SeenSecure Help

Anti-Bot Protection: Defensa Multicapa

Anti-Bot Protection: Multi-Layer Defense

Anti-Bot-Schutz: Mehrschichtige Verteidigung

Protection Anti-Bot : Défense Multicouche

Sistema de protección multicapa contra bots automatizados, scrapers y tráfico no humano mediante análisis de User-Agent, fingerprinting y verificación DNS.

Multi-layer protection system against automated bots, scrapers, and non-human traffic through User-Agent analysis, fingerprinting, and DNS verification.

Mehrschichtiges Schutzsystem gegen automatisierte Bots, Scraper und nicht-menschlichen Datenverkehr durch User-Agent-Analyse, Fingerprinting und DNS-Verifikation.

Système de protection multicouche contre les bots automatisés, les scrappers et le trafic non humain via l'analyse User-Agent, l'empreinte numérique et la vérification DNS.

🔒 Modo Privado🔒 Private Mode🔒 Privater Modus🔒 Mode Privé

👋 ¿Qué es? Un interruptor único, separado de las 5 capas de Anti-Bot, pensado para sitios que no deben aparecer nunca en buscadores ni ser accedidos por ningún bot: intranets, entornos de staging, o webs estrictamente privadas. A diferencia del resto del módulo Anti-Bot — que está diseñado para dejar pasar a Google, Bing y otros crawlers legítimos verificados — Modo Privado no hace ninguna excepción: bloquea absolutamente todo lo que se identifique como bot, incluidos los motores de búsqueda "buenos". 👋 What is it? A single switch, separate from the 5 Anti-Bot layers, designed for sites that must never appear in search engines or be accessed by any bot: intranets, staging environments, or strictly private sites. Unlike the rest of the Anti-Bot module — which is designed to let Google, Bing, and other verified legitimate crawlers through — Private Mode makes no exceptions: it blocks absolutely anything identified as a bot, including "good" search engines. 👋 Was ist das? Ein einzelner Schalter, getrennt von den 5 Anti-Bot-Schichten, für Websites, die niemals in Suchmaschinen erscheinen oder von Bots aufgerufen werden dürfen: Intranets, Staging-Umgebungen oder streng private Websites. Im Gegensatz zum Rest des Anti-Bot-Moduls — das darauf ausgelegt ist, Google, Bing und andere verifizierte legitime Crawler durchzulassen — macht der Private Modus keine Ausnahmen: Er blockiert alles, was als Bot erkannt wird, einschließlich der "guten" Suchmaschinen. 👋 Qu'est-ce que c'est ? Un interrupteur unique, distinct des 5 couches Anti-Bot, conçu pour les sites qui ne doivent jamais apparaître dans les moteurs de recherche ni être accessibles par un bot : intranets, environnements de test ou sites strictement privés. Contrairement au reste du module Anti-Bot — conçu pour laisser passer Google, Bing et autres crawlers légitimes vérifiés — le Mode Privé ne fait aucune exception : il bloque absolument tout ce qui est identifié comme un bot, y compris les "bons" moteurs de recherche.

🧩 ¿Qué hace al activarlo?What does it do when enabled?Was passiert bei Aktivierung?Que fait-il une fois activé ?

Tres cosas a la vez: (1) robots.txt pasa a Disallow: / para todos los user-agents, (2) cada página envía la cabecera HTTP X-Robots-Tag: noindex, nofollow, noarchive y una etiqueta <meta name="robots"> equivalente, y (3) el firewall bloquea en el acto cualquier petición cuyo User-Agent coincida con un bot/crawler conocido o con patrones genéricos de bot (bot, crawler, spider, scraper...).

Three things at once: (1) robots.txt switches to Disallow: / for every user-agent, (2) every page sends the X-Robots-Tag: noindex, nofollow, noarchive HTTP header plus an equivalent <meta name="robots"> tag, and (3) the firewall instantly blocks any request whose User-Agent matches a known bot/crawler or generic bot patterns (bot, crawler, spider, scraper...).

Drei Dinge gleichzeitig: (1) robots.txt wechselt für alle User-Agents zu Disallow: /, (2) jede Seite sendet den HTTP-Header X-Robots-Tag: noindex, nofollow, noarchive sowie ein entsprechendes <meta name="robots">-Tag, und (3) die Firewall blockiert sofort jede Anfrage, deren User-Agent mit einem bekannten Bot/Crawler oder generischen Bot-Mustern übereinstimmt (bot, crawler, spider, scraper...).

Trois choses à la fois : (1) robots.txt passe à Disallow: / pour tous les user-agents, (2) chaque page envoie l'en-tête HTTP X-Robots-Tag: noindex, nofollow, noarchive ainsi qu'une balise <meta name="robots"> équivalente, et (3) le pare-feu bloque instantanément toute requête dont le User-Agent correspond à un bot/crawler connu ou à des motifs génériques de bot (bot, crawler, spider, scraper...).

⚠️ Importante: efecto en el SEOImportant: SEO impactWichtig: SEO-AuswirkungImportant : impact SEO

Mientras esté activo, tu web dejará de aparecer en Google, Bing y cualquier buscador, y las páginas ya indexadas empezarán a desaparecer de los resultados. Actívalo solo si el sitio es realmente privado (intranet, staging, demo interna) y nunca en una web pública que quiera recibir tráfico de búsqueda.

While active, your site will stop appearing in Google, Bing, and any search engine, and already-indexed pages will start disappearing from results. Only enable it if the site is genuinely private (intranet, staging, internal demo) and never on a public site that wants search traffic.

Solange aktiv, verschwindet deine Website aus Google, Bing und jeder Suchmaschine, und bereits indexierte Seiten verschwinden nach und nach aus den Ergebnissen. Aktiviere es nur, wenn die Website wirklich privat ist (Intranet, Staging, interne Demo), niemals bei einer öffentlichen Website, die Suchverkehr erhalten möchte.

Tant qu'il est actif, votre site cessera d'apparaître sur Google, Bing et tout moteur de recherche, et les pages déjà indexées commenceront à disparaître des résultats. Activez-le uniquement si le site est réellement privé (intranet, staging, démo interne), jamais sur un site public qui souhaite du trafic de recherche.

🎯 ¿Dónde se activa?Where is it enabled?Wo wird es aktiviert?Où l'activer ?

En Firewall → Anti-Bot, en la tarjeta morada "🔒 Modo Privado" situada justo encima de las 5 capas. Al marcar la casilla, el plugin pide confirmación explícita antes de aplicarlo, precisamente por su efecto sobre el SEO.

In Firewall → Anti-Bot, on the purple "🔒 Private Mode" card located right above the 5 layers. Checking the box triggers an explicit confirmation prompt before it applies, precisely because of its SEO impact.

In Firewall → Anti-Bot, auf der lila Karte "🔒 Privater Modus" direkt über den 5 Schichten. Das Aktivieren der Checkbox löst wegen der SEO-Auswirkung eine explizite Bestätigungsabfrage aus.

Dans Firewall → Anti-Bot, sur la carte violette "🔒 Mode Privé" située juste au-dessus des 5 couches. Cocher la case déclenche une confirmation explicite avant application, précisément en raison de son impact SEO.

🔍 Capa 1: Blocklist de User-Agent🔍 Layer 1: User-Agent Blocklist🔍 Schicht 1: User-Agent-Blockliste🔍 Couche 1 : Liste noire User-Agent

👋 ¿Qué es un User-Agent? Cuando visitas una web, tu navegador se presenta automáticamente: "Hola, soy Chrome 120 en Windows". Esa presentación se llama User-Agent. Los bots también se presentan, pero a menudo dicen la verdad: "Hola, soy sqlmap", "Hola, soy curl". Esta capa reconoce esos nombres y bloquea al visitante. 👋 What is a User-Agent? When you visit a website, your browser automatically introduces itself: "Hi, I'm Chrome 120 on Windows". This introduction is called User-Agent. Bots also introduce themselves, and they often tell the truth: "Hi, I'm sqlmap", "Hi, I'm curl". This layer recognizes those names and blocks the visitor. 👋 Was ist ein User-Agent? Wenn du eine Website besuchst, stellt sich dein Browser automatisch vor: "Hallo, ich bin Chrome 120 unter Windows". Diese Vorstellung heißt User-Agent. Bots stellen sich auch vor, und sie sagen oft die Wahrheit: "Hallo, ich bin sqlmap", "Hallo, ich bin curl". Diese Schicht erkennt diese Namen und blockiert den Besucher. 👋 Qu'est-ce qu'un User-Agent ? Lorsque vous visitez un site web, votre navigateur se présente automatiquement : "Bonjour, je suis Chrome 120 sur Windows". Cette présentation s'appelle User-Agent. Les bots aussi se présentent, et ils disent souvent la vérité : "Bonjour, je suis sqlmap", "Bonjour, je suis curl". Cette couche reconnaît ces noms et bloque le visiteur.

Ejemplo: Visita normalExample: Normal visitBeispiel: Normaler BesuchExemple : Visite normale

Un usuario real llega desde Google. Su navegador envía: Mozilla/5.0 (Windows NT 10.0; Win64; x64) Chrome/120. No hay coincidencia con la blocklist → acceso permitido.

A real user arrives from Google. Their browser sends: Mozilla/5.0 (Windows NT 10.0; Win64; x64) Chrome/120. No blocklist match → access granted.

Ein echter Benutzer kommt von Google. Sein Browser sendet: Mozilla/5.0 (Windows NT 10.0; Win64; x64) Chrome/120. Kein Blocklist-Treffer → Zugriff erlaubt.

Un vrai utilisateur arrive depuis Google. Son navigateur envoie : Mozilla/5.0 (Windows NT 10.0; Win64; x64) Chrome/120. Aucune correspondance → accès autorisé.

Ejemplo: Ataque detectadoExample: Attack detectedBeispiel: Angriff erkanntExemple : Attaque détectée

Un atacante ejecuta sqlmap contra tu web. El User-Agent contiene "sqlmap". La blocklist lo reconoce → acceso bloqueado al instante, antes de que toque cualquier página.

An attacker runs sqlmap against your site. The User-Agent contains "sqlmap". The blocklist recognizes it → instant block before it touches any page.

Ein Angreifer führt sqlmap gegen deine Seite aus. Der User-Agent enthält "sqlmap". Die Blockliste erkennt es → sofortige Blockierung, bevor eine Seite berührt wird.

Un attaquant exécute sqlmap contre votre site. L'User-Agent contient "sqlmap". La liste noire le reconnaît → blocage instantané avant qu'il ne touche une page.

