Skip to content

Help

The questions people ask most. The steps themselves are in How it works, and getting out again is in Leaving.

Setting up

What is "the server my website runs on"?
The place your site really lives. If you use a website builder or a hosting platform, it is the address they gave your site, often ending in their own name. If you rent a server, it is that server's numeric address. Whoever built your site, or your host's support, can tell you.
It says my server did not answer.
Check the address for typing mistakes. If it is right, the server may only accept visitors from certain places, or may need the other choice under "Which name does that server expect?". The message on the screen says which it looks like.
Where do I change DNS records?
Where your domain is managed: usually the company you bought the name from. If you are not sure who that is, your web person will know, and the app can email them the records.
How long until the DNS change works?
It depends on the time-to-live of the record you are changing: the old value is remembered for that long. Lower it before you make the change and it spreads in minutes.
Visitors saw a certificate warning after the change.
A new certificate is issued for your site as soon as its DNS points at Blackwall, and until it arrives browsers warn. It clears by itself. Making the change at a quiet hour keeps this from most visitors.
My website's name has no www in front.
Some DNS providers cannot point a bare name, such as example.com, at another name. If yours cannot, protect www.example.com and forward the bare name to it, or move your DNS to a provider that can.

Day to day

A customer says they were blocked.
Ask for the reference on the page they saw. Type it into "Find by reference" under Stopped requests. Open the request and press "This was a real visitor". Requests like theirs are let through from then on.
What does an exception actually do?
It tells one rule to stop looking at one field on one page. Nothing else changes. You can have up to 50, and remove any of them in Firewall settings.
What is the difference between watching and blocking?
Watching lets every request through and lists the ones that would have been stopped. Blocking stops them. A new site watches until you switch.
What is pass-through for?
For when you need the firewall out of the way at once: something on your site is not working and you want to rule the firewall out. Every request reaches your site and nothing is inspected or recorded.
It says my server is not locked.
Your own server still answers people who contact it directly, so the firewall can be skipped by anyone who finds its address. Firewall settings shows two ways to close that, with text to copy.
It says the proof is missing.
The code that proves the site is yours is no longer where it was, often because the site was rebuilt. Put it back the same way as before. Until then your site stays up, uninspected.

What it keeps

What is recorded about my visitors?
For a request that passes: nothing but a count. For one that is stopped or noted: when, the address it came from, the page, the name its software gave itself (the user agent), the rules it matched and the part that matched, for 30 days.
Are passwords or cookies ever kept?
No. Cookies and sign-in headers are never written down, and a field whose name suggests a secret (a password, a card number, a token) is recorded by name only.
Can I get my data out?
Yes. Settings, then Export, has stopped requests and hourly counts as spreadsheets.

Still stuck?

[The address for Blackwall support and abuse reports goes here.]