Skip to content

Security (PRO)

Stop Brute-Force Attacks on Magic Link Logins

If an IP address hammers your login form with failed attempts, you want it stopped before it wastes resources or reaches a sensitive account. Magic Link PRO's Brute Force Protection does exactly that: it temporarily bans an IP address once it fails to log in too many times inside a short window. You configure it under Magic Link → Settings → Security.

Brute Force Protection (PRO)

PRO feature

Brute Force Protection is part of Magic Link PRO and lives on the Security settings tab, which is only available with PRO.

  1. Go to Magic Link → Settings → Security.
  2. Open Brute Force Protection and turn on Enable brute force protection.
  3. Set Max attempts — how many failed logins an IP gets before it is banned (default 10).
  4. Set Time window — the number of minutes those attempts are counted over (default 5).
  5. Set Ban duration — how many minutes the IP is blocked once the limit is reached (default 60).
  6. Save the settings.

The plugin states the rule as a sentence: "Block the IP address for {ban_duration} minutes when it fails to login {max_attempts} times in {time_window} minutes." When an IP crosses the limit inside the window, it is banned for the ban duration. Normal users request a link, receive it, and log in as usual, while an abusive source is stopped after a few tries.

Setting to Stop Brute Force Attacks on Magic Link Logins

Settings reference

Setting Default What it does
Enable brute force protection Off Turns the IP ban rule on.
Max attempts 10 Failed logins from one IP before it is banned.
Time window 5 minutes The period failed attempts are counted over.
Ban duration 60 minutes How long the IP stays blocked once banned.

For a related layer, the PRO IP Check setting (also under Magic Link → Settings → Security) requires that a Magic Link is used from the same IP address that requested it. If a link is opened from a different IP, it is refused, which blocks stolen or forwarded links from being used elsewhere. To go further and allow only specific addresses or ranges, see Restrict Magic Links by IP address.

Why it matters

Without protection, repeated abuse can waste server resources, fill inboxes with unwanted messages, make your login form feel unreliable, and increase risk for sensitive member areas. Brute Force Protection is most valuable on membership websites, customer portals, online stores, and any site with private user data.

Conclusion

Enable Brute Force Protection to ban abusive IP addresses automatically, and pair it with IP Check so links only work from where they were requested. Set the thresholds to match your traffic so genuine users are never caught. To reduce request floods before they reach the failure stage, see Slow down repeated Magic Link requests.

FAQs

Magic Link PRO's Brute Force Protection counts failed logins per IP address. When an IP fails to log in more than the allowed number of times inside the time window, the plugin bans that IP for the ban duration. The defaults ban an IP for 60 minutes after 10 failed attempts in 5 minutes.

Is Brute Force Protection free or PRO?

Brute Force Protection is a PRO feature. It sits on the Security settings tab, which is only available in Magic Link PRO. The free version does not include the automatic IP ban rule.

What are the default brute-force settings?

By default an IP is blocked for 60 minutes once it fails to log in 10 times within a 5-minute window. You can change Max attempts, Time window, and Ban duration under Magic Link → Settings → Security to match your site's traffic.

Will Brute Force Protection block legitimate users?

Rarely, if the thresholds are set sensibly. Only failed login attempts count, so a normal user who requests a link and logs in is never affected. If real users share an IP or retry often, raise Max attempts or shorten the Time window so genuine activity stays under the limit.

What is the difference between Brute Force Protection and IP Check?

Brute Force Protection bans an IP after too many failed attempts. IP Check instead requires that a link is used from the same IP that requested it, so a forwarded or stolen link fails when opened elsewhere. Both are PRO and live under Magic Link → Settings → Security.

Was this page helpful?