TL;DR: BFCM bot protection is a pre-season project, not a Black Friday morning scramble. Bot operators rehearse in October, hit inventory and checkout in November, and leave you with skewed analytics in December. This checklist walks through eight weeks of work: baselining real versus automated traffic, locking down checkout and inventory, protecting your ad budget from fake clicks and sessions, configuring Shopify's native tools, and setting up rules of engagement for the days when you cannot afford to block a real customer. Start now; by mid-November the window to test safely has closed.
Black Friday 2026 lands on November 27, with Cyber Monday on November 30. For most Shopify brands, those five days generate a double-digit share of annual revenue. They also generate the highest bot volume of the year. Inventory bots, card testers, price scrapers, and AI shopping agents all converge on the same checkout at the moment your team is least able to intervene.
This guide is the bot-side companion to our BFCM site speed checklist. Speed gets you ready for the traffic you want. BFCM bot protection makes sure that traffic is actually human, that your scarce inventory reaches paying customers, and that the numbers you report on December 1 are real.
Table of contents
- Why BFCM is peak season for bots too
- The eight-week BFCM bot protection timeline
- Weeks 8 to 6: Baseline your traffic and find the bots already there
- Weeks 5 to 4: Protect inventory and checkout
- Weeks 3 to 2: Protect ad spend and analytics
- Week 1: Configure Shopify's native controls and your runbook
- Frequently asked questions
Why BFCM is peak season for bots too
Bot operators plan around the same calendar you do. Three dynamics make the holiday weekend unusually attractive to them.
First, scarcity concentrates. Limited drops, doorbuster pricing, and bundle deals create resale margins that justify running automated checkout at scale. A bot that can clear a 200-unit allocation of a hyped product in under a minute pays for itself many times over on the secondary market. We covered the mechanics in our post on inventory hoarding bots on Shopify.
Second, noise provides cover. When your traffic triples, a 20 percent bot share is harder to spot than it would be in a quiet week in February. Teams are stretched and anomalies get waved through because "it's Black Friday."
Third, every merchant changes something. New payment methods, new discount logic, new apps, new landing pages. Each change is a fresh surface for card testing attacks and for scripts probing discount code enumeration.
Brands that treat bot defense as reactive find out on Saturday morning that a flagship product sold out to 40 buyers with sequential email addresses, and that conversion rate "dropped" because the denominator was padded with non-human visits.
The eight-week BFCM bot protection timeline
Working backward from November 27 gives you roughly eight weeks from the start of October. The sequence is front-loaded on purpose: anything that touches checkout or blocking rules must be tested while you can still afford a false positive.
- Weeks 8 to 6 (early to mid October): Baseline traffic, identify existing bot share, inventory your exposed surfaces.
- Weeks 5 to 4 (late October): Harden checkout, inventory, discount codes, and account creation. Test every rule against real customer sessions.
- Weeks 3 to 2 (early to mid November): Protect paid media and analytics; agree on the metrics your team will trust during the event.
- Week 1 (Thanksgiving week): Configure Shopify's scheduled bot protection, confirm monitoring, lock the runbook, and freeze changes.
Weeks 8 to 6: Baseline your traffic and find the bots already there
You cannot judge what is abnormal in November without knowing what normal looked like in October.
Pull server-side or edge-level request logs, not just analytics. Google Analytics 4 filters known bots and spiders automatically, but it only sees sessions that execute JavaScript. Headless browsers do execute JavaScript, so they show up in GA4 as real users, while simple scrapers that skip your tag never appear at all. Our guide to bot traffic in Google Analytics walks through the specific reports to check.
Compute a rough bot share by comparing edge requests to analytics sessions. If your edge logged 1.2 million page requests last week and GA4 reported 400,000 sessions, multi-page sessions do not explain the whole gap. Segment by user agent, ASN, and request pattern. Data center ASNs (cloud hosting providers rather than residential ISPs) hitting product pages at a steady 2 requests per second are not shoppers.
Catalog the surfaces bots will target. For most Shopify stores the list is short: product pages for scarce SKUs, the cart and checkout endpoints, discount code entry, account creation and login, gift card balance checks, and any public API your theme or apps expose. Note which you can rate limit, challenge, or monitor today.
