# Traffic rules: block or allow hits

> Use traffic rules to block or allow analytics hits by hostname, path, referrer, country, IP range, browser or event, for example to skip your office or staging.

**Site settings → Traffic rules** has seven lists. Each list is either a
**block list** (matching hits are dropped) or an **allow list**
(everything else is dropped). An empty list does nothing.

| List | Matches | Example |
|---|---|---|
| Hostnames | The page's hostname | `staging.example.com`, `*.vercel.app` |
| Paths | The page path | `/admin/*`, `/internal/*` |
| Referrers | The referrer's hostname | `spam-site.example` |
| Countries | ISO country code | `XX` |
| IP ranges | The visitor's IP, IPv4 or IPv6 CIDR | `203.0.113.0/24` |
| User agents | Browser family and major version | `Chrome 79` |
| Events | Custom event names | `Test event` |

Patterns use `*` wildcards and are case-insensitive. IP ranges use CIDR
notation.

## The test box

Enter a URL, referrer, country or IP to see whether a hit would be
counted and which rule would drop it.

## Privacy

IP ranges are checked in memory during ingest, like everything else about
the IP. Blocked hits aren't stored. We only count them per list, shown in
the Overview's footer. Blocked hits don't count toward usage.

## Common uses

- Exclude your office or VPN: block its IP range.
- Ignore preview deployments: block `*.vercel.app` or `*.netlify.app`, or
  allow only your production hostnames.
- Only count one country for a local site: allow list with that country.
