Bot traffic is corrupting Shopify analytics and killing ad performance for thousands of merchants. Here's how to put Cloudflare in front of your store — for free — and take back control of who gets in.
Your Shopify Analytics Are Probably Lying to You
During the 2024 holiday season, bots made up over 57% of ecommerce traffic — the first time automated traffic outnumbered real shoppers. By mid-2026, Cloudflare reported that automated systems had passed humans across its entire network.
For Shopify merchants, this isn't just noise in a chart. Bot sessions inflate every metric you pay for. They fill your analytics with visits that will never buy. They corrupt your Meta Pixel, so Facebook and Google optimize toward more junk traffic. And Shopify's built-in protection — while real — is a black box you can't tune or inspect.
The fix is putting your own Cloudflare account in front of your store. And the core setup is free.
Why Cloudflare Works for Shopify
Shopify already runs on Cloudflare's infrastructure. A feature called Orange-to-Orange (O2O) lets you place your own Cloudflare zone in front of Shopify's — so traffic flows through your rules first, then Shopify's. You write the rules. You see the logs. Bots get stopped before they ever touch your store.
The practical result: bots never generate Shopify sessions. Your analytics get cleaner. Your ad pixels stop feeding on junk. And you didn't have to pay for a Shopify Plus plan or a third-party app to get there.
How to Set It Up
- Add your domain to Cloudflare — go to cloudflare.com, click "Add domain", enter your store domain, and choose the free plan.
- Set up your DNS records — Cloudflare will scan your existing records. Make sure you have two CNAME records pointing at
shops.myshopify.com — one for your root domain and one for www — both with the orange cloud (Proxied) enabled. A small Shopify icon will appear next to each record confirming O2O is active.
- Update your nameservers — Cloudflare gives you two nameservers. Replace the ones at your domain registrar with these. Propagation takes a few hours.
- Set SSL mode to Full — in SSL/TLS → Overview, set the mode to Full. Do not use Flexible.
- Turn OFF "Always Use HTTPS" — in SSL/TLS → Edge Certificates, leave this toggle off. Shopify already handles the HTTP to HTTPS upgrade. Enabling this can silently break your SSL certificate renewal 60–90 days later.
The Bot Controls You Now Have
Once your domain is proxied through Cloudflare, head to the Security section. On the free plan you can:
- Bot Fight Mode — one toggle, on by default, blocks the most common scraper bots immediately
- WAF Custom Rules — block or challenge traffic by country, IP, user agent, or ASN (the network operator behind the bot)
- Rate Limiting — stop scrapers hammering your product catalog (e.g. max 30 requests per minute per IP)
- Analytics → Security — see exactly what's being blocked and where it's coming from
Upgrading to Cloudflare Pro ($25/month) adds a full managed ruleset — OWASP Top 10, known bad bot signatures — updated automatically with no rule-tuning required.
One Thing to Watch
Bots in 2026 sometimes bypass your custom domain entirely and hit your yourstore.myshopify.com address directly, bypassing Cloudflare altogether. The simplest fix: in Shopify admin go to Settings → Customer accounts and require customers to log in before checkout. This forces authentication at Shopify's own database level — something no bot can bypass.
Worth It?
The free Cloudflare setup takes about 20 minutes and immediately gives you more bot control than any Shopify plan offers natively. Your analytics get cleaner, your ad pixels stop learning from fake sessions, and you finally have visibility into what's actually hitting your store.
For most merchants, that's the whole job done — for $0.
Connect Claude to your Shopify store
Install ShopMCP and Claude can edit your store in 2 minutes. No developer needed.
Install ShopMCP →