Most automated traffic is not a search engine
Bots do more than flood a website. They copy prices and content, try leaked passwords against your login page, create fake accounts, hammer search and filter pages, and probe for vulnerable plugins. Many of them now use real browser user agents and rotate through residential proxies, so a simple user-agent filter or IP block list no longer catches them.
- Scrapers that copy product data, prices and content.
- Credential stuffing against login pages with leaked passwords.
- Attack bots behind HTTP floods and vulnerability scans.
- Abusive automation on search, forms and checkout.
A check real browsers pass on their own
When a website is under pressure, and for clients that go over their rate limit, Shieldify asks new visitors for a quick browser check. A real browser completes it automatically in a moment: it runs the check, stores a short-lived verification cookie and continues to the page. Scripts, simple HTTP clients and most automation tools cannot complete it, so they never reach your server.
Verified visitors are not asked again for hours, and people who share one address, such as an office or a mobile network, verify together instead of each seeing their own check.
A CAPTCHA that does not track your visitors
Traffic that still looks suspicious after the browser check meets a CAPTCHA instead of a hard block, so a real person always has a way through. The CAPTCHA runs on Shieldify's own servers. Visitor data is not sent to Google or any other captcha vendor, and no advertising cookies are set. The Trust Center lists the security cookies Shieldify uses.
Good bots get through, fake ones do not
Blocking search engines during an attack would cost you rankings. Shieldify lets Googlebot, Bingbot and Applebot through, but only after checking that the request really comes from the address ranges each company publishes. A scraper that only copies Googlebot's user agent is treated like any other unverified client.
Let your own machines in
Payment providers, webhooks, uptime monitors and mobile apps cannot run a browser check. Add their exact paths, such as /api/payment/callback, or their fixed IP addresses as trusted rules under Access rules. Keep each rule as narrow as possible; trusted paths still have their own abuse limits.
Challenged traffic, separate from the rest
The traffic dashboard shows challenges as their own series next to allowed and mitigated requests, live and over up to 180 days. Security events and the request log show which clients were challenged or blocked and why.