# Access rules

Accept submissions only from your own websites, and block IP addresses and countries.

Access rules limit where a form's submissions can come from. Set them in the form's **Settings**, **Spam protection**, **Access rules**.

## Allowed websites

Enter the sites that are allowed to send submissions, one per line:

```text
https://example.com
https://www.example.com
https://staging.example.com
```

Once the list has at least one site, Nisuform compares the site in each request's `Origin` header, or its `Referer` header when there is no `Origin`, with the list. Submissions from any other site are rejected with `403` and `origin_not_allowed`. Leave the list empty to accept submissions from any website.

* Only the scheme, host and port count. A full URL like `https://example.com/contact` is saved as `https://example.com`.
* `https://example.com` and `https://www.example.com` are different sites. Add both if your site answers on both.
* Add `http://localhost:3000`, or whatever your dev server uses, to test locally.
* Up to 50 sites per form.

Allowed websites also decide where a [`_redirect`](/docs/connect/special-fields#_redirect) may send visitors.

<Callout title="Browsers only" type="warn">
  Browsers always send `Origin` or `Referer`, and pages can't fake them. Scripts and servers can send any headers, or none. Requests without either header are allowed, so allowed websites stop other sites from embedding your form, but they don't stop a determined bot. Combine them with [Cloudflare Turnstile](/docs/protection/turnstile) for that.
</Callout>

## Blocked IP addresses

Enter IP addresses to block, one per line or separated by commas. Both IPv4 and IPv6 addresses work, and each must match exactly. Ranges are not supported. Up to 1,000 addresses per form.

Find a sender's address on any submission in the inbox, under **IP address**.

## Blocked countries

Pick countries to block. The country comes from where the request reaches Nisuform, based on the sender's IP address. VPNs and proxies change it.

## What blocked senders see

Submissions from a blocked IP address or country are dropped without notice. The sender gets a normal success response, without a `submissionId`, so they have no reason to try another way. Nothing is stored, and nothing counts toward your limits.

## Store IP addresses

**Store IP addresses** is on by default and saves each sender's IP address with the submission, so you can block it later. Turn it off for forms that don't need it. New submissions are then stored without an IP address. Blocking and rate limits still work, because they check the address while the request is handled. See [Privacy and data](/docs/account/privacy).
