Aftermath of spam attack! Need help with releasing IPs, and mass-blocking of profiles of a domain

I blocked many IPs after a massive spam attack. Now some people with genuine accounts aren’t able to login. It says “You can’t login with that IP”. How do I correct this?

Also, do blocked IPs get released after a few days? In my previous forum, I had configured it to 14 days.

And I have a few domains to the blocked list, that was responsible for many spammer profiles. So new registrations under these domains won’t be possible. But a quick domain search under Users returned many dormant profiles using that domain. Anyway I can mass-flush these profiles that belong to the blocked domain?

Go to /admin/logs/screened_ip_addresses.

After 1 year by default, configurable on settings.

Any dormant accounts are automatically removed after 2 years.

3 Likes

Are you using cloudflare and not the cloudflare template? Does your IP address match the one that Discourse sees for you or does it display the IP address of a cloudflare server?

i can’t help with releasing IP’s and blocked users within the forum but surely i can help you with the firewall if you are using Cloudflare.

I was able to release some IPs and that made things better. Now just exploring Akismet for spam control.

External check helps more rather than just discourse checks in place.
Discourse inbuilt checks can be used as a level 2 defense.