Bot Engagement from Ashburn, VA

Anyone getting inundated with traffic/engagement from Ashburn, VA? I was running Meta ads all summer and then one week I ended up getting a ton of traffic from Ashburn, VA (like 2k visits in the same day). I’ve battled with Shopify and Meta support to try and resolove with no luck.

Just today, after stopping my Meta ads last week, I sent an email (Klayvio) and it looks like I’m getting bombarded from Ashburn again, and even getting fake clicks on my email!

Ashburn houses major data hubs and servers including Amazon AWS. So normally I would say just dismiss it and exclude it from your analytics reports. 2000 is a bit much though for a single day. Just keep an eye on it.

The advice you received to simply “exclude Ashburn from your analytics” is actually dangerous for your marketing strategy.

The root cause here isn’t just that your Shopify dashboard numbers are inflated. The real architectural issue is that your Meta Pixel and Klaviyo algorithms are actively training on this bot data. If 2,000 bots entered via an ad, your Pixel now believes that bot profile represents your “ideal customer.” Meta will subsequently optimize your ad spend to find more “people” like that (i.e., more bots), essentially burning your budget to train the algorithm against you.

Regarding the email clicks, those are likely automated security scanners (often hosted in AWS us-east-1 data centers in Ashburn) checking your links for phishing before delivering the email.

Shopify Support typically cannot resolve this because it is not a platform bug; it is an external traffic quality issue. To stop the budget bleed, you need to stop the tracking events from firing, not just hide them in a report:

Log Forensics: This usually requires exporting raw access logs and running them through a Python analyzer to identify the specific User-Agents and IP CIDR ranges.

Data Center Filtering: Ashburn traffic is almost always AWS us-east-1. You need to identify which specific subnets are hitting you.

Conditional Script Loading: The solution is to wrap your Meta Pixel and analytics scripts in a custom logic block. This block checks the visitor’s IP against the known bot ranges and prevents the tracking script from initializing if there is a match.

This approach ensures that while the bots might still hit the site, they remain invisible to your marketing algorithms and do not skew your optimization data.

Best regards, Alexander

Thank you for this detailed reply and makes sense. I however do not know anything about the solution you mentioned, so how do i go about performing the below tasks:
Log Forensics: This usually requires exporting raw access logs and running them through a Python analyzer to identify the specific User-Agents and IP CIDR ranges.

Data Center Filtering: Ashburn traffic is almost always AWS us-east-1. You need to identify which specific subnets are hitting you.

Conditional Script Loading: The solution is to wrap your Meta Pixel and analytics scripts in a custom logic block. This block checks the visitor’s IP against the known bot ranges and prevents the tracking script from initializing if there is a match.

Hi MariaSSFF,

For your situation, the simplest and safest first step is Cloudflare. In most cases, this is enough and does not require any coding.

The setup is straightforward:
DNS: Route your domain through Cloudflare (the Free plan is usually sufficient).
WAF Rules: Create a Firewall rule to challenge traffic from ASN 16509 and ASN 14618. These ASNs belong to Amazon AWS and are commonly used by scanners in Ashburn.
Bot Fight Mode: Enable this in the security settings.

This blocks the traffic before your store loads, so your Meta Pixel and email tracking never fire.

Try this first. If it does not fully stop the issue or the bots adapt, only then does it make sense to move on to more complex, code-based solutions.

Best regards,
Alexander

I tried researching how to do this but i am not familiar. Is there someone at shopify who can implement on my behalf?

Hi MariaSSFF,

Shopify Support usually cannot implement this, because Cloudflare is an external security and DNS layer outside of Shopify itself.

Due to community rules, we cannot offer or promote services here. In practice, this is a very common and inexpensive task for a freelancer from the Shopify Partner Directory or platforms like Upwork, and usually takes under an hour for someone familiar with DNS and Cloudflare.

If you want to try on your own, an AI tool can also help by guiding you step by step using screenshots from your Cloudflare dashboard.

Best regards,
Alexander

Thank you. A freelancer has replied with many more hours than you stated. Can you help me decide if I need all of this?

Phase 1: Diagnostic & Analysis (5–7 hours)
Review Shopify setup & existing tracking
Analyze bot traffic patterns (Ashburn/AWS)
Identify suspicious IP ranges and bot behavior
Confirm the best approach without affecting real users

Phase 2: Implementation (7–9 hours)
Add conditional script logic for Meta Pixel and analytics
Integrate bot filtering logic (IP + behavior-based)
Ensure scripts only load for real visitors

Phase 3: Testing & Validation (3–4 hours)
Verify events are no longer firing from bots
Confirm analytics & Meta data are clean
Final review and documentation

Hi MariaSSFF,

The quote you received is not wrong, but it describes a much more advanced, second-stage approach.

To put it simply: you were looking for a basic lock on the door, while this proposal is closer to building a full internal security system. That level of work usually makes sense only if the simpler solution does not help.

As a first step, you can ask a freelancer very directly for this:

“I do not want custom script development. I want to route my DNS through Cloudflare and configure WAF firewall rules to block or challenge AWS ASNs 16509 and 14618.”

This specific task is quite standard and typically should not require many hours.

Best regards,
Alexander

Hi MariaSSFF,

I have been experiencing similar issues for the last couple of years and I did not and do not run ads ever. It actually led to a fraudulent charge and Shopify was unhelpful with this experience. Let me preface it that I know less than you and am a very tiny business with the ability to do these solutions.

For three years, I could not figure it out, but with the fraudulent charge; I was motivated and searching Reddit for answers and discovered the Shop App could be the main culprit (initially) because of, as a smart redditor explained, a backdoor in their account creation that allowed bots to create fake customer profiles, which were also creating fake subscriber accounts on my website. I removed it temporarily to see if it helped. It did! I permanently removed it and it has been a lot better. Until, the last couple of months. The fake customer accounts are not being created (thank goodness), but the bot views on my website do affect my SEO everywhere else. They will tell you the bot views do not affect anything, but I have been tracking it for over three years on Pinterest and Etsy and they definitely do affect my stats and sales on those platforms. I cannot speak too directly to others, but I have seen a difference in the amount of visibility overall specifically IG/FB. Now, I have been locking my store for 24 hours every time I get a spike. It resolves itself for a few weeks then happens again. I lock it again and it gets better. For example, I went from consistently 500k monthly Pinterest views to 100 when the Ashburn (and Council Bluff) views started. I am back up to 200k-300k views on Pinterest for the last several months when I made these changes.

It is a temporary solution for a potentially huge problem and I wish you the best! It is sooooooooo frustrating. I actually came on here today to find a solution, but hopefully, this short-term strategy can help you too or at the very least, send you in the right direction!

Take Care,

Jess