> ## Knowledge Base Index
> Fetch the complete knowledge base index at: https://help.crisp.chat/sitemap.xml
> Use this file to discover available pages before exploring further.
> Pure-Markdown content can be obtained by appending a '.md' suffix to the content URLs listed in the sitemap (without the trailing slash).

# How to Configure Chatbox Security and Anti-Bot Protection

*This article explains how to configure domain security and anti-bot protection for the Crisp chatbox.*

Crisp includes security mechanisms to prevent your [website chat widget](https://crisp.chat/en/livechat/) from being used on unauthorized domains and to protect chat sessions from automated traffic, fake visitors, spam, and message floods.

Most anti-bot protection works automatically. From the Chatbox Security settings, you can also control which domains are allowed to use your chatbox and temporarily increase the protection level when your workspace is under attack.

**In this guide, you will learn how to:**

* [Understand Crisp chatbox security](#1-understand-crisp-chatbox-security) → see which protections are applied automatically and which ones you can configure
* [Lock the chatbox to your website domain](#1-lock-the-chatbox-to-your-website-domain) → prevent your chatbox from loading on unauthorized websites
* [Add additional domains](#1-add-additional-domains) → use the same Crisp workspace securely across several websites
* [Understand automatic anti-bot protection](#1-understand-automatic-anti-bot-protection) → learn how Crisp protects chat sessions by default
* [Increase anti-bot protection during an attack](#1-increase-anti-bot-protection-during-an-attack) → choose a stronger protection level when needed
* [Use Under Attack mode only when necessary](#1-use-under-attack-mode-only-when-necessary) → apply the strongest protection temporarily
* [Troubleshoot chatbox security issues](#1-troubleshooting) → check common domain and anti-bot configuration problems
---

# ${color}[#0080dd](Understand Crisp chatbox security)

Chatbox Security settings are available from **Settings → Chatbox Settings → Chatbox Security**.

![](https://storage.crisp.chat/users/helpdesk/website/-/8/7/a/e/87ae2703583ac800/crisp-chatbox-security-setting_xzqu4x.png =850x574)

Two types of protection are relevant when securing your Crisp chatbox:

* **Domain protection** → controls which websites are allowed to load the chatbox linked to your workspace
* **Anti-bot protection** → protects chat sessions and messages against automated abuse and traffic floods

Crisp applies anti-bot safeguards automatically, so you normally do not need to change the protection level.

Manual settings are available when you need to authorize additional domains or temporarily reinforce protection during an attack.

For a broader overview of platform security, read [**how Crisp manages security across its services**](https://help.crisp.chat/en/article/how-crisp-manages-security-on-its-services-1oz4ttl/).
---

# ${color}[#0080dd](Lock the chatbox to your website domain)

The **Lock the chatbox to website domain (and subdomains)** option prevents your Crisp chatbox from being loaded from unauthorized domains.

This protects the [Crisp Website ID](https://help.crisp.chat/en/article/how-to-find-your-crisp-website-id-1ylqx1s/) associated with your workspace from being reused on another website.

**To enable domain locking:**

1. Open **Settings → Chatbox Settings → Chatbox Security**
2. Find **General Options**
3. Enable **Lock the chatbox to website domain (and subdomains)**

When enabled, Crisp checks the domain where the chatbox is loaded against the domains configured for your workspace.

Your configured website and its subdomains can continue loading the chatbox normally.

| If your chatbox displays an **Invalid Website** error after enabling domain locking, read [**how to troubleshoot "Invalid Website" errors in the Crisp chatbox**](https://help.crisp.chat/en/article/how-to-troubleshoot-invalid-website-errors-in-the-chatbox-8j93zr/).
---

# ${color}[#0080dd](Add additional domains)

You can authorize several domains to use the same Crisp workspace while keeping domain locking enabled.

This is useful when the same chatbox needs to be installed on websites such as:

* example.com
* example.fr
* app.example.com

**To add another authorized domain:**

1. Open **Settings → Workspace Settings**
2. Open your workspace information
3. Find **Additional domains**
4. Add the domain you want to authorize
5. Save your changes

![](https://storage.crisp.chat/users/helpdesk/website/-/8/7/a/e/87ae2703583ac800/add-additional-domains-to-cris_oyeyu.png =750x424)

Once the domain is added, the same Crisp chatbox can load from that website without disabling **Lock the chatbox to website domain (and subdomains)**.

