When a visitor is blocked

A person who is blocked sees a reference, and can send it to you or report it. You find that request, see the rule and Promote Copilot’s read, and choose the change.

What the visitor sees

After you promote a rule to block, a matching request can show your block page. It shows a reference for that request. The visitor can read that reference to you, or open Report this block. A report does not unblock them. The page does not name the rule.

The report link includes the reference. The visitor’s browser adds the site address. With JavaScript off, the form still asks for the site. Logs can take a few minutes to include the request.

What you see

The site page lists the report: the reference, the rule when the log has it, the path without the query string, Promote Copilot’s last read (Promote, Hold, or Needs allowlist), and the visitor’s note. Paste a reference to find it in the current log sample. The sites list shows how many reports are waiting.

An agency sees reports on each client site it owns. A client viewer can read the list and cannot change the rule. An operator sees the same list on Manage.

A credible report is one whose reference matches a blocked request. That note uses the attack-spike email switch and the same 6-hour cooldown, on its own clock. Slack and the webhook use that switch too. The mail names the rule and Copilot’s last read. It does not change WAF mode.

How you resolve it

The list links to the controls already on the site: Open Tuning, Save a narrow exception when Copilot says Needs allowlist, and Move this rule back to count or Undo when the rule is blocking. Each one is a click. Undo is read back from the firewall.

You still click Promote. Nothing is blocked automatically. A report never writes an allowlist, never moves a rule to count, and never undoes a promote.

Limits

The public form accepts 5 reports an hour from one network, and 8 new reports an hour for one site. A repeat of the same reference is stored once. An unknown site, two sites that share a name, a duplicate, and a full hour all show the same confirmation, so the form is not a way to learn whether a site is here. A network that is over the limit is asked to wait.

Visitor IP addresses are not stored. A note that contains an address is masked. The block page body stays within the size limit for a custom response, so it cannot include a long explanation or the rule name.

A report that never matches a blocked request stops waiting after 12 hours. Opening the site page does not send the email and does not change the firewall.

Answers

Does reporting a block let the visitor through?

No. The report stores a reference for the site owner. It does not allowlist, move a rule to count, or Undo.

Does the block page say which rule fired?

No. The visitor sees a reference and a way to report the block. The rule name stays on your site page.

Related guides

More in this section