⚠️ ImportanteImportantWichtigImportant

Algunos bots mienten en su User-Agent y fingen ser Chrome o Googlebot. Para detectarlos, necesitas las Capas 2 y 3.

Some bots lie about their User-Agent and pretend to be Chrome or Googlebot. To catch them, you need Layers 2 and 3.

Manche Bots lügen über ihren User-Agent und geben vor, Chrome oder Googlebot zu sein. Um sie zu erkennen, benötigst du Schicht 2 und 3.

Certains bots mentent sur leur User-Agent et prétendent être Chrome ou Googlebot. Pour les détecter, vous avez besoin des Couches 2 et 3.

La primera capa de protección analiza las cadenas de User-Agent enviadas por los navegadores y clientes para identificar patrones conocidos de bots y herramientas automatizadas.

The first protection layer analyzes User-Agent strings sent by browsers and clients to identify known patterns of bots and automated tools.

Die erste Schutzschicht analysiert die User-Agent-Zeichenfolgen, die von Browsern und Clients gesendet werden, um bekannte Muster von Bots und automatisierten Tools zu identifizieren.

La première couche de protection analyse les chaînes User-Agent envoyées par les navigateurs et clients pour identifier les motifs connus de bots et d'outils automatisés.

Mecanismo de DetecciónDetection MechanismErkennungsmechanismusMécanisme de Détection

  • Análisis de Patrones: Comparación contra lista de patrones conocidos
  • Pattern Analysis: Comparison against a list of known patterns
  • Musteranalyse: Vergleich mit einer Liste bekannter Muster
  • Analyse de motifs : Comparaison avec une liste de motifs connus
  • Blocklist Predefinida: Patrones de bots comunes pre-cargados
  • Predefined Blocklist: Pre-loaded common bot patterns
  • Vordefinierte Blockliste: Vorinstallierte häufige Bot-Muster
  • Liste noire prédéfinie : Motifs de bots courants préchargés
  • Blocklist Personalizada: Patrones adicionales definidos por el administrador
  • Custom Blocklist: Additional patterns defined by the administrator
  • Benutzerdefinierte Blockliste: Zusätzliche vom Administrator definierte Muster
  • Liste noire personnalisée : Motifs supplémentaires définis par l'administrateur
  • Validación de Protocolo: Detección de protocolos obsoletos
  • Protocol Validation: Detection of obsolete protocols
  • Protokollvalidierung: Erkennung veralteter Protokolle
  • Validation de protocole : Détection des protocoles obsolètes

Tipos de Patrones DetectadosTypes of Detected PatternsArten erkannter MusterTypes de motifs détectés

CategoríaEjemplosRiesgoDetección
ScannersHerramientas de análisisAltoPatrones específicos
BotsAutomatización webMedioLibrerías comunes
ScrapersExtracción de datosAltoFrameworks conocidos
Herramientas CLILínea de comandosMedioClientes HTTP
CategoryExamplesRiskDetection
ScannersAnalysis toolsHighSpecific patterns
BotsWeb automationMediumCommon libraries
ScrapersData extractionHighKnown frameworks
CLI ToolsCommand lineMediumHTTP clients
KategorieBeispieleRisikoErkennung
ScannerAnalysetoolsHochSpezifische Muster
BotsWebautomatisierungMittelHäufige Bibliotheken
ScraperDatenextraktionHochBekannte Frameworks
CLI-ToolsKommandozeileMittelHTTP-Clients
CatégorieExemplesRisqueDétection
ScannersOutils d'analyseÉlevéMotifs spécifiques
BotsAutomatisation webMoyenBibliothèques courantes
ScrapersExtraction de donnéesÉlevéFrameworks connus
Outils CLILigne de commandeMoyenClients HTTP

Configuración AdicionalAdditional ConfigurationZusätzliche KonfigurationConfiguration supplémentaire

  • Verificación HTTP/1.0: Bloqueo de protocolos antiguos
  • HTTP/1.0 Verification: Blocking of old protocols
  • HTTP/1.0-Prüfung: Blockierung alter Protokolle
  • Vérification HTTP/1.0 : Blocage des protocoles anciens
  • Análisis de Idioma: Detección de idiomas ausentes
  • Language Analysis: Detection of missing languages
  • Sprachanalyse: Erkennung fehlender Sprachen
  • Analyse de langue : Détection des langues manquantes
  • Validación Geo-Idioma: Inconsistencias geográficas
  • Geo-Language Validation: Geographic inconsistencies
  • Geo-Sprachvalidierung: Geografische Inkonsistenzen
  • Validation Géo-Langue : Incohérences géographiques
  • Blocklist Personalizada: Patrones adicionales
  • Custom Blocklist: Additional patterns
  • Benutzerdefinierte Blockliste: Zusätzliche Muster
  • Liste noire personnalisée : Motifs supplémentaires
Información: La capa 1 bloquea aproximadamente el 85% del tráfico automatizado básico con mínimo impacto en rendimiento. Info: Layer 1 blocks approximately 85% of basic automated traffic with minimal performance impact. Info: Schicht 1 blockiert etwa 85% des grundlegenden automatisierten Datenverkehrs mit minimalen Leistungseinbußen. Info : La couche 1 bloque environ 85% du trafic automatisé de base avec un impact minimal sur les performances.

🖥️ Capa 2: Bot Fingerprint Analyzer🖥️ Layer 2: Bot Fingerprint Analyzer🖥️ Schicht 2: Bot-Fingerprint-Analyzer🖥️ Couche 2 : Analyseur d'empreinte de Bot

🤔 ¿Qué pasa si un bot miente en su User-Agent? Algunos bots avanzados no usan herramientas como curl. Usan navegadores reales (Chrome, Firefox) pero en modo "sin cabeza" (headless) — funcionan sin pantalla, sin hacer ruido. La Capa 1 no los detecta porque su User-Agent es idéntico al de un Chrome real. Para eso sirve la Capa 2: les hace pruebas para ver si son humanos o máquinas. 🤔 What if a bot lies about its User-Agent? Some advanced bots don't use tools like curl. They use real browsers (Chrome, Firefox) but in "headless" mode — they run without a screen, without making noise. Layer 1 can't detect them because their User-Agent is identical to a real Chrome. That's what Layer 2 is for: it runs tests to determine if they're human or machine. 🤔 Was passiert, wenn ein Bot über seinen User-Agent lügt? Einige fortgeschrittene Bots verwenden keine Tools wie curl. Sie verwenden echte Browser (Chrome, Firefox) im "Headless"-Modus — sie laufen ohne Bildschirm, ohne Lärm zu machen. Schicht 1 kann sie nicht erkennen, weil ihr User-Agent identisch mit einem echten Chrome ist. Dafür ist Schicht 2 da: sie führt Tests durch, um festzustellen, ob sie menschlich oder maschinell sind. 🤔 Que se passe-t-il si un bot ment sur son User-Agent ? Certains bots avancés n'utilisent pas d'outils comme curl. Ils utilisent de vrais navigateurs (Chrome, Firefox) mais en mode "headless" — ils fonctionnent sans écran, sans faire de bruit. La Couche 1 ne peut pas les détecter car leur User-Agent est identique à celui d'un vrai Chrome. C'est là que la Couche 2 intervient : elle effectue des tests pour déterminer s'ils sont humains ou machines.

🧑 Humano realReal humanEchter MenschHumain réel

Tiene plugins como Adobe Reader, una pantalla de 1920×1080, su navegador renderiza WebGL correctamente, tarda 2 segundos en llenar un formulario. Puntuación: 95/100 (humano).

Has plugins like Adobe Reader, a 1920×1080 screen, renders WebGL correctly, takes 2 seconds to fill a form. Score: 95/100 (human).

Hat Plugins wie Adobe Reader, einen 1920×1080-Bildschirm, rendert WebGL korrekt, braucht 2 Sekunden zum Ausfüllen eines Formulars. Punktzahl: 95/100 (menschlich).

A des plugins comme Adobe Reader, un écran 1920×1080, rend le WebGL correctement, met 2 secondes à remplir un formulaire. Score : 95/100 (humain).

🤖 Bot headlessHeadless botHeadless-BotBot headless

Sin plugins, sin WebGL, resolución 800×600, responde en 0.05 segundos, no genera fingerprint de canvas. Puntuación: 15/100 (bot). Bloqueado.

No plugins, no WebGL, 800×600 resolution, responds in 0.05 seconds, no canvas fingerprint generated. Score: 15/100 (bot). Blocked.

Keine Plugins, kein WebGL, 800×600 Auflösung, Antwort in 0,05 Sekunden, kein Canvas-Fingerprint. Punktzahl: 15/100 (Bot). Blockiert.

Pas de plugins, pas de WebGL, résolution 800×600, répond en 0,05 seconde, pas d'empreinte canvas. Score : 15/100 (bot). Bloqué.

🔍 ¿Qué analiza?What does it analyze?Was wird analysiert?Qu'est-ce qui est analysé ?

Plugins del navegador, resolución de pantalla, renderizado WebGL, canvas fingerprint, orden de headers HTTP, tiempo de respuesta, fuentes del sistema.

Browser plugins, screen resolution, WebGL rendering, canvas fingerprint, HTTP header order, response time, system fonts.

Browser-Plugins, Bildschirmauflösung, WebGL-Rendering, Canvas-Fingerprint, HTTP-Header-Reihenfolge, Antwortzeit, Systemschriftarten.

Plugins du navigateur, résolution d'écran, rendu WebGL, empreinte canvas, ordre des en-têtes HTTP, temps de réponse, polices système.

La segunda capa realiza un análisis profundo de las características del navegador para crear un "fingerprint" único que permite identificar bots sofisticados que intentan imitar navegadores reales.

The second layer performs a deep analysis of browser characteristics to create a unique "fingerprint" that identifies sophisticated bots trying to imitate real browsers.

Die zweite Schicht führt eine tiefgehende Analyse der Browser-Eigenschaften durch, um einen eindeutigen "Fingerabdruck" zu erstellen, der ausgefeilte Bots identifiziert, die versuchen, echte Browser nachzuahmen.

La deuxième couche effectue une analyse approfondie des caractéristiques du navigateur pour créer une "empreinte" unique permettant d'identifier les bots sophistiqués qui tentent d'imiter de vrais navigateurs.

