If you searched for Cloudflare in front of Shopify, how to block bots on Shopify, or Shopify bot traffic, you’ve probably already seen the same recommendation: put your own Cloudflare zone ahead of the store and filter junk before it reaches Shopify.
That instinct is right. By the time a bot has created a checkout, the mess is already spread across four places — your abandoned checkout list, your customer records, your analytics, and your email platform. Everything after that is cleanup. Stopping traffic at the door is better than scrubbing abandoned checkouts later.
Cloudflare documents this setup officially. Shopify does not support it. Both of those facts can be true at once — and neither closes the gap that still lets checkout bots and card-testing scripts through.
How Cloudflare Orange-to-Orange (O2O) works
Shopify already runs on Cloudflare. Orange-to-Orange (O2O) means your custom domain goes through your Cloudflare zone first, then Shopify’s. Traffic path: visitor → your Cloudflare WAF / bot rules → Shopify → storefront.
You set it up by pointing a proxied CNAME at shops.myshopify.com and managing DNS in Cloudflare. Cloudflare detects the Shopify relationship automatically. On the free plan you can turn on Bot Fight Mode; on paid plans you get more control with Super Bot Fight Mode, custom WAF rules, rate limiting, and ASN blocks. That is the toolkit people mean when they say “put Cloudflare in front of Shopify to block bots.”
Paid bot-firewall apps in the Shopify App Store — Armex is the one merchants mention most in Community threads — are the same idea with someone else’s network and a guided install. Same door-check pattern. Same limits.
It’s the difference between checking IDs at the door and checking them at the register. Anyone turned away at the door never generates a receipt to clean up.
Why merchants put Cloudflare in front of Shopify
Nothing blocked ever reaches you. A bot stopped at the edge doesn’t create an abandoned checkout, a fake customer, or a line in your analytics. There’s nothing to tag, delete, or explain later. Compare that to bots that reach checkout and wreck your abandonment rate.
Most bot attacks are running on autopilot. Scripts often hammer a hard-coded store URL with nobody watching. Move DNS, challenge datacenter ASNs, or turn on Bot Fight Mode, and a lot of that traffic dies at the door — sometimes for months. If you’re drowning in Shopify bot traffic right now, that relief is real even when it isn’t permanent.
Merchants say edge filtering helps. In a long-running Shopify Community thread about bot traffic wrecking analytics, one merchant reports a proxy setup “dramatically cut the garbage from hitting our site.” Another says that since deploying something similar, “we haven’t had a single bot-related issue.”
The catch: .myshopify.com is never behind your Cloudflare
Here’s the part setup guides underplay — and it isn’t a flaw in Cloudflare or in Armex. It’s how Shopify is built.
Your .myshopify.com address can never sit behind your WAF. Shopify controls that hostname completely. No merchant Cloudflare zone, no bot-firewall app, and no DNS change can put a checkpoint in front of yourstore.myshopify.com. The store stays fully open for business there. One merchant thread documents three months of bot traffic coming in that way at a store that already had Cloudflare and bot protection on its custom domain. It made no difference.
Bots that know what they’re doing skip your branded domain. They hit cart and checkout paths on .myshopify.com directly — including card-testing scripts that never render your theme, never see Bot Fight Mode, and never trip your country or ASN rules.
App-style “bridge” setups have a related version of the same problem: they often guard one hostname while shoppers (and Google) end up on a second address that goes straight to Shopify unscreened. Shopify publishes and redirects to your primary domain by design. Anything advertised that widely cannot stay secret.
The fair summary: Cloudflare O2O and bot-firewall apps stop a lot of blind, autopilot junk on your custom domain. They do not stop anyone who aims at .myshopify.com — or anyone who looks like a real shopper on a normal home connection by the time they reach checkout.
Trade-offs before you flip the orange cloud
None of these are automatic dealbreakers. They are costs of putting an extra network in front of your store.
Shopify does not support the proxy. Their help docs are blunt: a proxy in front of your store is not supported. It can affect certificate provisioning and weakens Shopify’s own view of where visitors came from. Your store will probably work fine. If something breaks, Shopify support’s first ask is often to turn the proxy off.
You own SSL and DNS foot-guns. O2O guides warn about Always Use HTTPS breaking Shopify certificate renewal, and about proxying records that should stay DNS-only. Save your original DNS somewhere outside Cloudflare before you switch. If your zone goes misconfigured, your store goes down with it.
Third-party firewall apps see customer data. Any company screening HTTPS traffic decrypts it first — names, emails, phones, shipping addresses. With a free Cloudflare account you are still trusting Cloudflare (Shopify already does for infrastructure). With a smaller bot-firewall vendor you are adding a new middleman. Check privacy terms, retention, and who else can access logs the same way you’d vet any company between your customers and your store.
Cancelling isn’t just uninstalling. DNS you pointed at a paid firewall keeps working after you stop paying. Leaving it aimed at a service you no longer use is a real risk. Clean up domain settings when you leave.
Country and IP blockers at the theme layer are a different tool. They hide the storefront in the browser. They are not a substitute for edge WAF rules, and neither layer scores a convincing checkout that already got through.
Where this leaves you
Block what you can, as early as you can. Cloudflare in front of Shopify — O2O, Bot Fight Mode, WAF rules, rate limits — is a sound first door for Shopify bot traffic on your custom domain. Paid apps in the same category can bring the same kind of relief with less DNS homework.
It just can’t be your only layer. It doesn’t cover .myshopify.com. It doesn’t stop card-testing and checkout bots that never touch your proxied hostname. And no door check can tell a bot on residential broadband from a real customer — which is most of what still reaches checkout.
Something has to catch what gets through, and that has to happen where a bot finally gives itself away: in the checkout itself.
That’s what CartWatch does. It can block by IP and country at the door, then scores every checkout that gets through — checking the email, verifying the address, spotting sessions that were never a real browser, and catching order speeds no human matches. Likely bots get tagged on the customer record with what flagged them, and get held back from your Klaviyo and Omnisend sends before an email goes out. If you’re comparing tools, our Blockify vs. Negate vs. CartWatch breakdown covers which one solves which problem.
Guard the door with Cloudflare if it fits. Then install CartWatch from the Shopify App Store and see what’s still getting in.