Cordon

Does Shopify Block Bots and Countries by Default? (2026)

A clear answer on what Shopify blocks natively and what it does not. Shopify handles DDoS and platform security, but does not block bots, scrapers, VPNs, or countries at the visitor level.

Bas Lefeber5 min read
Diagram: a split showing what Shopify protects (platform, DDoS, checkout PCI) versus what it leaves to the merchant (bots, scrapers, VPNs, countries, IP rules)
On this page

TL;DR: Shopify secures its platform (DDoS defense, PCI-compliant checkout, SSL) but does not block bots, scrapers, VPNs, proxies, Tor, or countries at the visitor level for your individual store. That traffic reaches your storefront unless you add a filtering app. Platform security and traffic filtering are two different jobs, and Shopify only does the first. Cordon does the second, with a free plan for country and bot blocking.

Before installing anything, most merchants ask a reasonable question: does Shopify already handle this? It is worth a precise answer, because the marketing around both Shopify and blocking apps tends to blur the line. Here is exactly what Shopify blocks on its own and what it leaves to you.

What Shopify does protect

Shopify is a secure platform, and it is not fair to imply otherwise. Out of the box you get:

  • Platform-level DDoS protection. Shopify defends its infrastructure against large-scale volumetric attacks. If a botnet tries to take the platform down, that is Shopify's problem to absorb, and they do.
  • PCI DSS Level 1 compliant checkout. Card data is handled in Shopify's hosted, certified checkout. You are not storing card numbers, and the payment surface is Shopify's responsibility.
  • SSL on every store. All traffic is encrypted end to end.
  • Basic edge filtering of abusive infrastructure. Shopify drops some obviously malicious traffic at its network edge before it reaches any store.
  • Order-level fraud analysis on qualifying plans, which scores placed orders for risk.

This is real protection, and it is why "is Shopify secure" has a genuinely reassuring answer. The platform is secure. But platform security is not the same as controlling who reaches your specific store.

What Shopify does not block

Here is the part that surprises people. None of the following is handled by Shopify at your store's visitor level:

Traffic typeBlocked by Shopify natively?What it does to your store
Scrapers and price monitorsNoCopy your catalog and pricing
Checkout and drop botsNoSnipe limited inventory
Fake-account and form-spam botsNoBloat your list, hurt deliverability
VPN and proxy trafficNoHide fraud behind anonymized IPs
Tor exit nodesNoMaximum-anonymity abuse
Specific countriesNo (Markets is not a block)Browse, cart, and scrape freely
Individual bad IPsNoReturn repeatedly

Every row here reaches your storefront by default. Shopify's edge filtering catches crude, platform-wide abuse, not the store-specific traffic that costs an individual merchant money: the competitor scraping your prices, the bot creating fake accounts, the card tester behind a VPN, the visitor from a country you never ship to.

Why the "Markets is not a block" point matters

The single most common misconception is that Shopify Markets blocks countries. It does not. Markets controls where you sell: which countries appear as markets, which currencies you support, where you ship, and which shipping addresses checkout will accept. A visitor from a country you excluded from Markets can still load every page, read every product, download every image, add to cart, and pull your entire catalog through /products.json. Markets is a selling configuration, not a traffic filter. We unpack this fully in how to block a country on Shopify.

The same shape applies to fraud analysis and VPNs. Fraud analysis scores an order after it exists. It does not stop an anonymized visitor from reaching checkout. If you want the anonymized visit stopped before the order, that is a VPN and proxy blocking job, and Shopify does not do it.

Platform security versus traffic filtering

The clearest way to hold both ideas at once:

  • Platform security (Shopify's job): keeping the platform up, keeping checkout PCI-compliant, encrypting traffic, absorbing DDoS. Shopify does this well and you do not need an app for it.
  • Traffic filtering (your job): deciding which visitors reach your store. Bots, scrapers, anonymized traffic, unwanted countries, repeat-offender IPs. Shopify leaves this to you, and it is what a filtering app exists to do.

Confusing the two is what leads merchants to either over-trust ("Shopify handles security, so I am covered") or over-worry ("is my store even safe?"). The store is safe. The traffic is unfiltered.

What to add, and when

You do not need a traffic filter on day one of a store with no traffic. You need it when you start seeing the problems: a competitor cloning your catalog, bots inflating your ad clicks, chargebacks from mismatched-country orders, fake signups flooding your email tool, a limited drop getting sniped. When any of those start, an app that filters at the visit level is the fix.

Cordon does exactly that. It blocks bots, scrapers, VPNs, proxies, Tor, specific countries, and individual IPs before your page renders, in under 50 milliseconds, installed as a theme app extension so there is no script tag and no Lighthouse hit. And it always allows verified search engines, so filtering aggressively never touches your SEO. For the full picture of what belongs at each layer of store protection, see the Shopify security checklist.

Frequently asked questions

Does Shopify block bots automatically?

Shopify protects its platform from large-scale attacks like DDoS and filters some abusive infrastructure at its network edge. It does not block scrapers, price monitors, catalog bots, checkout bots, or fake-account bots at the visitor level for your individual store. That traffic reaches your storefront unless you add a blocker.

Can Shopify block a country by default?

No. Shopify Markets controls where you sell and ship, and checkout can reject shipping addresses you do not serve, but nothing in Shopify stops a visitor from any country from browsing your store, adding to cart, or scraping your catalog. Visitor-level country blocking requires an app or your own edge infrastructure.

Does Shopify detect VPN or proxy traffic?

No. Shopify has no setting that identifies whether a visitor's IP is a VPN, proxy, or Tor exit. Shopify fraud analysis scores an order after it is placed, but it does not block anonymized visits before they reach checkout.

Is Shopify secure without any extra apps?

The platform itself is secure. Shopify is PCI DSS Level 1 certified, hosts checkout, provides SSL on every store, and defends its own infrastructure. What it does not do is filter unwanted visitor traffic to your specific store. Platform security and traffic filtering are different jobs, and Shopify only does the first.

What do I need to add to block unwanted traffic?

A traffic-filtering app like Cordon. It blocks bots, scrapers, VPNs, proxies, Tor, specific countries, and individual IPs at the visit level, before your page renders, while always allowing verified search engines like Googlebot. The free plan covers country and bot blocking, and paid plans add VPN, proxy, and Tor detection.

Wrapping up

Shopify keeps the platform secure and the checkout compliant. It does not decide who reaches your store, and it does not block bots, scrapers, VPNs, or countries at the visitor level. That job is yours, and it is what a filtering app is for. If you have started seeing traffic you would rather not serve, try Cordon on the Shopify App Store. The free plan covers country and bot blocking, every paid plan has a 7-day free trial, and the pricing page has the full breakdown.

Related guides