- reject Register to IP domain - check for brute force attack - allow only two consecutive attempts to authenticate. If both failed block the account for 2 minutes.