What Ron said. The IPs change, permanently blocking thousands (other than by appropriate country blocking) is not the correct way to go about defense. ON THE OTHER HAND, I do permanently block a few, but with periodic checks to see if they ever go legit. Interestingly, it’s usually ones from Russia that remain on blacklists seemingly forever (I have one Russian IP on my list that’s going on 4 months blacklisted by various folks such as Spamhaus). It’s probably a waste of my time but I try to curate my permanently blocked IPs by occasionally checking them against blacklists using services such as
https://ipindetail.com/ip-blacklist-checker/
I also occasionally add truly obnoxious IP ranges to my .htaccess file, but only for a 4 week span. This is done manually, and again, might be a waste of time. But it feels good over morning coffee.
What’s actually needed is a Wordfence feature. So here comes a feature request. FEATURE REQUEST: Please provide us with a click option in the “Blocked IPs” list that checks an individual IP against the Wordfence Real Time Security Network and WAF, so we can ascertain if an IP that slipped past Wordfence primary protections can now be unblocked. This would be a fantastic Premium feature, perhaps secured in some way against abuse.
MTN