Skip to main content
web60

Infrastructure

Country Blocking on Your Website: Who It Really Locks Out

Ian O'Reilly··15 min read
Teal network nodes joined by teal lines, crossed by a thick navy arc that splits the network in two, on an off-white background

Most security plugins for WordPress offer a setting that looks like pure common sense. Pick the countries your customers come from, block everyone else, and a large share of the attack traffic hitting your site supposedly disappears overnight. It takes about thirty seconds to switch on. It feels responsible.

It is also a setting that routinely causes harm nobody connects back to its source. Country blocking does not only stop attackers. It stops anyone whose connection appears to come from the wrong place, and that group is larger, and more valuable to your business, than most owners expect.

This article is a reference for anyone who has switched on country blocking, is thinking about it, or has inherited a site where someone else did. It covers how the feature decides where a visitor is, the five groups it quietly turns away, whether it actually stops the attacks it promises to stop, and what a sensible alternative looks like.

How Country Blocking Decides Where a Visitor Is

Your website never learns where a visitor is physically standing. It sees an IP address, the number that identifies the connection. The blocking tool looks that number up in a geolocation database, which maps blocks of addresses to countries based on which internet provider holds them and where that provider operates.

At country level those databases are usually right. The problem is that "right" means "correct about the connection", not "correct about the person".

  • A customer from Athlone on holiday in Lanzarote connects through the hotel Wi-Fi. The connection is Spanish.
  • A customer using a work VPN appears wherever their employer's VPN gateway sits, which may be London, Amsterdam or Virginia.
  • An automated service, such as a search engine crawler or a payment processor, appears wherever its servers happen to run.

In every one of those cases the geolocation lookup is accurate and the blocking decision is still wrong. The visitor is a legitimate customer or a service your site depends on. The tool simply cannot tell.

The Five Groups Country Blocking Turns Away

The table below summarises who ends up on the wrong side of the wall. Each row is covered in detail in the sections that follow.

Who gets blockedWhere they appear to beWhat it costs you
Your own customers travellingWherever they are on holiday or businessLost orders and bookings, confused regulars
Overseas buyersTheir home countrySales you never see, from people who never complain
GooglebotMostly the United StatesPages dropping out of Google search
Your payment provider's notificationsCloud servers outside IrelandPaid orders stuck as unpaid
Customers in other EU countriesElsewhere in the EUA possible breach of the Geo-blocking Regulation
Two teal walls of rounded blocks topped with navy circles, separated by an open gap, with one navy circle wedged into a hole in the wall
A country block cannot tell a returning customer abroad from an attacker. Both simply appear to be somewhere else.

Your Own Customers, Travelling

Irish people travel a great deal. According to the CSO's Household Travel Survey, Irish residents took roughly 15 million overnight trips abroad in 2025, up about 11% on the year before [1]. Around a quarter of those trips were to visit friends and relatives, and a small share were for business.

Every one of those travellers is a potential visitor who, for the length of the trip, appears to be somewhere other than Ireland. The regular who books a table for the night they land home. The client who wants to check your opening hours before they fly back. The customer who remembers, while sitting in an airport, that they meant to order a gift.

Block the country they are in and they get an error page from your own website. Most will not ring to ask why. They will assume the site is broken, and some will book or buy from the next result instead.

Buyers Who Were Never in Ireland

Many local firms sell far more abroad than they realise, because overseas buyers arrive quietly through Google and never draw attention to themselves. Consider an illustrative case: a genealogy researcher in Mayo whose clients are almost entirely descendants of emigrants living in the United States, Canada and Australia. A well-meaning relative switches on "Ireland and UK only" in the security plugin to cut down on login attacks.

The researcher's enquiry form keeps working perfectly in every test they run from home. Enquiries simply slow down, then stop. There is no error in the inbox and no complaint from a customer, because the customers affected never got far enough to complain. By the time anyone connects the drop to a setting changed weeks earlier, a season's worth of leads has gone elsewhere.

That silence is what makes country blocking dangerous for any business with an overseas audience. Blocked visitors leave no trace in your enquiries, only a gap.

Googlebot, Crawling From the United States

This is the one that does the most damage for the widest range of businesses, including those who sell only in Ireland.

Google's own Search Central documentation states that the default IP addresses of the Googlebot crawler appear to be based in the USA, although it also crawls from some addresses outside the US [2]. Block the United States and you block Google's main crawler from reading your site. Wordfence, one of the most widely used WordPress security plugins, says plainly in its help documentation that its country blocking does not make exceptions for Googlebot and will block it if you block the USA [3].

