> For the complete documentation index, see [llms.txt](https://docs.link11.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.link11.com/product-guides/web-ddos/interface/blocklist.md).

# Blocklist

## **DDoS Blocklist**

This page displays a map, showing the source countries for blocked traffic.

<figure><img src="/files/RLWGyO4ejRRKtmgadZUn" alt=""><figcaption></figcaption></figure>

***

Below the map is the **Blocklist**, which shows all IPs that are currently being blocked.

<figure><img src="/files/EsOAtvoflkXZfWusGX3r" alt=""><figcaption></figcaption></figure>

**Date:** The date when the IP address was blocked.

**Attacker IP:** The attacking IP address.

**Attacker ISP:** The Internet Service Provider of the attacker.

**Country:** The country of the IP address

**Status:** Current status (Blocked or Unblocked)

## How IPs are blocked

During a DDoS attack, Web DDoS blocks hostile IPs by adding them to the Blocklist. Each blocking action includes a timer; the length of the timer depends on the severity of the IP's behavior.&#x20;

Unless a user removes it (as discussed below), each IP remains on the Blocklist until its timer expires. This remains true even when the system drops out of [Attack Mode](/product-guides/web-ddos/introduction.md#three-modes-of-security-posture).&#x20;

### The Unblock button

When the **Unblock** button is selected, all currently-blocked IPs are unblocked.&#x20;

If this is desired, it is not necessary to wait until the attack is over. Selecting the button will reset all blocked IPs, even during an attack.

{% hint style="warning" %}
The Unblock action does not "stick" to an IP. The button removes current blocks, but it does not begin a grace period or whitelist any traffic sources. \
\
If an IP continues to act maliciously, it will immediately be blocked again.
{% endhint %}

&#x20;
