Bot Prevention

How to Stop Bots From Creating Klaviyo Active Profiles

Most of the damage bots do to a Shopify store is measured in confusion: junk in the abandoned checkout list, an analytics funnel that stops meaning anything, customer records nobody wants. Klaviyo turns that confusion into a bill. It charges based on active profiles, bot checkouts create active profiles, and the fake profiles they create don’t unsubscribe, don’t bounce reliably, and don’t go away on their own.

The result is a Klaviyo bill that grows with your bot traffic instead of your business. Here’s how to stop that — and why the usual advice (CAPTCHA, double opt-in, cleanup segments) doesn’t close the gap for checkout-created profiles.

How Klaviyo active profiles drive your bill

Klaviyo’s pricing tiers are based on the number of active profiles in your account, and the definition is broader than most merchants assume. In Klaviyo’s own words, “any profile that can be emailed through Klaviyo is considered an active email profile.” Not profiles you emailed. Not profiles who subscribed. Profiles that could be emailed — including “never subscribed” contacts who only entered an email at Shopify checkout.

Klaviyo splits those into two categories in its own documentation on active profiles:

  1. Subscribers — people who filled out a form or otherwise explicitly consented to marketing.
  2. General engagement — people whose email arrived without explicit opt-in, “such as someone who placed an order or abandoned a checkout.”

That second category is the one that matters here. A bot that fills in an email at checkout and leaves lands squarely inside it. Those never-subscribed profiles still count toward your active profile limit.

This got more expensive in February 2025, when Klaviyo moved to enforcing that your plan match your active profile count. Per Klaviyo’s FAQ on the change, accounts that exceed their plan limit now get automatically upgraded at the start of the next billing cycle. Profile growth used to be something you could ignore until you chose to deal with it. Now it moves your bill without asking.

Why Shopify bot checkouts create billable Klaviyo profiles

The Shopify integration syncs checkout activity into Klaviyo, and a Started Checkout event carries an email with it. That email becomes a profile — whether or not the shopper opted in.

A merchant asked Klaviyo directly whether profile creation could be restricted to newsletter subscribers only. The answer from Klaviyo’s community team was unambiguous:

“If you have the Shopify integration, there isn’t currently a way to prevent people who provide their email at checkout, but don’t subscribe, from becoming a profile in Klaviyo.”

The recommended workaround is to filter sends — add a “person can receive email marketing because person subscribed” condition to your flows and segments. That protects your deliverability. It does nothing for your bill, because the profile still exists and still counts as an active profile. In the same thread, another merchant put the gap plainly: “Klaviyo is charging us for 40K profiles, but only 5k are active and opted in.”

When a store is under a bot attack — spam signups, fake abandoned checkouts, or a full list bombing run — the scripts submit an email address on every pass. Every run is a Started Checkout, and every Started Checkout is a Klaviyo profile.

And the opt-in box doesn’t save you either. In the checkouts CartWatch scores across merchant stores, bots routinely tick the marketing consent box — it’s ordinary behavior, not an edge case. That makes sense: a script filling in every field on a form has no particular reason to skip a checkbox, and for the ones harvesting discount codes, getting into your flows is the whole objective.

So there are two ways in, and they meet at the same line on your invoice:

  • The bot doesn’t opt in. Klaviyo creates the profile anyway, from the checkout event, and it counts as an active profile under “general engagement” — often showing as never subscribed.
  • The bot does opt in. You get the billable active profile and a subscriber — one that enters your welcome flow, receives your campaigns, and lands in the denominator of every open and click rate you look at.

The second path costs strictly more: the same charge, plus the sends, plus SMS credits if a phone number came with it, plus the deliverability damage of mailing an address that never actually asked for anything. Klaviyo lists e-commerce checkouts first among the surfaces attackers exploit in its guidance on list bombing, which it defines as “a malicious attack where the attacker exploits a signup form or checkout page by making a large number of fake submissions.”

How list bombing and fake profiles raise your Klaviyo bill

The volumes merchants report aren’t dramatic. One described roughly 20 fake accounts a day creating profiles and starting checkouts without ever adding to cart — “about 3 signups every 2 hrs. everyday, and I can’t seem to stop it.” Another reported 2,500+ spam bot email signups in about two months against 24 legitimate popup conversions.

Twenty a day is about 600 a month. Against Klaviyo’s published email tiers, which run roughly:

Active profilesApprox. monthly cost
250 (free)$0
500~$20
1,000~$30
2,500~$60
5,000~$100
10,000~$150
25,000~$400
50,000~$720

Take a store sitting at 4,400 real profiles on the 5,000 tier at ~$100/month. Six hundred bot profiles a month puts it over 5,000 inside the first month, and the auto-upgrade moves it to the 10,000 tier at ~$150. That’s a 50% increase driven entirely by traffic that will never open an email — and the fill rate doesn’t stop, so the next tier is roughly nine months out.