Audit your robots.txt for AI crawlers. Shopify lets you edit robots.txt through a robots.txt.liquid template. Decide now whether GPTBot, ClaudeBot, PerplexityBot, and Google-Extended should see your BFCM landing pages. Our analysis of AI shopping agents in ecommerce argues most brands should allow well-behaved agents while blocking abusive ones, but the decision is yours; what matters is that it is a decision, not a default.
By the end of week 6, you should have one number everyone agrees on: your current bot share of sessions and requests.
Weeks 5 to 4: Protect inventory and checkout
This is the core of any Shopify bot protection checklist, and it is where the stakes are highest, because a false positive here turns away a paying customer at the moment of purchase.
Identify your "protected" SKUs. Not every product needs defending. Pick the items with resale margin, constrained inventory, or marketing weight (the hero doorbuster that drives your email campaign). Shopify Plus bot protection events can cover up to 500 individual products or your whole catalog, so decide which list you will use.
Rate limit add-to-cart and checkout creation per client. A human adds an item to cart a handful of times per session. A checkout bot may create dozens of carts per minute from one IP, or one cart per minute from hundreds of IPs through a residential proxy pool. The first pattern is caught by per-IP limits; the second requires behavioral and fingerprint-based detection at the edge.
Harden discount codes. Single-use codes, codes tied to a customer account, and codes with a usage cap are harder to enumerate and resell. Avoid predictable patterns (BFCM10, BFCM20, BFCM30) that a script can guess in seconds. Monitor the rate of failed discount submissions; a spike is a clear signal of enumeration.
Block card testing before it costs you. Card testing attacks ramp up in the weeks before BFCM as fraud rings validate stolen cards against stores whose checkout they expect to be busy. Watch for bursts of low-value orders, many declines from one source, and new accounts created seconds before purchase. We detailed detection and response in our post on card testing attacks on Shopify. Every validated card that gets through becomes a chargeback in January.
Test every rule against real sessions. Run your proposed blocking and challenge rules in monitor-only mode for at least a week. Review what they would have blocked. If a rule would have challenged returning customers who shop through a corporate VPN, loosen it now.
Weeks 3 to 2: Protect ad spend and analytics
Bots also consume ad budget and corrupt the data your team uses to make real-time decisions during the sale.
Reconcile paid clicks against on-site behavior. If your Meta or Google campaigns report clicks that produce sessions with zero scroll depth, zero product views, and sub-second duration, you are paying for automated traffic. Agree with your media buyer on what share of invalid traffic is tolerable before you pause a placement.
Exclude data center traffic from retargeting audiences. Bot sessions that land on product pages can be added to your retargeting pools, where they inflate audience sizes and dilute match rates. Exclude known data center ASNs and sessions flagged as automated from any audience you build in the final two weeks.
Define the metrics you will trust during the event. Conversion rate is the most abused number during BFCM because bots sit in the denominator. Decide in advance whether your team will report CVR on all sessions, on filtered human sessions, or both. Document the filter. When someone asks on Saturday why CVR dropped 30 percent, the answer should be a known filter, not a panic.
Confirm your dashboards update on a cadence you can act on. A daily GA4 export is useless for a flash sale that lasts 45 minutes. For protected SKUs, you want near-real-time visibility into add-to-cart rate, checkout starts, and challenge pass rate by traffic source.
Revisit how to tell if your Shopify traffic is bots too; heuristics that work in a quiet month need recalibration when human traffic itself behaves unusually.
Week 1: Configure Shopify's native controls and your runbook
Shopify ships native checkout bot protection for Shopify Plus merchants. Use it, and understand its limits.
What Shopify's bot protection does. According to Shopify's documentation, the feature blocks known bots from checkout and slows down automated activity so customers can buy scarce products during flash sales. You can schedule a protection event for a specific time, choose a reCAPTCHA or hCaptcha challenge, protect all published products or up to 500 individual products, and customize the checkpoint page shoppers see. It must be activated through Shopify Plus Support before it appears in your admin.
