notified me of a plugin vulnerability across 50 of my sites. With one click on my smartphone, all sites were fixed within minutes.
Paul LaceyWordPress Expert
Rated 5 out of 5
I had been running iThemes, WordFence & Sucuri, but they kept getting hacked. Then I installed MalCare, which quickly found the malware and cleaned up the entire site.
Adam SilverFounder · ConciergeWP

Not sure what to block? Ask a real person.

Which countries, what it changes, how to undo it — support answers before you buy.

24/7 · SECURITY EXPERTS · NO OBLIGATION

Common questions, answered.

An Access Denied (403) page. Their request is dropped at the edge — your server does no further work for them.
As many as you want — pick them from the dropdown and each joins your block list. Some site owners block everything outside the countries they actually serve.
Yes. Go back to the GeoBlocking screen and remove the country from your list — traffic resumes immediately. Because nothing was ever edited on your site, nothing can break.
Some try. IPs arriving through VPNs and proxies get behavior analysis from the firewall, and malicious ones are blocked anyway. The border keeps the region out; the firewall keeps the actor out.
This is the classic geoblocking risk — search crawlers, uptime monitors, backup services, and payment webhooks live in specific countries. Check your firewall logs before you block, and be deliberate about regions where your search audience or infrastructure lives. Blocking is instantly reversible if you spot a problem.
Bot protection handles bad actors automatically, wherever they're from. Geoblocking is for when you want a region shut, not guarded. Many owners want both — and both come with the plugin.
No — it removes work. Blocked requests are dropped before your site runs any code, so blocking a region makes your server lighter, not busier.
Never. Manual geoblocking means thousands of .htaccess lines updated monthly — that's the project this feature retires. Country-to-IP mapping is the firewall's job.

Block your first country in the next five minutes.

Pick it from a dropdown. Requests drop at the edge from that moment. One click to reverse.

NO IP LISTS / NO .HTACCESS / TAKES EFFECT IMMEDIATELY