Skip to content

Bits of .NET

Daily micro-tips for C#, SQL, performance, and scalable backend engineering.

  • Asp.Net Core
  • C#
  • SQL
  • JavaScript
  • CSS
  • About
  • ErcanOPAK.com
  • No Access
  • Privacy Policy
Wordpress

Stop WordPress Comment Spam Without Plugins Using This .htaccess Rule

- 01.02.26 | 01.02.26 - ErcanOPAK

Getting hundreds of spam comments daily? Here’s a plugin-free solution that blocks 95% of spam bots at the server level.

The Problem: Most spam bots post comments by directly hitting your wp-comments-post.php file, bypassing your website’s front-end entirely. Anti-spam plugins catch this AFTER it reaches WordPress, wasting server resources processing garbage requests.

The Solution – Add to .htaccess:

<IfModule mod_rewrite.c>
RewriteEngine On

# Block comment spam bots
RewriteCond %{REQUEST_URI} ^/wp-comments-post\.php*
RewriteCond %{HTTP_REFERER} !^https?://yoursite\.com/.* [OR]
RewriteCond %{HTTP_USER_AGENT} ^$
RewriteRule .* - [F,L]
</IfModule>

Replace “yoursite.com” with your actual domain.

How It Works:
This rule checks two conditions for wp-comments-post.php requests:
1. Is the referer from your own domain?
2. Does the request include a user agent?

Legitimate comments come from users filling out your comment form (referer = your site). Spam bots directly POST to the file with empty or spoofed referers. If either condition fails, Apache returns a 403 Forbidden before WordPress even loads.

Why This Beats Plugins:
• Blocks spam at Apache level (before PHP executes)
• Zero database queries for blocked requests
• No plugin overhead or compatibility issues
• Works even if WordPress is broken

Edge Case Fix:
If legitimate commenters get blocked (rare), add their user agents as exceptions:

RewriteCond %{HTTP_USER_AGENT} !^(Mozilla|Chrome|Safari|Firefox).*

Monitor Results:
Check your server error log after 24 hours:

grep "wp-comments-post" /var/log/apache2/error.log | wc -l

You’ll see hundreds or thousands of blocked attempts. Each blocked request saved your server from loading WordPress, running anti-spam plugins, and querying the database.

Related posts:

The White Screen of Death Fix (WP_DEBUG)

WordPress REST API Slow — Disable Unused Endpoints

WordPress REST API Feels Slow

Post Views: 5

Post navigation

Fix Photoshop Lag on High-Resolution Displays with This GPU Setting
Recover Deleted WordPress Posts from Database (Even Without Backups)

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

April 2026
M T W T F S S
 12345
6789101112
13141516171819
20212223242526
27282930  
« Mar    

Most Viewed Posts

  • Get the User Name and Domain Name from an Email Address in SQL (950)
  • How to add default value for Entity Framework migrations for DateTime and Bool (858)
  • Get the First and Last Word from a String or Sentence in SQL (836)
  • How to select distinct rows in a datatable in C# (805)
  • How to make theater mode the default for Youtube (753)
  • Add Constraint to SQL Table to ensure email contains @ (578)
  • How to enable, disable and check if Service Broker is enabled on a database in SQL Server (564)
  • Average of all values in a column that are not zero in SQL (531)
  • How to use Map Mode for Vertical Scroll Mode in Visual Studio (489)
  • Find numbers with more than two decimal places in SQL (447)

Recent Posts

  • C#: Use Init-Only Setters for Immutable Objects After Construction
  • C#: Use Expression-Bodied Members for Concise Single-Line Methods
  • C#: Enable Nullable Reference Types to Eliminate Null Reference Exceptions
  • C#: Use Record Types for Immutable Data Objects
  • SQL: Use CTEs for Readable Complex Queries
  • SQL: Use Window Functions for Advanced Analytical Queries
  • .NET Core: Use Background Services for Long-Running Tasks
  • .NET Core: Use Minimal APIs for Lightweight HTTP Services
  • Git: Use Cherry-Pick to Apply Specific Commits Across Branches
  • Git: Use Interactive Rebase to Clean Up Commit History Before Merge

Most Viewed Posts

  • Get the User Name and Domain Name from an Email Address in SQL (950)
  • How to add default value for Entity Framework migrations for DateTime and Bool (858)
  • Get the First and Last Word from a String or Sentence in SQL (836)
  • How to select distinct rows in a datatable in C# (805)
  • How to make theater mode the default for Youtube (753)

Recent Posts

  • C#: Use Init-Only Setters for Immutable Objects After Construction
  • C#: Use Expression-Bodied Members for Concise Single-Line Methods
  • C#: Enable Nullable Reference Types to Eliminate Null Reference Exceptions
  • C#: Use Record Types for Immutable Data Objects
  • SQL: Use CTEs for Readable Complex Queries

Social

  • ErcanOPAK.com
  • GoodReads
  • LetterBoxD
  • Linkedin
  • The Blog
  • Twitter
© 2026 Bits of .NET | Built with Xblog Plus free WordPress theme by wpthemespace.com