What it does not do. Shopify is explicit that the feature is meant to limit auto-checkout bots, not to combat fraud related to bot activity. It applies only to the Online Store channel. Each event can last a maximum of 60 minutes, only one event can be scheduled at a time, and once active it cannot be edited, only deactivated. That makes it excellent for a 30-minute doorbuster and a poor fit for a five-day sale, for scrapers hammering collection pages, or for card testers who never reach a protected product.
Request access and schedule events now. Because activation goes through Plus Support, do not wait until the week of the sale. Schedule your protection windows around your biggest drops, set them in your store's time zone (not your browser's), and test the checkpoint page on mobile.
Layer edge protection for everything else. For the other 99 percent of the weekend, you need continuous detection at the edge: identifying headless browsers, residential proxy rotation, scraper fleets, and abusive AI crawlers before they reach Shopify's origin at all. That is where a dedicated layer such as Nostra Edge Protect fits, sitting in front of your store to shape bot traffic without adding a challenge to real customers. Our comparison of Shopify bot protection options breaks down where each tool is strong.
Write the runbook and freeze. Your runbook should fit on one page and answer five questions: Who is on call for each hour of the weekend? What dashboards do they watch? What thresholds trigger action (for example, challenge pass rate below 70 percent, or checkout creation rate above 5x baseline from a single ASN)? What actions are pre-approved without escalation? Who can approve loosening a rule if real customers are being blocked? Once it is written, freeze your theme, apps, and rules from the Monday before Thanksgiving onward.
Frequently asked questions
When should I start BFCM bot protection preparation?
Start at least eight weeks before Black Friday, which means early October for the 2026 holiday. You need two to three weeks to baseline traffic, two weeks to test rules in monitor-only mode, and a final week to configure scheduled events and freeze changes.
Does Shopify's built-in bot protection cover the whole Black Friday weekend?
No. Shopify's checkout bot protection is available to Shopify Plus merchants and is designed for scheduled flash sales. Each event lasts up to 60 minutes, only one can be scheduled at a time, and it covers the Online Store channel only. It is effective for a specific drop but does not provide continuous protection against scrapers, card testers, or sustained bot traffic across a multi-day sale.
How do I tell Black Friday bot traffic from a genuine traffic spike?
Look at behavior rather than volume. Human spikes bring proportional increases in product views, add-to-carts, and purchases, with normal session durations and scroll depth. Bot spikes show high request rates from data center ASNs, sessions that hit a single endpoint repeatedly, sub-second durations, and conversion patterns such as many orders with sequential emails or identical shipping addresses. Comparing edge request logs against analytics sessions is the fastest way to see the gap.
Will adding a CAPTCHA to checkout hurt my BFCM conversion rate?
A challenge on every checkout will cost you real sales, especially on mobile. The better approach is to challenge selectively: only on protected SKUs, only during scheduled windows, and only for sessions whose signals look automated. Edge-level detection that blocks obvious bots before they reach checkout reduces how often any human sees a challenge at all. Test any challenge flow on real devices before the sale.
How do inventory hoarding bots affect my holiday revenue if they still pay?
A bot that pays full price still damages you. You lose the customer relationship and the repeat purchase, you absorb support tickets from shoppers who could not buy, your scarce stock ends up on resale sites at a markup that makes your brand look exploitative, and your conversion and attribution data reflect a buyer who will never return.
Should I block AI crawlers like GPTBot and ClaudeBot during BFCM?
It depends on your goals. Well-behaved AI crawlers that respect robots.txt can help your products appear in AI-assisted shopping answers, which is increasingly how customers discover deals. Aggressive or unidentified crawlers that ignore your rules and hammer collection pages consume origin capacity you need for humans. Use robots.txt.liquid to set policy for identified crawlers and use edge detection to enforce it against those that do not identify themselves.
Get ahead of the bots before they get ahead of your sale
BFCM bot protection comes down to one truth: the weekend is too important and too short to improvise. Every rule you test in October is a false positive you avoid in November. If you want an edge layer that separates real shoppers from automated traffic continuously, without adding friction to the customers you spent all year earning, talk to the Nostra team about getting protection in place before the holiday freeze.