Bot traffic

Detect bot and automated traffic by the networks it runs on

Most automated traffic does not come from someone's living room. It comes from hosting providers, scanner infrastructure, proxy pools and Tor. FindIP Shield classifies the network behind each request or visit, reports it with the reason, and, on Cloudflare, can block the high-confidence cases once you choose to.

Free Preview · 10,000 events per site per day · No credit card · Terms apply

Hosting / datacenter Scanner infrastructure Tor Proxy Malicious IP Verified bots allowed
The problem

Behavioural bot detection is heavy. Network classification is not.

Full bot management products fingerprint the browser, watch mouse movement and score behaviour. They are powerful, expensive, and opaque about why a visitor was flagged.

A large share of automated traffic is identifiable earlier and more simply: the request arrives from a datacenter range, a known scanner, a Tor exit or an IP with a malicious history. Shield reports exactly that, with the reason, and is honest about what it does not do: it does not analyse behaviour or fingerprint devices.

At the Cloudflare edge Shield screens every request before it reaches your origin. In the browser it scores visits and form submits. Both start in monitor mode.

What Shield shows you

The evidence, then the response you choose

Infrastructure, named

Datacenter and hosting providers, scanner infrastructure, Tor exits and relays, proxies and malicious-IP categories, each a separate reason on the request or event.

Edge screening with a policy you control

On a Cloudflare-proxied hostname: allow and block lists, verified-bot handling, path rules, country rules, an AI-crawler policy and IP-rotation defence. Monitor mode first, with a preview of what Balanced mode would have blocked.

Fails open, removes in one click

If FindIP is slow or unavailable, requests pass through unchanged. One Worker, one route, and a one-click removal that leaves nothing behind.

Setup

Connect Cloudflare in three steps, no code

For sites proxied through Cloudflare. No Worker to write, no API tokens to paste; authorise, pick a hostname, and watch.

Connect Cloudflare

Authorize FindIP with your Cloudflare account. The consent screen lists exactly what is requested, and nothing is deployed yet.

Pick one hostname

Choose a hostname that is proxied through Cloudflare. Shield deploys one Worker and one route in front of it and shows you both before activating.

Watch in Monitor mode

Monitor is the default and never blocks. The Activity tab shows every screened visit with its outcome and reason, and a Balanced preview shows what that mode would have blocked.

Prefer another route? Not on Cloudflare? The browser snippet scores visits and form submits on any site.

Boundaries

What a risk score is, and what it is not

An assessment, not proof. A VPN, a hosting network or a changing IP is common for privacy-conscious and corporate users too. Shield explains the reasons so you can decide; it does not pass judgement on a person.
Friction, not a security boundary. Anything decided in the browser can be bypassed by someone who controls it. For decisions that matter, verify the session from your server with your secret key.
Unknown is never safe. Where no intelligence was available the status is unknown. Shield fails open: if a decision does not arrive, the form submits as normal.
Questions

Frequently asked

The Cloudflare policy has explicit handling for verified bots, and Monitor mode never blocks anyone. Review the Activity tab for at least a week before enabling Balanced mode, and keep verified bots allowed.

No. Shield classifies the network a request came from and explains why. It does not fingerprint devices or analyse behaviour. For many sites that is the signal they were missing; for others it complements a full bot product.

Only the visitor IP, hostname, path and method. No headers, cookies, bodies or responses. The full data inventory is in the documentation.

Requests pass through unchanged. The failure matrix in the documentation covers timeouts, errors, invalid responses and Worker exceptions; every row forwards the request.

Start by watching one real flow.

Create a free Shield site, install it, and look at the first real event before you decide on any response.

Connect Cloudflare, free

Free Preview · Informational risk signals · You control enforcement