The Way Most Merchants Do It

You buy a domain, go to Shopify Settings → Domains, click "Connect existing domain", and you're done. It works. Your store loads, SSL is handled, everything looks fine.

And for basic use, it is fine. Shopify's default domain connection is genuinely solid — free SSL, automatic renewal, no configuration needed.

But you're also handing Shopify full control over every decision about who gets into your store and what you can see about them. There's no way to inspect traffic, no way to write your own rules, and no visibility into what's actually hitting your site beyond what Shopify chooses to show you.

The Shopify-Only Setup: Pros and Cons

What you get:

  • Zero setup complexity — point your DNS, done
  • Free SSL certificate, auto-renewed by Shopify
  • Shopify's built-in bot protection (a black box, but it's there)
  • Fully supported — Shopify will help you debug it

What you give up:

  • No ability to write your own firewall rules
  • No request-level logs — you see sessions, not traffic
  • No control over which bots can crawl your store
  • No way to block countries, IP ranges, or specific networks
  • No visibility into AI crawler activity hitting your products

That last point matters more than it used to. AI shopping agents from ChatGPT, Perplexity, and others are crawling Shopify stores constantly — and whether they can see your products affects whether you show up when someone asks an AI assistant for a recommendation. With a default Shopify setup, you have zero say in this.

What Changes When You Route Through Cloudflare

Shopify itself already runs on Cloudflare's infrastructure. A feature called Orange-to-Orange (O2O) lets you place your own free Cloudflare account in front of Shopify's layer. Traffic flows through your rules first, then Shopify handles the rest. Your store works exactly as before — checkout, SSL, redirects, everything — but now you're in the driver's seat.

Here's what you can actually do:

  • Allow AI bots full access — explicitly whitelist GPTBot, ClaudeBot, PerplexityBot so they can index your products and drive AI-powered discovery. By default, Cloudflare zones created after mid-2025 block these. You may already be invisible to AI search without knowing it.
  • Block bad bots — enable Bot Fight Mode with one toggle to stop scrapers, fake sessions, and traffic that corrupts your analytics and ad pixels
  • Block countries or regions — if you don't ship to China and 70% of your sessions are from there with zero orders, block the ASN (network operator) in seconds
  • Rate limit scrapers — stop automated tools hammering your product catalog, e.g. max 30 requests per minute per IP
  • See real request logs — not just "4,000 sessions" but every URL, user agent, status code, and response time, including traffic Shopify analytics never surfaces
  • WAF custom rules — write precise firewall rules for anything: block a specific IP range, challenge traffic from VPNs, protect specific pages

None of this requires a paid Cloudflare plan. The free tier covers all of the above.

How to Set It Up (The Short Version)

  1. Add your domain to Cloudflare — go to cloudflare.com, click "Add domain", enter your store domain, pick the free plan. Cloudflare scans your existing DNS records automatically.
  2. Fix your DNS records — delete any A record pointing to Shopify's IP (23.227.38.65) and replace with two CNAME records, both set to Proxied (orange cloud):
    Type Name Target Proxy
    CNAME @ shops.myshopify.com 🟠 Proxied
    CNAME www shops.myshopify.com 🟠 Proxied
    A small Shopify icon will appear next to each record — that's O2O confirming it's active.
  3. Update your nameservers — Cloudflare gives you two nameservers. Go to your domain registrar and replace the existing ones with Cloudflare's. Propagation takes a few hours.
  4. Set SSL to Full — in SSL/TLS → Overview, set mode to Full. Not Flexible.
  5. Turn OFF "Always Use HTTPS" — in SSL/TLS → Edge Certificates, leave this off. Shopify already handles the HTTPS upgrade. Turning this on can silently break your SSL renewal 60–90 days later.
  6. Connect the domain in Shopify — go to Settings → Domains → Connect existing domain, enter your domain. It will show Connected, possibly with an amber Cloudflare warning. That warning is expected — ignore it, your store is working.

Total time: about 20 minutes, plus a few hours waiting for nameservers to propagate.

The One Setting Most Merchants Get Wrong

After setup, go straight to Security → Bots in your Cloudflare dashboard and check what's configured. Cloudflare zones created after mid-2025 block AI crawlers by default. If you want ChatGPT and Perplexity to be able to see your products — and you probably do — you need to explicitly allow them. This is a one-minute fix once you're in Cloudflare, but it's invisible in a default Shopify setup.

Is It Worth It?

If you're happy with Shopify's defaults and don't need traffic control, the native setup is fine. But if you've ever looked at your analytics and wondered why 60% of your sessions have a 100% bounce rate and zero orders, or if you want AI assistants to be able to recommend your products, or if you just want to actually see what's hitting your store — routing through Cloudflare is a 20-minute setup that costs nothing and gives you a level of control Shopify simply doesn't offer.

Plenty of major brands already run it: Ruggable, Hodinkee, Mejuri, and dozens more run Cloudflare in front of Shopify in production every day.

Your store can too.