Monthly Cloudflare blocklist review to catch stale IP blocks

By General Input

Every month we check who really owns the addresses you block, then flag the ones that may now be turning away real customers.

Integrations

  • IPinfo
  • Cloudflare
  • Slack Bot

Type

Agentic Task

Categories

  • Engineering
  • Operations

On the first Monday of every month at 9am, review my Cloudflare blocklist and tell me which rules have gone stale. Never delete anything automatically, because I want to approve every removal myself.

Start by pulling every entry using Cloudflare's List IP Access Rules operation, covering both my zone-level and my account-level rules. Each rule tells you what it targets (a single IP, a CIDR range, an ASN, or a country), the mode it applies (block, challenge, or allow), any note attached to it, and when it was created. Use the creation date to work out how old each block is.

Then enrich each rule with IPinfo. For single IPs and CIDR ranges, use Get Full IP Details to see the current owner, city, country, and network type. Use Core / Plus IP Lookup to check the privacy and VPN detection flags. For any rule that blocks a whole autonomous system, use Get ASN Details to see the organisation behind it, its country, and the prefixes it covers, so I can tell how much of the internet that one rule actually reaches.

Two data caveats to handle gracefully. IPinfo's privacy and VPN detection, company, and carrier fields are paid-plan data, and a field that is not included in my plan is simply left out of the response rather than failing the request. Do not read a missing field as evidence of anything: carry on using the location and network owner data, and say plainly in the digest when the VPN signal was unavailable rather than implying the address came back clean. Separately, skip any entry that comes back marked as a bogon (a non-routable address such as an internal 10.x or 192.168.x range), since there is no location or network data to judge it against. Do not report those as unknown.

Judge each block against what the data shows now, and sort them into keep, review, and likely stale. Call out the risky ones specifically: residential or mobile ranges that were most likely reassigned to innocent users since the block was added; blocks that now cover a major cloud or CDN provider that real customer traffic runs through; country-wide and ASN-wide rules that are far broader than whatever the original threat was; and any rule older than twelve months with no remaining VPN, proxy, or hosting signal.

Post the result to my security channel in Slack as a grouped digest, sending it as the bot. Group the rules under likely stale, review, and keep, with likely stale first so the actionable items lead. For each rule, show the rule ID, what it targets, how old it is, what IPinfo reports about it today, and a one-line recommendation. Keep recommendations concrete, for example: 'Residential broadband range in Vietnam, no proxy or hosting signal, blocked 19 months ago, strong candidate for removal.'

If the blocklist is long, summarise the keep group as a count with a couple of examples rather than listing every rule, so the digest stays readable. If nothing looks stale this month, still post a short all-clear noting how many rules were checked. Close every digest with a reminder that nothing was changed and that any removal needs my approval first.

Related prompts

Explore more prompts
A brand asset library your marketing team actually searchesTurn Mailjet email clicks into ranked HubSpot follow-upsClean out the Looker dashboards and Looks nobody opensLiveKit live operations console for room moderationWake up dormant Keap leads with a researched reasonLiveChat coverage board for planning next week's shiftsPhone routing control panel for LiveKit voice agentsLinkedIn Ads budget pacing dashboard for every client accountGive your team Looker numbers without buying more seatsPause marketing emails to escalated customers, then restore them