Block Bad Bots and Scanners in Nginx

Most unwanted traffic is not sophisticated: scripts probe for .env files, .git directories and admin panels you do not run. Matching those paths at the edge is cheap and rarely blocks a real user.

Match probes, not user agents

User-agent strings are trivial to fake. Requests for paths your site never serves are a more reliable signal.

location ~* ^/(\.env|\.git|wp-login\.php|phpmyadmin) {
    return 444;
}

444 versus 403

Nginx 444 closes the connection without a response, which costs the scanner time and gives no information. Use 403 while testing so you can see what matches.

Open the Bot & scanner blocking generator

Frequently asked questions

Will this block Googlebot?

Not if you only match paths that do not exist on your site. Avoid blocking by broad user-agent patterns.

Guides