I’m experiencing a persistent issue with high volumes of suspicious traffic on my Shopify store, and I’d like to understand if this is a known limitation or if there’s any effective solution within Shopify.
Problem description
A large portion of my traffic is coming from countries such as:
Bangladesh (~34%)
India (~20%)
Nepal (~10%)
This traffic has the following characteristics:
No conversions (0 orders, 0 checkout, 0 cart activity)
Very low engagement
Appears continuously in both Shopify Analytics and Live View
Behavior strongly suggests bots or automated traffic
What I already implemented
I’ve taken multiple steps to try to mitigate this:
1. Cloudflare protection (on primary domain)
Country blocking rules (Bangladesh, Nepal, India, etc.)
Rate limiting
Bot filtering
Result: Cloudflare does NOT detect this traffic
2. Domain configuration
All .myshopify.com domains are redirected to my primary domain
Still receiving traffic
3. Shopify app (Blockify – Fraud Filter)
Blocking specific countries
Blocking VPN / Proxy traffic
No significant impact on analytics
Key observation
This traffic does NOT appear in Cloudflare logs, which strongly suggests:
- Requests are hitting Shopify infrastructure directly
Likely via .myshopify.com or internal endpoints
Main concerns
This traffic is distorting Shopify Analytics significantly
There is no way to filter or clean this data inside Shopify
It becomes difficult to trust metrics like:
Sessions
Conversion rate
Live View
Questions
Is this a known limitation of Shopify’s infrastructure?
Is there ANY way to:
block traffic at the Shopify level?
restrict access to .myshopify.com?
Does Shopify internally filter bots, or is ALL traffic counted?
Are there any recommended best practices from Shopify to handle this?
Goal
I want to ensure that analytics reflect real user behavior, not automated traffic.
Final note
From what I can tell, this traffic is bypassing any external protection (like Cloudflare), which makes it difficult to control at the store level.
If anyone has faced this and found a workaround, I’d really appreciate your input.
I think you have checked all possible things as you mentioned, and you are not doing anything’s wrong.. you have clear understanding about the shopify ecosystem.
1- shopify have limitations, we can not blocked the traffic.
2- no possible from shopify.
3- should have no option to filter bot traffic.
4- you can share the suggestion to shopify with exact query, I have also noted.
Note - but you can control the and filter the unnecessary traffic ( medium, county etc ) with help of google search console, Google G4, and direct notifications to Google support..
A lot of what you’re seeing is bot / scraper traffic hitting Shopify directly, so Cloudflare never even gets a chance to see it (especially if it’s going via Shopify hosted endpoints or cached paths).
Shopify does filter some bots internally, but it’s not perfect, and you can’t fully block or clean it from the Shopify side.
In practice, most people don’t “fix” it, they just ignore Analytics noise and rely more on:
GA4 (with bot filtering)
server-side events/real checkout data
conversion-focused metrics instead of sessions
Also you generally can’t block .myshopify.com traffic or stop it at the Shopify level.
If it’s heavily skewing decisions, the real workaround is just treating Shopify Analytics as directional and not the truth.
Thanks a lot for taking the time to respond, I really appreciate it.
After digging deeper and testing multiple approaches (Cloudflare rules, country blocking, Shopify apps like Blockify, etc.), it does seem that this is indeed a limitation of Shopify’s architecture, especially with traffic hitting directly through Shopify infrastructure or .myshopify.com endpoints.
Your explanation confirms what I was starting to suspect.
For now, I’ll shift my focus to:
relying more on GA4 (with proper filtering/segments)
focusing on conversion-based metrics instead of raw sessions
treating Shopify Analytics as directional rather than absolute
Still, I believe this is an area where Shopify could improve in the future, especially regarding bot filtering and analytics accuracy.
I haven’t had a chance to use it yet but I know that @thorup is working on solution for this that uses a combination of factors to block suspicious sessions and stop polluting the analytics. Might be worth reaching out to him