In practice that means Google stops being able to see new pages or changes, then starts treating existing pages as unreachable. Your rankings do not collapse the day you tick the box. They erode over the following weeks, which is exactly why the cause is so hard to trace.

The obvious workaround, blocking US visitors but letting Googlebot through, creates a different conflict. When asked about exactly that setup in 2022, Google's John Mueller said it "would be against the webmaster guidelines", as reported by Search Engine Roundtable [4]. Showing Google a page that real users in the same country cannot see is treated as cloaking. There is no clean version of a US block for a site that wants to rank.

Your Payment Provider's Notifications

This is the dependency that almost nobody thinks about. When a customer pays through an online checkout, the payment provider often confirms the result by sending a separate notification, called a webhook, from its own servers to your website. Your shop uses that message to mark the order as paid.

Stripe publishes the full list of addresses its webhook notifications can come from [5]. When we checked each of those addresses against Amazon Web Services' published address ranges while researching this article, every one sat in a data centre region in the United States, India or Germany. None were in Ireland.

A shop set to allow Ireland only will, depending on how its checkout is configured, reject some or all of those confirmations. The customer has paid. Their bank shows the charge. Your shop shows the order as pending, or never sends the confirmation email, and the first you hear of it is a customer asking where their order is. The same principle applies to other payment, booking and shipping services that talk to your site from servers abroad.

Customers in Other EU Countries

The final group raises a legal point rather than a commercial one. The EU Geo-blocking Regulation, which has applied since December 2018, restricts traders from blocking or limiting a customer's access to their website because of the customer's nationality or where they live. The CCPC's guidance for businesses puts it directly: the Regulation "bans traders from blocking access to websites and re-routing without a consumer's prior consent" [6].

The CCPC lists the exceptions as situations where an EU or national legal requirement obliges the trader to block access. Security is not listed among them. The Regulation concerns other EU and EEA countries, so blocking a non-EU country is a separate question. But a blanket "Ireland only" rule on a trading website that serves consumers sits uncomfortably close to what the Regulation prohibits. If your site does this today, it is worth raising with your solicitor rather than assuming a security rationale covers it.

Does Country Blocking Actually Stop Attacks?

It reduces noise. It does not stop a determined attacker, and it was never going to.

The login attempts and vulnerability probes that hit a typical WordPress site come largely from automated tools running on hijacked home computers, compromised websites and rented cloud servers. Those machines are everywhere, including throughout Europe and inside Ireland. An attacker who finds a site blocked from one country simply retries from a server in an allowed one, which costs them nothing.

What country blocking does achieve is a cleaner security log. Fewer entries, fewer alerts, a quieter dashboard. That has some operational value, and to be fair to the feature, cutting the volume of junk login attempts does reduce load on a busy site. But a quieter log is not the same as a safer site. The attacks that matter, the ones exploiting an outdated plugin or a reused password, arrive from allowed countries just as easily.

There is one situation where tight geographic restrictions genuinely make sense. A business with a legal duty to restrict access by jurisdiction, or a large retailer with an in-house security team and the budget for an enterprise edge firewall, can run carefully maintained geographic rules with proper exceptions and logging. Premium managed hosts that bundle that kind of enterprise firewall, along with the staff to tune it, genuinely suit that workload better. That is not most businesses reading this, and it is not the tick-box in a plugin.

A teal arched door with a navy keyhole standing in front of soft overlapping pale teal circles on an off-white background
Protect the door, not the map. Hardening the login does more than blocking whole countries.

Protect the Door, Not the Map

A better approach starts from a simple principle. Security controls should target behaviour, not geography. The things attackers actually do, such as hammering the login page, guessing passwords, or requesting files that do not exist, can be detected and stopped wherever they come from, without turning away customers who happen to be abroad.

A proper setup for a small business site should do four things:

  1. Protect the login, not the whole site. If you keep any geographic rule at all, limit it to the login page. Customers never need to reach your login page. Googlebot does not need it either. Wordfence itself offers a login-only option.
  2. Stop repeated failures automatically. Rate limiting and temporary bans for an address that fails too many logins deal with brute-force attempts from any country. We cover how these attacks work in our guide to WordPress brute-force login attacks.
  3. Make the password irrelevant. Two-factor authentication on every administrator account means a guessed or leaked password is not enough on its own.
  4. Harden the server, not just the plugin. Protection that runs at server level catches malicious traffic before WordPress even loads, which is both more effective and lighter on your site's resources.

