SO SORRY
yes, of course domain name - has multiple IPs, and these, change, I’m no expert in DNS, but use nslookup and many other tools.. I have no doubt that placed the first domain name, banip loaded a set of IPs (i.e. “ALL” that nslookup returned at that time), however, the domain kept working, in response to a ping, my suspicious, is that given that banip blocked, say 10 ips, the subsequent ping failed, and internally did another “nslookup” to pull more IPs, and then, started working on a totally NEW IP. I kept doing that about 10-15 times, i.e. each time added the new IP manually to the banip block, reloaded, and still, ping would “find” another IP, that previously did not show up in the nslookup.
nothing else changes as the DNS servers are fixed to 1.1.1.1 and not the ISP..
I think it’s GOOD that it is ADDING (as needed), but i think to REMOVE is probably not a good idea, due to the above description, that an nslookup is LIMITED in the amount of IPs it can return, even if the domain has, say 50 IPs globally, then it would return say 10 to my region, and those would be blocked, but, as mentioned, i think the blocking is “triggering” further nslookup to maybe find an alternate IP, and then ping DOES WORK on a new ip ![]()
so, if now banip would REMOVE prior ones, the next ping will find them, and so forth.
I think to add is good, as it would expand the set of inclusion, the removal should be more on the user end, like suggested before, if one feels it’s overly blocked, they can grep/remove the auto-added, and leave just the domain names, and let banip rebuild the block on the next reload.
Sorry for the confusion of the ip vs domain name, innocent typo that caused u to think i’m a total clueless, which is, pretty far from reality, but, such is world today, not much trust between entities ![]()
Hope to regain your trust and respect your time, way beyond you can imagine.. will try to find some time to look into it more deeply and also contribute later.
Stormy.



