I'm curious how people handle blacklisted IP addresses in practice. Do you review and manage them manually, maintain internal scripts, import threat intelligence feeds, or rely on a commercial security or email-filtering service? I'm especially interested in how you keep lists updated and prevent them from becoming stale or too large.
5 Answers
It really depends on what you’re protecting. Email, web applications, and general network access have different requirements. For web attacks, one approach is to detect repeated suspicious requests—such as injection attempts—then temporarily add the source address to a firewall list. The block expires naturally after a month or two, which helps avoid keeping stale entries forever.
For a small setup, we add addresses to the blacklist and leave them there unless someone reports a legitimate service being blocked. It’s simple, although you do need a way to handle false positives when they eventually appear.
We use a shell script to update the firewall with a maintained set of addresses every night. If a task is repetitive and predictable, scripting it saves a lot of time and avoids manual mistakes.
Automation is the practical approach. We pull known malicious infrastructure into our firewall drop policies on a schedule, and our security tools can also push indicators into watch or block lists. Those changes flow into firewall and cloud rules every few minutes.
For larger environments, a commercial security platform can handle much of this through threat intelligence, antivirus, and automated analysis. We stopped maintaining manual blacklists years ago and let the platform manage the feeds and enforcement.

Related Questions
Can't Load PhpMyadmin On After Server Update
Redirect www to non-www in Apache Conf
How To Check If Your SSL Cert Is SHA 1
Windows TrackPad Gestures