That last point is where your hosting platform matters more than any plugin setting. On Web60, server-level security hardening and fail2ban intrusion prevention watch for abusive behaviour, such as repeated failed logins, and block the offending address at the server, while automatic malware scanning checks the site itself. Because it acts on behaviour rather than location, a customer in Boston and a crawler in California reach the site normally, while the machine trying hundreds of passwords does not. You can read more about how Web60's security-hardened Irish infrastructure is put together.

One limitation is worth stating clearly. Behaviour-based blocking works on addresses, and some mobile networks place many customers behind a single shared address. An aggressive ban on one misbehaving device can occasionally catch others on the same network for the length of the ban. That is why ban durations should be temporary and thresholds sensible, and why an operations team needs to be able to lift a ban quickly when a genuine customer reports a problem. It is a far narrower risk than blocking an entire continent, but it is not zero.

For the wider picture of how these layers fit together with backups and recovery, our WordPress security and backup guide sets out the full operational approach.

How to Review Your Country Blocking in Four Steps

If you are not sure whether your site has country blocking switched on, it takes around ten minutes to find out and correct it.

  1. Audit. Open your security plugin's settings, and any firewall service in front of your site, and look for sections labelled country blocking, geo-blocking or blocked regions.
  2. Verify. Use the URL Inspection tool in Google Search Console to run a live test on your homepage and confirm that Google can fetch it.
  3. Scope. If you keep any country rule, change it from "entire site" to "login page only", and make sure no EU country is on the list for the public site.
  4. Monitor. Over the following fortnight, watch for payment confirmations arriving normally and for enquiries from overseas returning, and check Search Console's page indexing report for any drop.

Where This Leaves You

Country blocking is sold as an easy win, and for your security log it is. For your customers, your search rankings and your checkout, it is a filter that cannot distinguish a threat from a regular on holiday, a buyer in Toronto or the crawler that decides whether you appear in Google at all.

Protecting the login page and letting the server deal with abusive behaviour gives you most of the security benefit with none of the lost business. If your site was set up years ago and nobody remembers what was ticked, a ten-minute review is a sensible thing to put in the diary this week.

Frequently Asked Questions

Should I block other countries from my WordPress website?

For most small business sites, no. Blocking whole countries turns away customers who are travelling, overseas buyers, Google's crawler and payment notifications from abroad, while attackers simply switch to a server in an allowed country. If you want a geographic rule, apply it to your login page only and rely on rate limiting, two-factor authentication and server-level protection for the rest.

Will blocking the United States hurt my Google rankings?

Very likely. Google's documentation says Googlebot's default crawler addresses appear to be based in the USA, and at least one major WordPress security plugin states that its country blocking will block Googlebot if the USA is blocked. Letting Googlebot through while blocking US visitors is not a safe fix either, because Google has said that showing its crawler content that users in the same country cannot see goes against its guidelines.

Is it legal to block EU visitors from my website?

The EU Geo-blocking Regulation restricts traders from blocking or limiting a customer's access to their website because of nationality or place of residence within the EU. The CCPC's guidance lists exceptions only where an EU or national legal requirement obliges the block, and security is not among them. If your trading website blocks other EU countries, get advice from a solicitor on your specific situation.

Why are my WooCommerce orders stuck as pending after changing security settings?

One common cause is that your security settings are blocking notifications from your payment provider. Providers such as Stripe confirm payments by sending a message from their own servers, which run in data centres outside Ireland. If your site only allows Irish traffic, those confirmations can be rejected, leaving paid orders marked as pending. Remove the country rule, or scope it to the login page, and verify that new orders update correctly.

Does country blocking stop hackers?

It reduces the volume of automated attempts from the blocked countries, which makes security logs quieter. It does not stop a determined attacker, because the tools used for most attacks run on compromised computers and cloud servers located all over the world, including in Ireland and elsewhere in Europe. Behaviour-based defences such as login rate limiting and server-level intrusion prevention protect you regardless of where the attack comes from.

How do I check whether Google can still reach my website?

Open Google Search Console, enter your homepage address into the URL Inspection tool and run a live test. If Google reports that it cannot fetch the page, or returns an access denied or blocked error, check your security plugin and any firewall service for country or bot blocking rules. The page indexing report will also show whether pages are dropping out of Google over time.

Sources

IO
Ian O'ReillyOperations Director, Web60

Ian oversees Web60's hosting infrastructure and operations. Responsible for the uptime, security, and performance of every site on the platform, he writes about the operational reality of keeping Irish business websites fast, secure, and online around the clock.

More by Ian O'Reilly →

Ready to get your business online?

Describe your business. AI builds your website in 60 seconds.

Build My Website Free →
Buy NowTry Free
Country Blocking on Your Website: Who It Locks Out | Web60