In the article, quite a few listed sources of traffic would simply be completely unable to access the server if the author could get away with a geoblock.
In the article, quite a few listed sources of traffic would simply be completely unable to access the server if the author could get away with a geoblock.
But the numbers don't lie. In my case, I locked down to a fairly small group of European countries and the server went down from about 1500 bot scans per day down to 0.
The tradeoff is just too big to ignore.
Every country has (at the very least) a few bad actors, it's a small handful of countries that actively protect their bad actors from any sort of accountability or identification.
It's funny observing their tactics though. On the whole, spammers have moved from bare domain to various prefixes like @outreach.domain, @msg.domain, @chat.domain, @mail.domain, @contact.domain and most recently @email.domain.
It's also interesting watching the common parts before the @. Most recently I've seen a lot of marketing@, before that chat@ and about a month after I blocked that chat1@. I mostly block *@domain though, so I'm less aware of these trends.
Or I might try and put up Anubis only for them.
I got accidentally locked out from my server when I connected over Starlink that IP-maps to the US even though I was physically in Greece.
As a practical advice, I would use a blocklist for commerce websites, and allowlist for infra/personal.
In the end I found another online store, paid $74, and got the device. So the better store lost the sale due to blocking non-US orders.
I don't know how much of a corner case this is.
I'm not saying don't block, just saying be aware of the unintended blocks and weigh them.