Técnicas de AnálisisAnalysis TechniquesAnalysetechnikenTechniques d'analyse

  • Detección Headless: Identificación de navegadores sin interfaz gráfica
  • Headless Detection: Identification of browsers without a graphical interface
  • Headless-Erkennung: Identifizierung von Browsern ohne grafische Oberfläche
  • Détection Headless : Identification des navigateurs sans interface graphique
  • Canvas Fingerprint: Análisis de renderizado gráfico
  • Canvas Fingerprint: Graphic rendering analysis
  • Canvas-Fingerprint: Analyse der Grafikdarstellung
  • Empreinte Canvas : Analyse du rendu graphique
  • WebGL Renderer: Características de renderizado 3D
  • WebGL Renderer: 3D rendering characteristics
  • WebGL-Renderer: 3D-Rendering-Eigenschaften
  • Rendu WebGL : Caractéristiques de rendu 3D
  • Análisis de Timing: Patrones de tiempo de respuesta
  • Timing Analysis: Response time patterns
  • Timing-Analyse: Reaktionszeitmuster
  • Analyse temporelle : Modèles de temps de réponse
  • Detección de Features: Capacidades del navegador
  • Feature Detection: Browser capabilities
  • Funktionserkennung: Browser-Fähigkeiten
  • Détection de fonctionnalités : Capacités du navigateur

Proceso de ScoringScoring ProcessBewertungsprozessProcessus de notation

  1. Recolección de Datos: Extracción de características del navegador
  2. Data Collection: Extraction of browser characteristics
  3. Datensammlung: Extraktion von Browser-Merkmalen
  4. Collecte de données : Extraction des caractéristiques du navigateur
  5. Análisis Comparativo: Comparación con perfiles conocidos
  6. Comparative Analysis: Comparison with known profiles
  7. Vergleichsanalyse: Vergleich mit bekannten Profilen
  8. Analyse comparative : Comparaison avec des profils connus
  9. Asignación de Puntuación: Cálculo de score de humanidad
  10. Score Assignment: Calculation of humanity score
  11. Punktzuweisung: Berechnung des Menschlichkeits-Scores
  12. Attribution de score : Calcul du score d'humanité
  13. Toma de Decisión: Acción basada en umbral configurado
  14. Decision Making: Action based on configured threshold
  15. Entscheidungsfindung: Aktion basierend auf konfiguriertem Schwellenwert
  16. Prise de décision : Action basée sur le seuil configuré

Características EvaluadasEvaluated CharacteristicsBewertete MerkmaleCaractéristiques évaluées

CategoríaCaracterísticaPesoDetección
Headers HTTPOrden y valoresMedioComparación
PluginsPlugins instaladosAltoDetección
ResoluciónTamaño de pantallaBajoAnálisis
CanvasRenderizado gráficoAltoPruebas
WebGLCapacidades 3DAltoConsultas
CategoryFeatureWeightDetection
HTTP HeadersOrder and valuesMediumComparison
PluginsInstalled pluginsHighDetection
ResolutionScreen sizeLowAnalysis
CanvasGraphic renderingHighTests
WebGL3D capabilitiesHighQueries
KategorieMerkmalGewichtErkennung
HTTP-HeaderReihenfolge und WerteMittelVergleich
PluginsInstallierte PluginsHochErkennung
AuflösungBildschirmgrößeNiedrigAnalyse
CanvasGrafische DarstellungHochTests
WebGL3D-FähigkeitenHochAbfragen
CatégorieCaractéristiquePoidsDétection
En-têtes HTTPOrdre et valeursMoyenComparaison
PluginsPlugins installésÉlevéDétection
RésolutionTaille d'écranFaibleAnalyse
CanvasRendu graphiqueÉlevéTests
WebGLCapacités 3DÉlevéRequêtes
Nota: Esta capa puede detectar bots que usan navegadores headless o intentan imitar características humanas. Note: This layer can detect bots using headless browsers or attempting to mimic human characteristics. Hinweis: Diese Schicht kann Bots erkennen, die headless-Browser verwenden oder versuchen, menschliche Eigenschaften nachzuahmen. Remarque : Cette couche peut détecter les bots utilisant des navigateurs headless ou tentant d'imiter des caractéristiques humaines.

🌐 Capa 3: Verificación de Crawlers🌐 Layer 3: Crawler Verification🌐 Schicht 3: Crawler-Verifikation🌐 Couche 3 : Vérification des Crawlers

La tercera capa confirma que un visitante que dice ser "Googlebot" es realmente Googlebot, evitando que atacantes se hagan pasar por crawler. Verifica la autenticidad de crawlers que se identifican como motores de búsqueda legítimos mediante análisis DNS inverso y validación de identidad.

The third layer verifies the authenticity of crawlers that identify themselves as legitimate search engines through reverse DNS analysis and identity validation.

Die dritte Schicht überprüft die Authentizität von Crawlern, die sich als legitime Suchmaschinen ausgeben, durch Reverse-DNS-Analyse und Identitätsvalidierung.

La troisième couche vérifie l'authenticité des crawlers qui s'identifient comme des moteurs de recherche légitimes via une analyse DNS inversée et une validation d'identité.

Mecanismo de VerificaciónVerification MechanismVerifikationsmechanismusMécanisme de vérification

  1. DNS Inverso: Verificación de IP → dominio
  2. Reverse DNS: Verification of IP → domain
  3. Reverse-DNS: Überprüfung von IP → Domain
  4. DNS inversé : Vérification de IP → domaine
  5. DNS Directo: Verificación de dominio → IP
  6. Forward DNS: Verification of domain → IP
  7. Forward-DNS: Überprüfung von Domain → IP
  8. DNS direct : Vérification de domaine → IP
  9. Validación de Identidad: Confirmación de autenticidad
  10. Identity Validation: Confirmation of authenticity
  11. Identitätsvalidierung: Bestätigung der Authentizität
  12. Validation d'identité : Confirmation de l'authenticité
  13. Comparación de Patrones: Análisis de comportamiento
  14. Pattern Comparison: Behavioral analysis
  15. Mustervergleich: Verhaltensanalyse
  16. Comparaison de motifs : Analyse comportementale

Crawlers VerificadosVerified CrawlersVerifizierte CrawlerCrawlers vérifiés

TipoDescripciónVerificaciónRiesgo
Motores BúsquedaCrawlers indexadoresDNS + ComportamientoBajo
Social MediaBots de redes socialesDNS + HeadersMedio
AnalyticsHerramientas de análisisDNS + PatronesBajo
SEO ToolsHerramientas SEODNS + ComportamientoMedio
TypeDescriptionVerificationRisk
Search EnginesIndexing crawlersDNS + BehaviorLow
Social MediaSocial network botsDNS + HeadersMedium
AnalyticsAnalysis toolsDNS + PatternsLow
SEO ToolsSEO toolsDNS + BehaviorMedium
TypBeschreibungVerifikationRisiko
SuchmaschinenIndexierende CrawlerDNS + VerhaltenNiedrig
Soziale MedienSocial-Media-BotsDNS + HeaderMittel
AnalyticsAnalysetoolsDNS + MusterNiedrig
SEO-ToolsSEO-WerkzeugeDNS + VerhaltenMittel
TypeDescriptionVérificationRisque
Moteurs de rechercheCrawlers d'indexationDNS + ComportementFaible
Réseaux sociauxBots de réseaux sociauxDNS + En-têtesMoyen
AnalyticsOutils d'analyseDNS + MotifsFaible
Outils SEOOutils SEODNS + ComportementMoyen

Detección de FalsificacionesForgery DetectionFälschungserkennungDétection de falsifications

  • IPs Inválidas: Direcciones no asignadas al dominio
  • Invalid IPs: Addresses not assigned to the domain
  • Ungültige IPs: Nicht der Domain zugewiesene Adressen
  • IPs invalides : Adresses non attribuées au domaine
  • Headers Falsos: User-Agent no coincidente
  • Fake Headers: Mismatched User-Agent
  • Gefälschte Header: Nicht übereinstimmender User-Agent
  • En-têtes falsifiés : User-Agent non correspondant
  • Comportamiento Anómalo: Patrones no típicos
  • Anomalous Behavior: Non-typical patterns
  • Anomalies Verhalten: Nicht typische Muster
  • Comportement anormal : Motifs non typiques
  • Tiempo de Respuesta: Velocidad inusual
  • Response Time: Unusual speed
  • Antwortzeit: Ungewöhnliche Geschwindigkeit
  • Temps de réponse : Vitesse inhabituelle

Sistema de CachéCache SystemCache-SystemSystème de cache

  • Caché DNS: Almacenamiento de verificaciones
  • DNS Cache: Storage of verifications
  • DNS-Cache: Speicherung von Überprüfungen
  • Cache DNS : Stockage des vérifications
  • TTL Configurable: Duración del caché
  • Configurable TTL: Cache duration
  • Konfigurierbare TTL: Cache-Dauer
  • TTL configurable : Durée du cache
  • Whitelist: IPs excluidas de verificación
  • Whitelist: IPs excluded from verification
  • Whitelist: Von der Überprüfung ausgeschlossene IPs
  • Liste blanche : IPs exclues de la vérification
  • Invalidación Manual: Limpieza de caché
  • Manual Invalidation: Cache clearing
  • Manuelle Ungültigmachung: Cache-Bereinigung
  • Invalidation manuelle : Nettoyage du cache
Resultado: Esta capa previene que bots falsos se hagan pasar por motores de búsqueda legítimos. Result: This layer prevents fake bots from impersonating legitimate search engines. Ergebnis: Diese Schicht verhindert, dass sich gefälschte Bots als legitime Suchmaschinen ausgeben. Résultat : Cette couche empêche les faux bots de se faire passer pour des moteurs de recherche légitimes.
🤔 Nota importante: 🤔 Important note: 🤔 Wichtiger Hinweis: 🤔 Note importante : Los crawlers legítimos como Googlebot y Bingbot no envían la cabecera Accept-Language y pueden venir desde cualquier país (no solo España). Si la Capa 1 (idioma vacío) o el Geo Blocking los bloquearan, tu web dejaría de aparecer en Google. Por eso, el plugin reconoce estos crawlers por su User-Agent y los salta en esas comprobaciones. Si un atacante finge ser Googlebot ("spoofing"), la Capa 3 (que ves aquí) lo detecta mediante verificación DNS y lo bloquea. Legitimate crawlers like Googlebot and Bingbot do not send the Accept-Language header and may come from any country (not just Spain). If Layer 1 (empty language) or Geo Blocking blocked them, your site would disappear from Google. That is why the plugin recognizes these crawlers by their User-Agent and exempts them from those checks. If an attacker pretends to be Googlebot ("spoofing"), Layer 3 (right here) catches them via DNS verification and blocks them. Legitime Crawler wie Googlebot und Bingbot senden keinen Accept-Language-Header und können aus jedem Land kommen (nicht nur Spanien). Wenn Schicht 1 (leere Sprache) oder Geo-Blocking sie blockieren würden, wäre Ihre Website nicht mehr bei Google auffindbar. Daher erkennt das Plugin diese Crawler an ihrem User-Agent und nimmt sie von diesen Prüfungen aus. Wenn ein Angreifer vorgibt, Googlebot zu sein ("Spoofing"), wird er von Schicht 3 (DNS-Verifikation) erkannt und blockiert. Les crawlers légitimes comme Googlebot et Bingbot n'envoient pas l'en-tête Accept-Language et peuvent venir de n'importe quel pays (pas seulement l'Espagne). Si la couche 1 (langue vide) ou le Geo Blocking les bloquaient, votre site disparaîtrait de Google. C'est pourquoi le plugin reconnaît ces crawlers par leur User-Agent et les exempte de ces vérifications. Si un attaquant se fait passer pour Googlebot ("spoofing"), la couche 3 (ci-dessous) le détecte via la vérification DNS et le bloque.

