How to Configure Chatbox Security and Anti-Bot Protection
This article explains how to configure domain security and anti-bot protection for the Crisp chatbox.
Crisp includes security mechanisms to prevent your website chat widget from being used on unauthorized domains and to protect chat sessions from automated traffic, fake visitors, spam, and message floods.
Most anti-bot protection works automatically. From the Chatbox Security settings, you can also control which domains are allowed to use your chatbox and temporarily increase the protection level when your workspace is under attack.
In this guide, you will learn how to:
- Understand Crisp chatbox security → see which protections are applied automatically and which ones you can configure
- Lock the chatbox to your website domain → prevent your chatbox from loading on unauthorized websites
- Add additional domains → use the same Crisp workspace securely across several websites
- Understand automatic anti-bot protection → learn how Crisp protects chat sessions by default
- Increase anti-bot protection during an attack → choose a stronger protection level when needed
- Use Under Attack mode only when necessary → apply the strongest protection temporarily
- Troubleshoot chatbox security issues → check common domain and anti-bot configuration problems
Understand Crisp chatbox security
Chatbox Security settings are available from Settings → Chatbox Settings → Chatbox Security.

Two types of protection are relevant when securing your Crisp chatbox:
- Domain protection → controls which websites are allowed to load the chatbox linked to your workspace
- Anti-bot protection → protects chat sessions and messages against automated abuse and traffic floods
Crisp applies anti-bot safeguards automatically, so you normally do not need to change the protection level.
Manual settings are available when you need to authorize additional domains or temporarily reinforce protection during an attack.
For a broader overview of platform security, read how Crisp manages security across its services.
Lock the chatbox to your website domain
The Lock the chatbox to website domain (and subdomains) option prevents your Crisp chatbox from being loaded from unauthorized domains.
This protects the Crisp Website ID associated with your workspace from being reused on another website.
To enable domain locking:
- Open Settings → Chatbox Settings → Chatbox Security
- Find General Options
- Enable Lock the chatbox to website domain (and subdomains)
When enabled, Crisp checks the domain where the chatbox is loaded against the domains configured for your workspace.
Your configured website and its subdomains can continue loading the chatbox normally.
Add additional domains
You can authorize several domains to use the same Crisp workspace while keeping domain locking enabled.
This is useful when the same chatbox needs to be installed on websites such as:
To add another authorized domain:
- Open Settings → Workspace Settings
- Open your workspace information
- Find Additional domains
- Add the domain you want to authorize
- Save your changes

Once the domain is added, the same Crisp chatbox can load from that website without disabling Lock the chatbox to website domain (and subdomains).
Add each domain where the chatbox is legitimately installed.
To install the widget on another website, follow how to install Crisp Live Chat on a custom website.
Understand automatic anti-bot protection
Crisp automatically protects the chatbox against abusive traffic.
These protections can apply when visitors:
- Create a new chat session
- Join an existing chat session
- Send messages through the chatbox
When Crisp detects certain abnormal traffic conditions, additional protections such as Proof-of-Work challenges can be applied automatically before a visitor enters a chat session.
This helps limit automated session creation, fake visitor floods, and message spam without requiring a manual configuration.
Increase anti-bot protection during an attack
If your chatbox is receiving abnormal bot traffic or spam, you can manually increase its anti-bot protection level.
Go to Settings → Chatbox Settings → Chatbox Security, then find Anti-Bot Protections.

The following levels are available:
Protection level | Behavior |
|---|---|
Default (Recommended) | Uses Crisp automatic anti-bot protections |
Challenge all users (Easy) | Adds a light verification challenge for chatbox users |
Challenge all users (Medium) | Adds a stronger verification challenge |
Challenge all users (Hard) | Applies a stricter verification challenge |
I'm under attack (Extreme) | Forces the strongest protection for chatbox users |
To change the protection level:
- Open Anti-bot protection level
- Select the level you want to apply
- The new protection is automatically saved
The higher the protection level, the more verification may be required before a visitor can enter the chat session or send a message.
This can increase the time required to open or interact with the chatbox.
Use Under Attack mode only when necessary
I'm under attack (Extreme) is the strongest manual protection level.
Use it when your workspace is actively receiving a large amount of automated traffic, fake visitor sessions, or spam messages and the default protections are not sufficient.
To enable it:
- Open Settings → Chatbox Settings → Chatbox Security
- Find Anti-Bot Protections
- Open Anti-bot protection level
- Select I'm under attack (Extreme)
Extreme mode forces additional verification for chatbox users. While it is enabled:
- Opening the chatbox may take longer
- Sending a message may require additional verification
- The normal chatbox experience can be temporarily degraded
- Website visitors may no longer appear normally in MagicMap
To restore the default protection, open the same setting and select Default (Recommended).
Crisp will continue applying its automatic anti-bot safeguards after Extreme mode is disabled.
Troubleshooting
Most security-related chatbox issues can be checked from the domain and anti-bot settings.
Issue | What to check |
|---|---|
The chatbox takes longer to open or send messages | Check whether a manual Anti-bot protection level is enabled |
The chatbox works on the main domain but not another website | Check Additional domains and your domain lock configuration |
Legitimate visitors cannot connect to the chatbox | Review the current anti-bot protection level and return to Default if stronger protection is no longer required |
Visitors no longer appear normally in MagicMap | Check whether I'm under attack (Extreme) is enabled |
The chatbox displays an Invalid Website error | Confirm that the current website is authorized and that the correct Website ID is installed |
For domain-related errors, follow the Crisp Invalid Website troubleshooting guide.
For other loading or connection problems, read how to troubleshoot Crisp chatbox visibility issues.
Updated on: 21/08/2026
Thank you!