If you want to restrict access to a specific folder on your website, you can use rules in the .htaccess file to allow or block specific IP addresses. This is useful for securing sensitive directories or limiting access to internal resources.
Table of Contents
What .htaccess can do in this case
The .htaccess file allows you to:
- Allow access only from specific IP addresses
- Block access from unwanted IPs
- Restrict access to an entire directory
- Control access at folder level without changing application code
How to allow only specific IP addresses
To allow access only for selected IPs and block everyone else, place the following rules inside the .htaccess file located in the directory you want to protect:
Order Deny,Allow
Deny from All
Allow from YOUR_IP_ADDRESS You can add multiple allowed IPs by repeating the Allow from line.
How to block specific IP addresses
If you want to block only certain IPs while allowing everyone else:
Order Allow,Deny
Allow from All
Deny from BAD_IP_ADDRESS You can also list multiple blocked IPs if needed.
How it works
- The file is read by the web server when someone tries to access the folder
- Rules are applied in order (depending on
Order Allow,DenyorOrder Deny,Allow) - Access is either granted or rejected before the request reaches your application (e.g. WordPress)
Important notes
- These rules affect only the directory where the
.htaccessfile is placed and all subdirectories below it - Incorrect configuration may block access to your entire site
- Modern Apache versions may prefer
Require ipsyntax instead ofAllow/Deny, depending on server configuration - Always test changes carefully to avoid locking yourself out
Summary
Using .htaccess allow/deny rules is a simple way to control access to a directory without modifying application code. It is commonly used for securing admin folders, backups, or private areas of a website.