Dominios PTR por CrawlerPTR Domains by CrawlerPTR-Domains nach CrawlerDomaines PTR par Crawler

CrawlerUser-AgentDominio PTR (DNS inverso)
GooglebotGooglebot.googlebot.com, .google.com
Bingbotbingbot, msnbot.search.msn.com
YandexBotYandexBot.yandex.ru, .yandex.net, .yandex.com
BaiduspiderBaiduspider.baidu.com, .baidu.jp
DuckDuckBotDuckDuckBot.duckduckgo.com
ApplebotApplebot.applebot.apple.com
Facebookfacebookexternalhit, Facebot.facebook.com, .fbsv.net
TwitterTwitterbot.twttr.com, .twitter.com
SemrushBotSemrushBot.semrush.com
AhrefsBotAhrefsBot.ahrefs.com
CrawlerUser-AgentPTR Domain (Reverse DNS)
GooglebotGooglebot.googlebot.com, .google.com
Bingbotbingbot, msnbot.search.msn.com
YandexBotYandexBot.yandex.ru, .yandex.net, .yandex.com
BaiduspiderBaiduspider.baidu.com, .baidu.jp
DuckDuckBotDuckDuckBot.duckduckgo.com
ApplebotApplebot.applebot.apple.com
Facebookfacebookexternalhit, Facebot.facebook.com, .fbsv.net
TwitterTwitterbot.twttr.com, .twitter.com
SemrushBotSemrushBot.semrush.com
AhrefsBotAhrefsBot.ahrefs.com
CrawlerUser-AgentPTR-Domain (Reverse-DNS)
GooglebotGooglebot.googlebot.com, .google.com
Bingbotbingbot, msnbot.search.msn.com
YandexBotYandexBot.yandex.ru, .yandex.net, .yandex.com
BaiduspiderBaiduspider.baidu.com, .baidu.jp
DuckDuckBotDuckDuckBot.duckduckgo.com
ApplebotApplebot.applebot.apple.com
Facebookfacebookexternalhit, Facebot.facebook.com, .fbsv.net
TwitterTwitterbot.twttr.com, .twitter.com
SemrushBotSemrushBot.semrush.com
AhrefsBotAhrefsBot.ahrefs.com
CrawlerUser-AgentDomaine PTR (DNS inversé)
GooglebotGooglebot.googlebot.com, .google.com
Bingbotbingbot, msnbot.search.msn.com
YandexBotYandexBot.yandex.ru, .yandex.net, .yandex.com
BaiduspiderBaiduspider.baidu.com, .baidu.jp
DuckDuckBotDuckDuckBot.duckduckgo.com
ApplebotApplebot.applebot.apple.com
Facebookfacebookexternalhit, Facebot.facebook.com, .fbsv.net
TwitterTwitterbot.twttr.com, .twitter.com
SemrushBotSemrushBot.semrush.com
AhrefsBotAhrefsBot.ahrefs.com

Ejemplo de VerificaciónVerification ExampleVerifizierungsbeispielExemple de Vérification

Caso 1: Googlebot genuinoCase 1: Genuine GooglebotFall 1: Echtes GooglebotCas 1 : Googlebot authentique

IP: 66.249.66.1 UA: Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html) # Paso 1: DNS inverso (PTR) 66.249.66.1 → crawl-66-249-66-1.googlebot.com ✅ Tiene PTR # Paso 2: ¿Termina en .googlebot.com? crawl-66-249-66-1.googlebot.com → ends with .googlebot.com ✅ # Paso 3: DNS directo crawl-66-249-66-1.googlebot.com → 66.249.66.1 ✅ IP coincide # Resultado: ✅ GENUINO

Caso 2: Googlebot falsoCase 2: Fake GooglebotFall 2: Gefälschtes GooglebotCas 2 : Faux Googlebot

IP: 185.220.101.1 UA: Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html) # Paso 1: DNS inverso (PTR) 185.220.101.1 → tor-exit-node.example.org ✅ Tiene PTR # Paso 2: ¿Termina en .googlebot.com? tor-exit-node.example.org → NO ❌ No coincide # Resultado: ❌ FALSO (posible nodo Tor/Proxy)
Impacto en rendimiento: Cada verificación requiere 2 consultas DNS (inversa + directa). El caché integrado (configurable de 1h a 7días) evita consultas repetitivas. Para crawlers legítimos que visitan regularmente, solo la primera solicitud tiene latencia adicional (~50-200ms). Performance impact: Each verification requires 2 DNS lookups (reverse + forward). The built-in cache (configurable from 1h to 7d) prevents repeated lookups. For legitimate crawlers that visit regularly, only the first request has additional latency (~50-200ms). Leistungsauswirkungen: Jede Überprüfung erfordert 2 DNS-Abfragen (reverse + forward). Der integrierte Cache (konfigurierbar von 1h bis 7d) verhindert wiederholte Abfragen. Bei legitimen Crawlern, die regelmäßig besuchen, hat nur die erste Anfrage eine zusätzliche Latenz (~50-200ms). Impact sur les performances : Chaque vérification nécessite 2 requêtes DNS (inverse + directe). Le cache intégré (configurable de 1h à 7j) évite les requêtes répétitives. Pour les crawlers légitimes qui visitent régulièrement, seule la première requête a une latence supplémentaire (~50-200ms).
Solución de problemas:
  • Falsos positivos con Googlebot: Verifica que el servidor resuelva DNS correctamente. Algunos entornos de hosting restringen consultas DNS salientes.
  • False positives with Googlebot: Verify that your server resolves DNS correctly. Some hosting environments restrict outgoing DNS queries.
  • Falschpositive mit Googlebot: Überprüfen Sie, ob Ihr Server DNS korrekt auflöst. Einige Hosting-Umgebungen schränken ausgehende DNS-Abfragen ein.
  • Faux positifs avec Googlebot : Vérifiez que votre serveur résout correctement le DNS. Certains environnements d'hébergement restreignent les requêtes DNS sortantes.
  • Caché DNS: Si un crawler legítimo es erróneamente bloqueado, limpia la caché desde el admin. La caché se invalida automáticamente al cumplir el TTL.
  • DNS Cache: If a legitimate crawler is wrongly blocked, clear the cache from the admin panel. The cache auto-invalidates when TTL expires.
  • DNS-Cache: Wenn ein legitimer Crawler fälschlicherweise blockiert wird, leeren Sie den Cache aus dem Admin-Bereich. Der Cache wird automatisch ungültig, wenn die TTL abläuft.
  • Cache DNS : Si un crawler légitime est bloqué par erreur, videz le cache depuis l'admin. Le cache s'invalide automatiquement à l'expiration du TTL.
  • Whitelist: Añade IPs de servicios que fallen la verificación pero sean legítimos para tu sitio (p.ej., herramientas de monitorización).
  • Whitelist: Add IPs of services that fail verification but are legitimate for your site (e.g., monitoring tools).
  • Whitelist: Fügen Sie IPs von Diensten hinzu, die bei der Überprüfung fehlschlagen, aber für Ihre Website legitim sind (z.B. Überwachungstools).
  • Liste blanche : Ajoutez les IPs des services qui échouent à la vérification mais sont légitimes pour votre site (p. ex., outils de surveillance).

📄 Capa 4: Control de robots.txt📄 Layer 4: robots.txt Control📄 Schicht 4: robots.txt-Steuerung📄 Couche 4 : Contrôle robots.txt

La cuarta capa te permite controlar qué partes de tu sitio pueden rastrear los motores de búsqueda mediante el archivo robots.txt, sin necesidad de editarlo manualmente.

The fourth layer lets you control which parts of your site search engines can crawl via the robots.txt file, without needing to edit it manually.

Die vierte Schicht ermöglicht Ihnen die Steuerung, welche Teile Ihrer Website Suchmaschinen über die robots.txt-Datei crawlen dürfen, ohne sie manuell bearbeiten zu müssen.

La quatrième couche vous permet de contrôler quelles parties de votre site les moteurs de recherche peuvent crawler via le fichier robots.txt, sans avoir à le modifier manuellement.

¿Qué es robots.txt? Es un archivo de texto que se coloca en la raíz de tu sitio web y da instrucciones a los robots de los motores de búsqueda (Googlebot, Bingbot, etc.) sobre qué páginas o secciones pueden o no pueden rastrear e indexar. What is robots.txt? It is a text file placed in the root of your website that gives instructions to search engine robots (Googlebot, Bingbot, etc.) about which pages or sections they can or cannot crawl and index. Was ist robots.txt? Es ist eine Textdatei im Stammverzeichnis Ihrer Website, die Suchmaschinen-Robotern (Googlebot, Bingbot, etc.) Anweisungen gibt, welche Seiten oder Bereiche sie crawlen und indexieren dürfen oder nicht. Qu'est-ce que robots.txt ? C'est un fichier texte placé à la racine de votre site web qui donne des instructions aux robots des moteurs de recherche (Googlebot, Bingbot, etc.) sur les pages ou sections qu'ils peuvent ou ne peuvent pas crawler et indexer.

¿Cómo funciona?How does it work?Wie funktioniert es?Comment ça marche ?