At 2,500 fake profiles in two months, a store with 8,000 real contacts crosses 10,000 and keeps going. That’s how a modest bot problem becomes a permanent bump in your Klaviyo bill.

Why fake profiles don’t leave your active profile count

The instinct is that junk profiles age out. Some do — Klaviyo automatically suppresses hard bounces, and a suppressed profile stops counting toward active profiles. But that only catches addresses that fail delivery.

A lot of bot-submitted addresses don’t fail. List bombing frequently uses real, deliverable addresses belonging to real people who have no idea they were signed up, which is exactly why Klaviyo warns that sending to them produces spam complaints and blocklisting rather than clean bounces. Randomized addresses on live domains behave the same way at the SMTP layer. Those fake profiles are deliverable, so they never auto-suppress, and they never unsubscribe because nobody is reading. They sit in your active profile count paying rent until you personally suppress them.

The billing hit is also the smaller half of the problem. Klaviyo’s list-bombing guidance is direct about the rest: higher hard bounce rates, higher spam complaints, lower open rates, damaged sender reputation, spam trap hits, and potentially getting blocklisted so your email stops reaching anyone. That bill comes due on the opt-in bots in particular, since those are the ones your flows actually mail — and it’s a category Shopify’s own abandoned-checkout bot filtering doesn’t touch. And your engagement metrics degrade quietly — open and click rates fall because the denominator is padded, which makes it harder to tell whether a campaign underperformed or your list is just full of ghosts. (The same denominator problem shows up in your Shopify data, where bot checkouts destroy your abandonment rate.)

Why CAPTCHA and double opt-in don’t stop checkout bots

Klaviyo’s staff recommendations in these threads are consistent: double opt-in, CAPTCHA on forms, honeypot fields, and segment-and-suppress cleanup afterward. Each is worth doing for spam signups on forms. None of them stops bots from creating active profiles at Shopify checkout.

Double opt-in comes closest, and it’s genuinely worth turning on — it’s the only item on that list that keeps an opt-in bot out of your welcome flow. But it governs whether someone joins a list, not whether a profile is created. The Shopify integration creates the profile from the checkout event either way, and Klaviyo has confirmed there’s no way to stop that. An unconfirmed bot is a bot you don’t email and still pay for every month as an active profile.

CAPTCHA and honeypots protect your signup forms, but the traffic described in these threads goes at checkout directly, often through cart permalinks that skip your storefront entirely, so there’s frequently no form for the challenge to sit on.

Segment-and-suppress does work on the bill — reducing active profiles is the right lever — but look at what it actually asks of you. The segment Klaviyo suggests for finding fakes (can receive email, received 3+ emails in 180 days, zero opens, clicks, or orders lifetime) is a behavioral proxy, not a bot test, and it catches quiet real customers alongside bots — so you can’t suppress it wholesale without torching people who simply don’t open much. That leaves reviewing profiles by hand, one judgment call at a time, at the 600-a-month rate above, and then doing it again next week because the fill rate never stops. It’s hours of recurring work to hold down a bill, and inaccurate at that: you’re guessing months after the fact, once the evidence that would actually separate the two — the IP, the browser context, whether the address is disposable, how fast the requests arrived — is long gone, against patterns the bots change continuously. Nobody sustains it. The cleanup happens once, then not again for two quarters while the count climbs back up. You already paid for those months, and you’re paying for the ones the segment misses.

How to suppress bot profiles before they raise your bill

The lever is right, but the timing is wrong. Klaviyo is explicit that “Klaviyo does not charge for suppressed profiles” — suppression, not deletion, is what removes a profile from your billable active profile count. So the goal isn’t a quarterly cleanup. It’s suppressing the fake profile in the same minute it’s created, while the evidence to identify it still exists.

That’s what CartWatch does. It scores every Shopify checkout webhook in real time against the signals bots can’t fake convincingly — email format and disposability, address verification, missing visitor context that a real browser session always leaves, and request velocity no human matches — then auto-tags the customer in Shopify and suppresses the matching profile in Klaviyo and Omnisend automatically, with an audit trail of exactly what tripped the score.

It can’t stop Klaviyo from creating the profile; nothing can, as long as the Shopify integration is live. What it can do is make sure the profile is suppressed before your next bill is calculated, instead of after you’ve paid for it a dozen times. If your active profile count has been growing faster than your sales, install CartWatch from the Shopify App Store and find out how much of that growth is real.

Written by the CartWatch Team

We build bot and fraud detection for Shopify checkouts, and write about what we see across the merchants who use it.