MySQL Error 1129: Host Is Blocked
Fix MySQL Error 1129 by inspecting host_cache and handshake errors, correcting the connection problem, then safely unblocking the client host.
On this page
MySQL Error 1129 (HY000, ER_HOST_IS_BLOCKED) means the server has blocked new connections from a client host after too many successive connection errors. The message commonly says Host '...' is blocked because of many connection errors; unblock with 'mysqladmin flush-hosts'. See the MySQL 8.4 error reference.
The host cache is used for non-local TCP connections. MySQL does not use it for localhost loopback TCP addresses such as 127.0.0.1 or ::1, or for Unix socket, named-pipe, and shared-memory connections. A local test can therefore succeed while a remote application host remains blocked. See DNS lookups and the host cache.
Inspect the blocked client and its connection errors
Before clearing the cache, ask an administrator to capture the client IP address as MySQL sees it and inspect the matching Performance Schema row:
SELECT
IP,
HOST,
HOST_VALIDATED,
SUM_CONNECT_ERRORS,
COUNT_HOST_BLOCKED_ERRORS,
COUNT_HANDSHAKE_ERRORS,
FIRST_ERROR_SEEN,
LAST_ERROR_SEEN
FROM performance_schema.host_cache
WHERE IP = '203.0.113.25';
Replace the example address with the affected client IP. SUM_CONNECT_ERRORS is not a count of every kind of connection problem: MySQL assesses only blocking protocol-handshake errors for validated hosts against max_connect_errors. The table also separates blocked-host and handshake-error counters. Its columns and meanings are documented in the host_cache table reference.
Check the configured threshold as well:
SHOW GLOBAL VARIABLES LIKE 'max_connect_errors';
Correct the handshake problem before unblocking
Review the application host’s network path, firewall or proxy behavior, TLS settings, and MySQL client/server compatibility. Repeatedly retrying a connection that fails during the protocol handshake can add more errors. If the client uses a proxy, NAT, or a pool of application instances, confirm which source IP MySQL actually sees before changing the account or server settings.
Do not treat Error 1129 as a password error. Failed authentication has a different code; see MySQL Error 1045: access denied for a user. Error 1129 concerns a host blocked by the connection-error threshold, while Error 1130 means the server does not allow the client host to connect under its account host rules.
Unblock the host after collecting evidence
Flushing the host cache clears all cached host entries and unblocks blocked hosts, not only the one client shown in the error. After recording the relevant row and correcting the handshake problem, an administrator can run:
mysqladmin --host=db.example.com --user=admin --password flush-hosts
The client prompts for the password. In MySQL 8.4, this command requires RELOAD or DROP on performance_schema.host_cache. Another option is TRUNCATE TABLE performance_schema.host_cache, which requires the table’s DROP privilege. Do not use the old FLUSH HOSTS SQL statement on MySQL 8.4; it was removed in that release. See the MySQL 8.4 guide to flushing the host cache.
Avoid masking recurring network failures
Increasing max_connect_errors makes the threshold harder to reach, but it does not repair broken TCP or TLS handshakes. MySQL’s guidance is to check for connection problems before raising the threshold. Change this global setting only after reviewing the handshake counters and addressing the source of the errors with the database administrator.
For a quick classification of related connection codes, use the MySQL connection error triage helper. For the rest of the error guides, browse MySQL Error Troubleshooting.