Cuando un motor de búsqueda visita tu sitio, lo primero que hace es buscar el archivo robots.txt en la raíz. Si existe, lo lee y sigue sus instrucciones:

When a search engine visits your site, the first thing it does is look for the robots.txt file in the root. If it exists, it reads it and follows its instructions:

Wenn eine Suchmaschine Ihre Website besucht, sucht sie zuerst nach der robots.txt-Datei im Stammverzeichnis. Wenn sie existiert, liest sie sie und befolgt ihre Anweisungen:

Lorsqu'un moteur de recherche visite votre site, la première chose qu'il fait est de chercher le fichier robots.txt à la racine. S'il existe, il le lit et suit ses instructions :

  1. User-agent: Especifica a qué robot aplican las reglas (por ejemplo, Googlebot para Google, * para todos).
  2. User-agent: Specifies which robot the rules apply to (e.g., Googlebot for Google, * for all).
  3. User-agent: Gibt an, für welchen Roboter die Regeln gelten (z.B. Googlebot für Google, * für alle).
  4. User-agent: Spécifie à quel robot les règles s'appliquent (par exemple, Googlebot pour Google, * pour tous).
  5. Disallow: Indica las rutas que NO debe rastrear. Disallow: /wp-admin/ bloquea todo el panel de administración.
  6. Disallow: Indicates the paths that should NOT be crawled. Disallow: /wp-admin/ blocks the entire admin panel.
  7. Disallow: Gibt die Pfade an, die NICHT gecrawlt werden sollen. Disallow: /wp-admin/ blockiert das gesamte Admin-Panel.
  8. Disallow: Indique les chemins qui NE doivent PAS être crawler. Disallow: /wp-admin/ bloque tout le panneau d'administration.
  9. Allow: Indica las rutas que SÍ puede rastrear (usado para excepciones dentro de un bloqueo).
  10. Allow: Indicates the paths that CAN be crawled (used for exceptions within a block).
  11. Allow: Gibt die Pfade an, die gecrawlt werden DÜRFEN (wird für Ausnahmen innerhalb einer Blockierung verwendet).
  12. Allow: Indique les chemins qui PEUVENT être crawler (utilisé pour les exceptions dans un blocage).
  13. Sitemap: Indica la ubicación del archivo sitemap.xml para ayudar a los buscadores a encontrar tu contenido.
  14. Sitemap: Indicates the location of the sitemap.xml file to help search engines find your content.
  15. Sitemap: Gibt den Speicherort der sitemap.xml-Datei an, um Suchmaschinen bei der Suche nach Ihren Inhalten zu helfen.
  16. Sitemap: Indique l'emplacement du fichier sitemap.xml pour aider les moteurs de recherche à trouver votre contenu.
  17. Crawl-delay: Tiempo de espera (en segundos) entre solicitudes del mismo robot. Útil para servidores con recursos limitados.
  18. Crawl-delay: Wait time (in seconds) between requests from the same robot. Useful for servers with limited resources.
  19. Crawl-delay: Wartezeit (in Sekunden) zwischen Anfragen desselben Roboters. Nützlich für Server mit begrenzten Ressourcen.
  20. Crawl-delay: Temps d'attente (en secondes) entre les requêtes du même robot. Utile pour les serveurs aux ressources limitées.

Plantillas predefinidasPreset templatesVordefinierte VorlagenModèles prédéfinis

El plugin incluye 4 plantillas para cubrir los casos más comunes. Selecciona la que mejor se adapte a tu situación:

The plugin includes 4 templates to cover the most common cases. Select the one that best fits your situation:

Das Plugin enthält 4 Vorlagen für die häufigsten Fälle. Wählen Sie die Vorlage, die am besten zu Ihrer Situation passt:

Le plugin inclut 4 modèles pour couvrir les cas les plus courants. Sélectionnez celui qui correspond le mieux à votre situation :

PlantillaCuándo usarlaEfecto
ProducciónSitio en funcionamiento con contenido públicoPermite rastrear todo el sitio. Opcionalmente puedes marcar bloqueos específicos (wp-admin, etc.)
DesarrolloSitio en desarrollo, staging o con contenido duplicadoBloquea completamente el rastreo (Disallow: /). Ningún motor de búsqueda indexará el sitio.
SEO optimizadoProducción con enfoque en seguridad SEOPermite contenido público pero bloquea wp-admin, wp-json, xmlrpc. Mejor equilibrio.
Máxima indexaciónPrioridad máxima en aparecer en buscadoresPermite a todos los bots (Googlebot, Bingbot, Yandex, DuckDuckBot, etc.) indexar sin restricciones.
TemplateWhen to useEffect
ProductionLive site with public contentAllows crawling the entire site. Optionally you can mark specific blocks (wp-admin, etc.)
DevelopmentDevelopment site, staging or duplicate contentCompletely blocks crawling (Disallow: /). No search engine will index the site.
SEO optimizedProduction with SEO security focusAllows public content but blocks wp-admin, wp-json, xmlrpc. Best balance.
Maximum indexingMaximum priority on search engine visibilityAllows all bots (Googlebot, Bingbot, Yandex, DuckDuckBot, etc.) to index without restrictions.
VorlageWann verwendenEffekt
ProduktionLive-Website mit öffentlichen InhaltenErmöglicht das Crawlen der gesamten Website. Optional können Sie spezifische Blöcke markieren (wp-admin, etc.)
EntwicklungEntwicklungsseite, Staging oder doppelte InhalteBlockiert das Crawlen vollständig (Disallow: /). Keine Suchmaschine wird die Website indexieren.
SEO optimiertProduktion mit SEO-SicherheitsfokusErlaubt öffentliche Inhalte, blockiert aber wp-admin, wp-json, xmlrpc. Beste Balance.
Maximale IndexierungMaximale Priorität auf Sichtbarkeit in SuchmaschinenErlaubt allen Bots (Googlebot, Bingbot, Yandex, DuckDuckBot, etc.) die uneingeschränkte Indexierung.
ModèleQuand l'utiliserEffet
ProductionSite en ligne avec contenu publicPermet le crawl de tout le site. Optionnellement, vous pouvez marquer des blocages spécifiques (wp-admin, etc.)
DéveloppementSite en développement, staging ou contenu en doubleBloque complètement le crawl (Disallow: /). Aucun moteur de recherche n'indexera le site.
SEO optimiséProduction avec focus sécurité SEOPermet le contenu public mais bloque wp-admin, wp-json, xmlrpc. Meilleur équilibre.
Indexation maximalePriorité maximale sur la visibilité dans les moteurs de recherchePermet à tous les bots (Googlebot, Bingbot, Yandex, DuckDuckBot, etc.) d'indexer sans restrictions.

Directivas de bloqueo explicadasBlocking directives explainedBlockierungsanweisungen erklärtDirectives de blocage expliquées

Cada directiva de bloqueo disponible en el plugin tiene un propósito específico:

Each blocking directive available in the plugin has a specific purpose:

Jede im Plugin verfügbare Blockierungsanweisung hat einen bestimmten Zweck:

Chaque directive de blocage disponible dans le plugin a un objectif spécifique :

Directiva¿Qué bloquea?¿Debería bloquearlo?
/wp-admin/El panel de administración de WordPress✅ Sí. No tiene sentido que el login o el admin aparezcan en Google.
/wp-includes/Archivos internos del núcleo de WordPress✅ Sí. Son archivos de sistema, no tienen contenido útil para indexar.
/wp-json/La API REST de WordPress✅ Sí. Los endpoints de la API no son páginas que deban indexarse.
/?rest_route=Forma alternativa de acceder a la REST API✅ Sí. Misma razón que wp-json, es redundante permitirlo.
/xmlrpc.phpEl protocolo XML-RPC (usado por apps antiguas)✅ Sí. Es un blanco común de ataques de fuerza bruta.
DirectiveWhat it blocksShould you block it?
/wp-admin/The WordPress admin panel✅ Yes. No point in having the login or admin appear in Google.
/wp-includes/Internal WordPress core files✅ Yes. These are system files, no useful content to index.
/wp-json/The WordPress REST API✅ Yes. API endpoints are not pages that should be indexed.
/?rest_route=Alternative way to access the REST API✅ Yes. Same reason as wp-json, it is redundant to allow it.
/xmlrpc.phpThe XML-RPC protocol (used by old apps)✅ Yes. It is a common brute force attack target.
AnweisungWas wird blockiert?Sollten Sie es blockieren?
/wp-admin/Das WordPress-Admin-Panel✅ Ja. Es macht keinen Sinn, dass der Login oder Admin in Google erscheinen.
/wp-includes/Interne WordPress-Kerndateien✅ Ja. Dies sind Systemdateien, kein nutzbarer Inhalt zum Indexieren.
/wp-json/Die WordPress-REST-API✅ Ja. API-Endpunkte sind keine Seiten, die indexiert werden sollten.
/?rest_route=Alternative Möglichkeit zum Zugriff auf die REST-API✅ Ja. Gleicher Grund wie wp-json, es ist redundant, dies zu erlauben.
/xmlrpc.phpDas XML-RPC-Protokoll (von alten Apps verwendet)✅ Ja. Es ist ein häufiges Ziel von Brute-Force-Angriffen.
DirectiveCe qu'elle bloqueDevriez-vous la bloquer ?
/wp-admin/Le panneau d'administration WordPress✅ Oui. Il n'est pas utile que la connexion ou l'admin apparaissent dans Google.
/wp-includes/Fichiers internes du noyau WordPress✅ Oui. Ce sont des fichiers système, aucun contenu utile à indexer.
/wp-json/L'API REST WordPress✅ Oui. Les points de terminaison API ne sont pas des pages à indexer.
/?rest_route=Manière alternative d'accéder à l'API REST✅ Oui. Même raison que wp-json, il est redondant de l'autoriser.
/xmlrpc.phpLe protocole XML-RPC (utilisé par les anciennes apps)✅ Oui. C'est une cible courante d'attaques par force brute.

