Hi, my project agrogrupo-app (team: lalmari-4457s-projects) is on the Hobby plan and legitimate users are being blocked by the automatic DDoS Mitigation system, even though I have no custom rules, no IP blocking, and Bot Protection is set to Off.
In Firewall → Traffic, I can see the denials are attributed to "DDoS Mitigation," coming mostly from Telmex Colombia S.A. and UFINET Panama S.A. — both are normal residential/business ISPs in Colombia/Latin America that my real users (not bots) connect from.
Blocked request IDs: iad1::1789420292-jwOr0ROM1m3RbVVbuzeKCnzJbdRHXkV7 iad1::1789421038-oNBTFQofksOZrUbKLoKllOemvCvOpYLL iad1::1789421927-gQQ2VVLnNR3TR6NTyzJF36UEmB85AGO8
This is a production app used daily by a small business, and the false positives are preventing normal users from logging in. Since System Bypass Rules aren't available on the Hobby plan, could you please review why this ISP traffic is being flagged, and let me know if there's a way to fix this without upgrading?
Thanks in advance.