Security (PRO)

How Do I Stop Brute Force Attacks on Magic Link Logins?

Quick Answer

Brute Force Protection (PRO) temporarily bans an IP address after too many failed attempts, and IP Control (PRO) can require that a link is used from the same IP that requested it. Both live under Settings → Security.

Brute Force Protection (PRO)

Go to Settings → Security → Brute Force Protection. Set:

  • Max attempts — how many attempts an IP gets before it is banned.
  • Time window — the period those attempts are counted over.
  • Ban duration — how long the IP is blocked once the limit is reached.

When an IP crosses the limit inside the window, it is banned for the ban duration. Normal users request a link, receive it, and log in as usual, while an abusive source is stopped after a few tries.

IP Control (PRO)

Go to Settings → Security → IP Control. When enabled, a Magic Link only works from the same IP address that requested it. If a link is opened from a different IP, it is refused. This blocks stolen or forwarded links from being used elsewhere.

Why It Matters

Without protection, repeated abuse can:

  • Waste server resources
  • Fill inboxes with unwanted messages
  • Make your login form feel unreliable
  • Increase risk for sensitive member areas

Best For

  • Membership websites
  • Customer portals
  • Online stores
  • Any site with private user data

Setting to Stop Brute Force Attacks on Magic Link Logins

Was this page helpful?

Previous
Throttle repeated requests