Reglas personalizadas: ejemplos prácticosCustom rules: practical examplesBenutzerdefinierte Regeln: praktische BeispieleRègles personnalisées : exemples pratiques

Puedes añadir reglas manuales para crawlers específicos. Aquí tienes ejemplos de uso común:

You can add manual rules for specific crawlers. Here are some common use examples:

Sie können manuelle Regeln für bestimmte Crawler hinzufügen. Hier sind einige Beispiele für die häufigsten Anwendungen:

Vous pouvez ajouter des règles manuelles pour des crawlers spécifiques. Voici quelques exemples d'utilisation courante :

Ejemplo 1: Bloquear un crawler específicoExample 1: Block a specific crawlerBeispiel 1: Bestimmten Crawler blockierenExemple 1 : Bloquer un crawler spécifique

# Bloquear completamente a SemrushBot User-agent: SemrushBot Disallow: / # Pero permitir todo lo demás User-agent: * Allow: /
# Completely block SemrushBot User-agent: SemrushBot Disallow: / # But allow everything else User-agent: * Allow: /
# SemrushBot komplett blockieren User-agent: SemrushBot Disallow: / # Aber alles andere erlauben User-agent: * Allow: /
# Bloquer complètement SemrushBot User-agent: SemrushBot Disallow: / # Mais autoriser tout le reste User-agent: * Allow: /

Ejemplo 2: Permitir solo a GoogleExample 2: Allow only GoogleBeispiel 2: Nur Google erlaubenExemple 2 : Autoriser uniquement Google

# Solo Google puede rastrear User-agent: Googlebot Allow: / # Todos los demás, bloqueados User-agent: * Disallow: /
# Only Google can crawl User-agent: Googlebot Allow: / # Everyone else, blocked User-agent: * Disallow: /
# Nur Google darf crawlen User-agent: Googlebot Allow: / # Alle anderen, gesperrt User-agent: * Disallow: /
# Seul Google peut crawler User-agent: Googlebot Allow: / # Tous les autres, bloqués User-agent: * Disallow: /

Ejemplo 3: Bloquear imágenes de GoogleExample 3: Block images from GoogleBeispiel 3: Bilder von Google blockierenExemple 3 : Bloquer les images de Google

# Google Images no debe indexar tus imágenes User-agent: Googlebot-Image Disallow: / # Google normal sí puede rastrear User-agent: Googlebot Allow: /
# Google Images should not index your images User-agent: Googlebot-Image Disallow: / # Regular Google can still crawl User-agent: Googlebot Allow: /
# Google Images soll Ihre Bilder nicht indexieren User-agent: Googlebot-Image Disallow: / # Normales Google darf weiter crawlen User-agent: Googlebot Allow: /
# Google Images ne doit pas indexer vos images User-agent: Googlebot-Image Disallow: / # Google normal peut toujours crawler User-agent: Googlebot Allow: /

🗺️ Generador de Sitemap XML🗺️ XML Sitemap Generator🗺️ XML-Sitemap-Generator🗺️ Générateur de Sitemap XML

El generador de sitemap crea automáticamente un archivo sitemap.xml con todas las URLs públicas de tu sitio (posts, páginas, CPTs). Se sirve en la URL /sitemap.xml de tu sitio.

The sitemap generator automatically creates a sitemap.xml file with all public URLs on your site (posts, pages, CPTs). It is served at /sitemap.xml on your site.

Der Sitemap-Generator erstellt automatisch eine sitemap.xml-Datei mit allen öffentlichen URLs Ihrer Website (Beiträge, Seiten, CPTs). Sie wird unter /sitemap.xml auf Ihrer Website bereitgestellt.

Le générateur de sitemap crée automatiquement un fichier sitemap.xml avec toutes les URLs publiques de votre site (articles, pages, CPTs). Il est servi à l'URL /sitemap.xml de votre site.

CaracterísticasFeaturesFunktionenFonctionnalités

  • Incluye automáticamente todas las entradas, páginas y tipos de contenido público.
  • Automatically includes all posts, pages, and public content types.
  • Enthält automatisch alle Beiträge, Seiten und öffentlichen Inhaltstypen.
  • Inclut automatiquement tous les articles, pages et types de contenu public.
  • Respeta las rutas bloqueadas en las directivas de bloqueo. Si marcaste "Bloquear /wp-admin/", esa ruta no aparecerá en el sitemap.
  • Respects the blocked paths in the blocking directives. If you checked "Block /wp-admin/", that path will not appear in the sitemap.
  • Respektiert die blockierten Pfade in den Blockierungsanweisungen. Wenn Sie "/wp-admin/ blockieren" markiert haben, wird dieser Pfad nicht in der Sitemap erscheinen.
  • Respecte les chemins bloqués dans les directives de blocage. Si vous avez coché "Bloquer /wp-admin/", ce chemin n'apparaîtra pas dans le sitemap.
  • Soporta sitemaps indexados: si tienes más de 5000 URLs, se genera un sitemap principal que enlaza a sitemaps secundarios (/sitemap-1.xml, /sitemap-2.xml, etc.).
  • Supports indexed sitemaps: if you have more than 5000 URLs, a main sitemap is generated linking to secondary sitemaps (/sitemap-1.xml, /sitemap-2.xml, etc.).
  • Unterstützt indizierte Sitemaps: Wenn Sie mehr als 5000 URLs haben, wird eine Haupt-Sitemap generiert, die auf sekundäre Sitemaps verweist (/sitemap-1.xml, /sitemap-2.xml, etc.).
  • Prend en charge les sitemaps indexés : si vous avez plus de 5000 URLs, un sitemap principal est généré avec des liens vers des sitemaps secondaires (/sitemap-1.xml, /sitemap-2.xml, etc.).
  • La caché se invalida automáticamente al publicar o actualizar contenido.
  • Cache is automatically invalidated when content is published or updated.
  • Der Cache wird automatisch ungültig, wenn Inhalte veröffentlicht oder aktualisiert werden.
  • Le cache est automatiquement invalidé lors de la publication ou de la mise à jour de contenu.
Nota: El sitemap generado reemplaza cualquier sitemap que WordPress genere por defecto. Si usas un plugin de SEO (Yoast, Rank Math, etc.), puedes mantener su sitemap y desactivar esta función. Note: The generated sitemap replaces any sitemap that WordPress generates by default. If you use an SEO plugin (Yoast, Rank Math, etc.), you can keep its sitemap and disable this feature. Hinweis: Die generierte Sitemap ersetzt jede von WordPress standardmäßig generierte Sitemap. Wenn Sie ein SEO-Plugin (Yoast, Rank Math, etc.) verwenden, können Sie dessen Sitemap behalten und diese Funktion deaktivieren. Remarque : Le sitemap généré remplace tout sitemap que WordPress génère par défaut. Si vous utilisez un plugin SEO (Yoast, Rank Math, etc.), vous pouvez conserver son sitemap et désactiver cette fonction.

Solución de problemasTroubleshootingFehlerbehebungDépannage

  • Google no indexa mi sitio: Revisa que no tengas seleccionado "Desarrollo (bloquear todo)". Si usas "SEO optimizado", verifica que no hayas bloqueado páginas importantes sin querer. Comprueba tu sitio en Google Search Console.
  • Google is not indexing my site: Check that you do not have "Development (block all)" selected. If using "SEO optimized", verify you have not accidentally blocked important pages. Check your site in Google Search Console.
  • Google indexiert meine Website nicht: Überprüfen Sie, ob Sie nicht "Entwicklung (alles blockieren)" ausgewählt haben. Wenn Sie "SEO optimiert" verwenden, stellen Sie sicher, dass Sie nicht versehentlich wichtige Seiten blockiert haben. Überprüfen Sie Ihre Website in der Google Search Console.
  • Google n'indexe pas mon site : Vérifiez que vous n'avez pas sélectionné "Développement (tout bloquer)". Si vous utilisez "SEO optimisé", vérifiez que vous n'avez pas accidentellement bloqué des pages importantes. Consultez votre site dans Google Search Console.
  • Los cambios no se reflejan: Los motores de búsqueda cachean robots.txt. Pueden pasar horas o días hasta que Google lo vuelva a leer. Usa la herramienta de prueba de robots.txt en Search Console para forzar la actualización.
  • Changes are not reflected: Search engines cache robots.txt. It can take hours or days for Google to re-read it. Use the robots.txt tester in Search Console to force an update.
  • Änderungen werden nicht übernommen: Suchmaschinen cachen robots.txt. Es kann Stunden oder Tage dauern, bis Google es erneut liest. Verwenden Sie den robots.txt-Tester in der Search Console, um ein Update zu erzwingen.
  • Les changements ne sont pas reflétés : Les moteurs de recherche mettent en cache robots.txt. Il peut falloir des heures ou des jours pour que Google le relise. Utilisez l'outil de test robots.txt dans Search Console pour forcer une mise à jour.
  • Quiero que Google indexe más rápido: Asegúrate de tener un sitemap.xml configurado y que apunte a tus páginas principales. Envía el sitemap desde Google Search Console.
  • I want Google to index faster: Make sure you have a sitemap.xml configured pointing to your main pages. Submit the sitemap from Google Search Console.
  • Ich möchte, dass Google schneller indexiert: Stellen Sie sicher, dass eine sitemap.xml konfiguriert ist, die auf Ihre Hauptseiten verweist. Reichen Sie die Sitemap in der Google Search Console ein.
  • Je veux que Google indexe plus rapidement : Assurez-vous d'avoir un sitemap.xml configuré pointant vers vos pages principales. Soumettez le sitemap depuis Google Search Console.
Recuerda: robots.txt solo controla el rastreo, no la indexación. Si una página es enlazada desde otro sitio, Google puede indexarla incluso si está bloqueada en robots.txt. Para evitar que una página aparezca en Google, usa la meta etiqueta noindex o protegela con contraseña. Remember: robots.txt only controls crawling, not indexing. If a page is linked from another site, Google may index it even if blocked in robots.txt. To prevent a page from appearing in Google, use the noindex meta tag or password-protect it. Denken Sie daran: robots.txt steuert nur das Crawling, nicht die Indexierung. Wenn eine Seite von einer anderen Website verlinkt wird, kann Google sie indexieren, selbst wenn sie in robots.txt blockiert ist. Um zu verhindern, dass eine Seite in Google erscheint, verwenden Sie das noindex-Meta-Tag oder schützen Sie sie mit einem Passwort. N'oubliez pas : robots.txt ne contrôle que le crawl, pas l'indexation. Si une page est liée depuis un autre site, Google peut l'indexer même si elle est bloquée dans robots.txt. Pour empêcher une page d'apparaître dans Google, utilisez la balise meta noindex ou protégez-la par mot de passe.

🛡️ Capa 5: Validación Estricta de IPs (Anti-Spoofing)🛡️ Layer 5: Strict IP Validation (Anti-Spoofing)🛡️ Schicht 5: Strenge IP-Validierung (Anti-Spoofing)🛡️ Couche 5 : Validation stricte des IP (Anti-Spoofing)

La quinta capa garantiza que cada protección del plugin (login, rate limiting, CAPTCHA, geo-bloqueo, whitelists, etc.) vea siempre la IP real del visitante, no una IP que él mismo declare en las cabeceras HTTP.