Add each domain where the chatbox is legitimately installed.

||| Only add domains that you control or explicitly want to authorize for this Crisp workspace.

To install the widget on another website, follow [**how to install Crisp Live Chat on a custom website**](https://help.crisp.chat/en/article/how-to-install-crisp-live-chat-software-on-a-custom-website-10wcj3l/).
---

# ${color}[#0080dd](Understand automatic anti-bot protection)

Crisp automatically protects the chatbox against abusive traffic.

These protections can apply when visitors:

* Create a new chat session
* Join an existing chat session
* Send messages through the chatbox

When Crisp detects certain abnormal traffic conditions, additional protections such as **Proof-of-Work challenges** can be applied automatically before a visitor enters a chat session.

This helps limit automated session creation, fake visitor floods, and message spam without requiring a manual configuration.

|| In normal conditions, keep the anti-bot protection level on **Default (Recommended)**. Crisp applies the standard protections automatically.
---

# ${color}[#0080dd](Increase anti-bot protection during an attack)

If your chatbox is receiving abnormal bot traffic or spam, you can manually increase its anti-bot protection level.

Go to **Settings → Chatbox Settings → Chatbox Security**, then find **Anti-Bot Protections**.

![](https://storage.crisp.chat/users/helpdesk/website/-/8/7/a/e/87ae2703583ac800/crisp-chatbox-anti-bot-protect_1yllioh.png =750x371)

The following levels are available:

| Protection level | Behavior |
| ---- |
| **Default (Recommended)** | Uses Crisp automatic anti-bot protections |
| **Challenge all users (Easy)** | Adds a light verification challenge for chatbox users |
| **Challenge all users (Medium)** | Adds a stronger verification challenge |
| **Challenge all users (Hard)** | Applies a stricter verification challenge |
| **I'm under attack (Extreme)** | Forces the strongest protection for chatbox users |

**To change the protection level:**

1. Open **Anti-bot protection level**
2. Select the level you want to apply
3. The new protection is automatically saved

The higher the protection level, the more verification may be required before a visitor can enter the chat session or send a message.

This can increase the time required to open or interact with the chatbox.
---

# ${color}[#0080dd](Use Under Attack mode only when necessary)

**I'm under attack (Extreme)** is the strongest manual protection level.

Use it when your workspace is actively receiving a large amount of automated traffic, fake visitor sessions, or spam messages and the default protections are not sufficient.

**To enable it:**

1. Open **Settings → Chatbox Settings → Chatbox Security**
2. Find **Anti-Bot Protections**
3. Open **Anti-bot protection level**
4. Select **I'm under attack (Extreme)**

Extreme mode forces additional verification for chatbox users. While it is enabled:

* Opening the chatbox may take longer
* Sending a message may require additional verification
* The normal chatbox experience can be temporarily degraded
* Website visitors may no longer appear normally in MagicMap

||| **Under Attack mode should only be enabled temporarily.** Once the abusive traffic has stopped, return the protection level to **Default (Recommended)**.

To restore the default protection, open the same setting and select **Default (Recommended)**.

Crisp will continue applying its automatic anti-bot safeguards after Extreme mode is disabled.
---

# ${color}[#0080dd](Troubleshooting)

Most security-related chatbox issues can be checked from the domain and anti-bot settings.

| Issue | What to check |
| ---- |
| **The chatbox takes longer to open or send messages** | Check whether a manual **Anti-bot protection level** is enabled |
| **The chatbox works on the main domain but not another website** | Check **Additional domains** and your domain lock configuration |
| **Legitimate visitors cannot connect to the chatbox** | Review the current anti-bot protection level and return to **Default** if stronger protection is no longer required |
| **Visitors no longer appear normally in MagicMap** | Check whether **I'm under attack (Extreme)** is enabled |
| **The chatbox displays an Invalid Website error** | Confirm that the current website is authorized and that the correct Website ID is installed |

For domain-related errors, follow [**the Crisp Invalid Website troubleshooting guide**](https://help.crisp.chat/en/article/how-to-troubleshoot-invalid-website-errors-in-the-chatbox-8j93zr/).

For other loading or connection problems, read [**how to troubleshoot Crisp chatbox visibility issues**](https://help.crisp.chat/en/article/how-to-troubleshoot-chatbox-visibility-issues-7v450s/).