The fifth layer guarantees that every protection in the plugin (login, rate limiting, CAPTCHA, geo-blocking, whitelists, etc.) always sees the visitor's real IP, not an IP the visitor declares himself in HTTP headers.

Die fünfte Schicht stellt sicher, dass jede Schutzfunktion des Plugins (Login, Rate Limiting, CAPTCHA, Geo-Blocking, Whitelists usw.) immer die echte IP des Besuchers sieht – nicht eine IP, die der Besucher selbst in den HTTP-Headern angibt.

La cinquième couche garantit que chaque protection du plugin (connexion, rate limiting, CAPTCHA, géo-blocage, listes blanches, etc.) voit toujours la véritable IP du visiteur, et non une IP déclarée par le visiteur lui-même dans les en-têtes HTTP.

¿Qué ataque evita? Cualquier visitante puede añadir cabeceras HTTP a su petición. Un atacante que envíe X-Forwarded-For: 127.0.0.1 (o una IP distinta en cada petición) engaña a los contadores por IP: fuerza bruta en el login, rate limiting, intentos de CAPTCHA, geo-bloqueo o whitelists. Con la IP falseada, el atacante nunca acumula intentos fallidos y nunca llega a ser bloqueado. También puede fingir ser una IP de tu whitelist o de pasarelas de pago para eludir los controles. What attack does it prevent? Any visitor can add HTTP headers to their request. An attacker sending X-Forwarded-For: 127.0.0.1 (or a different IP on each request) fools IP-based counters: brute force on login, rate limiting, CAPTCHA attempts, geo-blocking, or whitelists. With a spoofed IP, the attacker never accumulates failed attempts and never gets blocked. They can also pretend to be an IP from your whitelist or from payment gateways to bypass controls. Welchen Angriff verhindert sie? Jeder Besucher kann seinem Request HTTP-Header hinzufügen. Ein Angreifer, der X-Forwarded-For: 127.0.0.1 (oder bei jedem Request eine andere IP) sendet, täuscht die IP-Zähler: Brute-Force beim Login, Rate Limiting, CAPTCHA-Versuche, Geo-Blocking oder Whitelists. Mit gefälschter IP häuft der Angreifer nie fehlgeschlagene Versuche an und wird nie gesperrt. Er kann auch so tun, als sei er eine IP aus Ihrer Whitelist oder von Zahlungsanbietern, um Kontrollen zu umgehen. Quelle attaque cela évite-t-il ? Tout visiteur peut ajouter des en-têtes HTTP à sa requête. Un attaquant qui envoie X-Forwarded-For: 127.0.0.1 (ou une IP différente à chaque requête) trompe les compteurs par IP : force brute sur la connexion, rate limiting, tentatives de CAPTCHA, géo-blocage ou listes blanches. Avec une IP falsifiée, l'attaquant n'accumule jamais de tentatives échouées et n'est jamais bloqué. Il peut aussi se faire passer pour une IP de votre liste blanche ou de passerelles de paiement pour contourner les contrôles.

Esto no es un límite más. Un límite por IP solo funciona si la IP es real: si el atacante puede cambiar de IP a voluntad, el límite deja de existir. Esta capa no añade ningún contador nuevo: hace que los contadores que ya tienes cuenten a quien debe. Es la diferencia entre tener un límite de 5 intentos y que esos 5 intentos sean siempre de la misma persona.

This is not an extra limit. An IP-based limit only works if the IP is real: if the attacker can change IP at will, the limit ceases to exist. This layer adds no new counter: it makes the counters you already have count the right person. It is the difference between having a 5-attempt limit and those 5 attempts always coming from the same person.

Dies ist keine zusätzliche Grenze. Ein IP-basierter Grenzwert funktioniert nur, wenn die IP echt ist: Wenn der Angreifer die IP beliebig wechseln kann, hört der Grenzwert auf zu existieren. Diese Schicht fügt keinen neuen Zähler hinzu – sie sorgt dafür, dass die Zähler, die Sie bereits haben, die richtige Person zählen. Es ist der Unterschied zwischen einem Limit von 5 Versuchen und der Tatsache, dass diese 5 Versuche immer von derselben Person kommen.

Ce n'est pas une limite supplémentaire. Une limite basée sur l'IP ne fonctionne que si l'IP est réelle : si l'attaquant peut changer d'IP à volonté, la limite cesse d'exister. Cette couche n'ajoute aucun nouveau compteur : elle fait en sorte que les compteurs que vous avez déjà comptent la bonne personne. C'est la différence entre avoir une limite de 5 tentatives et que ces 5 tentatives viennent toujours de la même personne.

¿Cómo funciona?How does it work?Wie funktioniert es?Comment ça marche ?

  1. Toda protección que cuenta por IP (login, rate limiting, CAPTCHA, geo, whitelists) resuelve la IP del visitante con una única función central validada del firewall, en lugar de leer las cabeceras que el visitante declara.
  2. Every protection that counts by IP (login, rate limiting, CAPTCHA, geo, whitelists) resolves the visitor IP through a single central firewall-validated function, instead of reading the headers the visitor declares.
  3. Jede Schutzfunktion, die nach IP zählt (Login, Rate Limiting, CAPTCHA, Geo, Whitelists), ermittelt die Besucher-IP über eine einzige zentrale, firewall-validierte Funktion, statt die vom Besucher angegebenen Header zu lesen.
  4. Toute protection qui compte par IP (connexion, rate limiting, CAPTCHA, géo, listes blanches) résout l'IP du visiteur via une fonction centrale unique validée par le pare-feu, au lieu de lire les en-têtes déclarés par le visiteur.
  5. Esa función solo confía en X-Forwarded-For, X-Real-IP o CF-Connecting-IP cuando la conexión TCP real (REMOTE_ADDR, imposible de falsear) proviene de Cloudflare o de un proxy interno de confianza.
  6. That function only trusts X-Forwarded-For, X-Real-IP, or CF-Connecting-IP when the real TCP connection (REMOTE_ADDR, impossible to spoof) comes from Cloudflare or a trusted internal proxy.
  7. Diese Funktion vertraut X-Forwarded-For, X-Real-IP oder CF-Connecting-IP nur, wenn die echte TCP-Verbindung (REMOTE_ADDR, nicht fälschbar) von Cloudflare oder einem vertrauenswürdigen internen Proxy stammt.
  8. Cette fonction ne fait confiance à X-Forwarded-For, X-Real-IP ou CF-Connecting-IP que lorsque la connexion TCP réelle (REMOTE_ADDR, impossible à falsifier) provient de Cloudflare ou d'un proxy interne de confiance.
  9. Si la petición llega directa, la IP usada es siempre la de la conexión TCP real, ignorando cualquier cabecera que el visitante escriba a mano.
  10. If the request arrives directly, the IP used is always the real TCP connection IP, ignoring any header the visitor writes by hand.
  11. Wenn der Request direkt ankommt, wird immer die IP der echten TCP-Verbindung verwendet, egal welche Header der Besucher von Hand schreibt.
  12. Si la requête arrive directement, l'IP utilisée est toujours celle de la connexion TCP réelle, en ignorant tout en-tête écrit à la main par le visiteur.

¿Qué protege esta capa?What does this layer protect?Was schützt diese Schicht?Que protège cette couche ?

  • Los intentos de login y el rate limiting: el contador ya no se puede reiniciar con cabeceras falsas.
  • Login attempts and rate limiting: the counter can no longer be reset with fake headers.
  • Login-Versuche und Rate Limiting: Der Zähler kann nicht mehr mit gefälschten Headern zurückgesetzt werden.
  • Les tentatives de connexion et le rate limiting : le compteur ne peut plus être réinitialisé avec de faux en-têtes.
  • CAPTCHA, blacklist/whitelist y geo-bloqueo: siempre se aplican a la IP correcta.
  • CAPTCHA, blacklist/whitelist and geo-blocking: always applied to the correct IP.
  • CAPTCHA, Blacklist/Whitelist und Geo-Blocking: Sie werden immer auf die korrekte IP angewendet.
  • CAPTCHA, listes noire/blanche et géo-blocage : toujours appliqués à la bonne IP.
  • Verificación de crawlers y el resto de detecciones que usan la IP del visitante.
  • Crawler verification and all other IP-based detections.
  • Crawler-Verifikation und alle anderen IP-basierten Erkennungen.
  • La vérification des crawlers et toutes les autres détections basées sur l'IP.
Compatible con Cloudflare y proxies: Si tu sitio está detrás de Cloudflare o de un proxy del hosting, las cabeceras de IP se aceptan automáticamente solo cuando la conexión TCP real proviene de Cloudflare o de un proxy interno de confianza. No necesitas configurar nada más: en conexiones directas (el caso habitual), las cabeceras falsas se ignoran siempre. Compatible with Cloudflare and proxies: If your site is behind Cloudflare or a hosting proxy, IP headers are automatically accepted only when the real TCP connection comes from Cloudflare or a trusted internal proxy. No extra configuration needed: on direct connections (the usual case), spoofed headers are always ignored. Kompatibel mit Cloudflare und Proxys: Wenn Ihre Website hinter Cloudflare oder einem Hosting-Proxy liegt, werden IP-Header automatisch nur akzeptiert, wenn die echte TCP-Verbindung von Cloudflare oder einem vertrauenswürdigen internen Proxy stammt. Keine weitere Konfiguration nötig: Bei direkten Verbindungen (der übliche Fall) werden gefälschte Header immer ignoriert. Compatible avec Cloudflare et les proxys : Si votre site est derrière Cloudflare ou un proxy d'hébergement, les en-têtes IP sont automatiquement acceptés uniquement lorsque la connexion TCP réelle provient de Cloudflare ou d'un proxy interne de confiance. Aucune configuration supplémentaire nécessaire : en connexion directe (le cas habituel), les en-têtes falsifiés sont toujours ignorés.

🚫 Bloquear IP que intenta spoofing (opción)Block IP that attempts spoofing (option)IP blockieren, die Spoofing versucht (Option)Bloquer l'IP qui tente un spoofing (option)

Por defecto, esta capa se limita a ignorar la IP falsa: la petición continúa con la IP real y el intento queda registrado en el log con la marca "🛡️ Anti-Spoofing". La tarjeta Capa 5 (Firewall → Anti-Bot) incluye el botón/interruptor "🚫 Bloquear IP que intenta spoofing" para añadir el bloqueo activo: si una cabecera declara una IP distinta de la real, la petición se corta al instante con un 403. El botón solo puede activarse si antes está en ON el interruptor "Activar Validación Estricta de IPs"; si apagas la capa, el bloqueo se desmarca automáticamente.

By default, this layer only ignores the fake IP: the request continues with the real IP and the attempt is recorded in the log with the "🛡️ Anti-Spoofing" tag. The Layer 5 card (Firewall → Anti-Bot) includes the button/switch "🚫 Block IP that attempts spoofing" to add active blocking: if a header claims an IP different from the real one, the request is cut off instantly with a 403. The button can only be turned ON if the "Enable Strict IP Validation" switch is already ON; if you turn the layer off, the block option is automatically unchecked.

Standardmäßig ignoriert diese Schicht die gefälschte IP einfach: Die Anfrage läuft mit der echten IP weiter und der Versuch wird im Log mit dem Kennzeichen "🛡️ Anti-Spoofing" vermerkt. Die Karte Schicht 5 (Firewall → Anti-Bot) enthält den Schalter/Button "🚫 IP blockieren, die Spoofing versucht" für die aktive Sperrung: Wenn ein Header eine andere IP angibt als die echte, wird die Anfrage sofort mit einem 403 abgebrochen. Der Schalter kann nur aktiviert werden, wenn zuvor der Schalter "Strikte IP-Validierung aktivieren" auf AN steht; wenn Sie die Schicht ausschalten, wird die Sperroption automatisch abgewählt.

Par défaut, cette couche se contente d'ignorer l'IP falsifiée : la requête continue avec l'IP réelle et la tentative est consignée dans le journal avec la marque "🛡️ Anti-Spoofing". La carte Couche 5 (Firewall → Anti-Bot) comprend le bouton/interrupteur "🚫 Bloquer l'IP qui tente un spoofing" pour ajouter le blocage actif : si un en-tête déclare une IP différente de la réelle, la requête est coupée immédiatement avec un 403. Le bouton ne peut être activé que si l'interrupteur "Activer la validation stricte des IP" est d'abord sur ON ; si vous désactivez la couche, l'option de blocage se décoche automatiquement.

  • Activada (ON): si una cabecera declara una IP distinta de la real, la petición se corta al instante con un 403 y se registra como "Anti-spoofing: IP falsa detectada y bloqueada (X-Forwarded-For: …)".
  • Enabled (ON): if a header claims an IP different from the real one, the request is cut off instantly with a 403 and logged as "Anti-spoofing: IP falsa detectada y bloqueada (X-Forwarded-For: …)" (the log marker is in Spanish).
  • Aktiviert (ON): Wenn ein Header eine andere IP angibt als die echte, wird die Anfrage sofort mit einem 403 abgebrochen und als "Anti-spoofing: IP falsa detectada y bloqueada (X-Forwarded-For: …)" protokolliert (die Log-Markierung ist auf Spanisch).
  • Activée (ON) : si un en-tête déclare une IP différente de la réelle, la requête est coupée immédiatement avec un 403 et consignée comme "Anti-spoofing: IP falsa detectada y bloqueada (X-Forwarded-For: …)" (la marque du journal est en espagnol).
  • Desactivada (OFF, recomendada por defecto): el intento solo se marca y la IP falsa se descarta; la visita continúa con la IP real.
  • Disabled (OFF, recommended by default): the attempt is only flagged and the fake IP is discarded; the visit continues with the real IP.
  • Deaktiviert (OFF, standardmäßig empfohlen): Der Versuch wird nur markiert und die gefälschte IP verworfen; der Besuch läuft mit der echten IP weiter.
  • Désactivée (OFF, recommandée par défaut) : la tentative est uniquement signalée et l'IP falsifiée est écartée ; la visite continue avec l'IP réelle.
⚠️ Advertencia: Actívala solo si tus visitantes se conectan directamente. Algunos proxies corporativos o redes de operadores reescriben X-Forwarded-For en conexiones legítimas y podrían quedar bloqueados. Con Cloudflare o el proxy del hosting no afecta: sus cabeceras se siguen aceptando porque la conexión real viene de ellos. El botón solo tiene efecto si la capa está activada (de hecho queda deshabilitado mientras la capa esté apagada) y el firewall está en un modo de bloqueo (Protección/Estricto); en modo Monitor solo se registra. ⚠️ Warning: Only enable it if your visitors connect directly. Some corporate proxies or carrier networks rewrite X-Forwarded-For on legitimate connections and could get blocked. Cloudflare or the hosting proxy are unaffected: their headers are still accepted because the real connection comes from them. The button only takes effect when the layer is enabled (in fact, it is disabled while the layer is off) and the firewall is in a blocking mode (Protect/Strict); in Monitor mode it only logs. ⚠️ Warnung: Aktivieren Sie es nur, wenn Ihre Besucher sich direkt verbinden. Einige Unternehmens-Proxys oder Betreibernetzwerke überschreiben X-Forwarded-For bei legitimen Verbindungen und könnten gesperrt werden. Cloudflare oder der Hosting-Proxy sind nicht betroffen: Ihre Header werden weiterhin akzeptiert, weil die echte Verbindung von ihnen kommt. Der Schalter wirkt nur, wenn die Schicht aktiviert ist (und bleibt tatsächlich deaktiviert, solange die Schicht aus ist) und die Firewall im Sperrmodus ist (Schutz/Streng); im Überwachungsmodus wird nur protokolliert. ⚠️ Avertissement : Activez-le uniquement si vos visiteurs se connectent directement. Certains proxys d'entreprise ou réseaux d'opérateurs réécrivent X-Forwarded-For sur des connexions légitimes et pourraient être bloqués. Cloudflare ou le proxy d'hébergement ne sont pas concernés : leurs en-têtes restent acceptés car la connexion réelle provient d'eux. Le bouton n'a d'effet que si la couche est activée (il reste d'ailleurs désactivé tant que la couche est éteinte) et que le pare-feu est en mode bloquant (Protection/Strict) ; en mode Surveillance, il ne fait que journaliser.

Solución de problemasTroubleshootingFehlerbehebungDépannage

  • Los logs muestran la IP del proxy en vez de la del visitante: Comprueba que tu proxy no sea una IP pública (algunas CDNs como Cloudflare usan IPs públicas). Si usas un proxy con IP pública que no es Cloudflare, la capa no puede distinguirla de un atacante y tratará sus cabeceras como falsas.
  • Logs show the proxy IP instead of the visitor IP: Check that your proxy is not a public IP (some CDNs like Cloudflare use public IPs). If you use a proxy with a public IP that is not Cloudflare, the layer cannot distinguish it from an attacker and will treat its headers as fake.
  • In den Logs erscheint die Proxy-IP statt der Besucher-IP: Prüfen Sie, ob Ihr Proxy keine öffentliche IP hat (einige CDNs wie Cloudflare verwenden öffentliche IPs). Wenn Sie einen Proxy mit öffentlicher IP verwenden, der nicht Cloudflare ist, kann die Schicht ihn nicht von einem Angreifer unterscheiden und behandelt seine Header als gefälscht.
  • Les journaux montrent l'IP du proxy au lieu de celle du visiteur : Vérifiez que votre proxy n'a pas une IP publique (certains CDN comme Cloudflare utilisent des IP publiques). Si vous utilisez un proxy avec une IP publique qui n'est pas Cloudflare, la couche ne peut pas le distinguer d'un attaquant et traitera ses en-têtes comme faux.
  • Si desactivo esta capa, ¿algo deja de funcionar? No: cada módulo vuelve a su comportamiento original; por sí sola esta capa no bloquea nada, solo hace que los bloqueos existentes cuenten la IP correcta. Se recomienda mantenerla activa; es una protección PRO.
  • If I disable this layer, does anything stop working? No: every module returns to its original behavior; on its own this layer blocks nothing, it just makes existing blocks count the correct IP. Keeping it enabled is recommended; it is a PRO protection.
  • Wenn ich diese Schicht deaktiviere, funktioniert dann etwas nicht mehr? Nein: Jedes Modul kehrt zu seinem ursprünglichen Verhalten zurück; diese Schicht blockiert für sich genommen nichts, sie sorgt nur dafür, dass bestehende Sperren die korrekte IP zählen. Es wird empfohlen, sie aktiviert zu lassen; es ist eine PRO-Schutzfunktion.
  • Si je désactive cette couche, quelque chose cesse-t-il de fonctionner ? Non : chaque module revient à son comportement d'origine ; cette couche ne bloque rien en soi, elle fait simplement en sorte que les blocages existants comptent la bonne IP. Il est recommandé de la laisser activée ; c'est une protection PRO.
  • ¿Qué pasa si un visitante envía una IP falsa en las cabeceras? Con la capa activa, la IP falsa se ignora y la conexión se trata con la IP real, dejando en el log la marca "🛡️ Anti-Spoofing". Si además está activada la opción "🚫 Bloquear IP que intenta spoofing", la petición se bloquea con 403 en el acto. Con la capa desactivada, el plugin vuelve a su comportamiento original y el log muestra una sola fila por visita, con la IP real.
  • What happens if a visitor sends a fake IP in the headers? With the layer enabled, the fake IP is ignored and the connection is treated with the real IP, leaving the "🛡️ Anti-Spoofing" tag in the log. If the "🚫 Block IP that attempts spoofing" option is also enabled, the request is blocked with 403 on the spot. With the layer disabled, the plugin returns to its original behavior and the log shows a single row per visit, with the real IP.
  • Was passiert, wenn ein Besucher eine gefälschte IP in den Headern sendet? Bei aktivierter Schicht wird die gefälschte IP ignoriert und die Verbindung mit der echten IP behandelt; im Log erscheint das Kennzeichen "🛡️ Anti-Spoofing". Wenn zusätzlich die Option "🚫 IP blockieren, die Spoofing versucht" aktiviert ist, wird die Anfrage sofort mit 403 gesperrt. Bei deaktivierter Schicht kehrt das Plugin zu seinem ursprünglichen Verhalten zurück und das Log zeigt eine einzelne Zeile pro Besuch, mit der echten IP.
  • Que se passe-t-il si un visiteur envoie une IP falsifiée dans les en-têtes ? Avec la couche activée, l'IP falsifiée est ignorée et la connexion est traitée avec l'IP réelle, laissant la marque "🛡️ Anti-Spoofing" dans le journal. Si l'option "🚫 Bloquer l'IP qui tente un spoofing" est également activée, la requête est bloquée avec un 403 immédiatement. Avec la couche désactivée, le plugin revient à son comportement d'origine et le journal affiche une seule ligne par visite, avec l'IP réelle.