A traffic spike can look promising until orders stay flat and most of the new sessions come from an unexpected country. Before changing anything, separate two questions: is the activity probably automated, and is its geography a storefront-access problem you want to solve?
Leafy’s Quick Answer
In Shopify admin, add Human or bot session to a sessions-related report, then add country to see where those sessions cluster. If you only want a clearer report, filter to human sessions. If repeated unwanted traffic comes from a country you do not serve and you want it kept outside the storefront, that is where a ShieldLeaf country rule fits.
Confirm the pattern in Shopify Analytics
Shopify labels online-store sessions as probably human or bot. Start there instead of treating a low conversion rate as proof:
- Go to Analytics → Reports and open a sessions-related report.
- Add Human or bot session under Dimensions.
- Compare human and bot sessions over the same dates.
- Add country, referrer, landing page, or device to see whether the unusual traffic has a consistent pattern.
Shopify’s bot-filtering documentation says the filter applies to sessions-related metrics and new data from October 7, 2025. Older periods cannot be classified retroactively, so compare dates the filter actually covers.
Ask three questions before acting
1. Is the activity labeled as bot traffic?
Use Shopify’s classification as the starting evidence. Then look for supporting signs such as a sudden volume change, repeated visits to the same pages, unusual referrers, or activity that does not correspond with a campaign or launch.
2. Is the pattern consistently geographic?
Break the bot-labeled sessions down by country and compare them with the markets you serve. One brief spike is weak evidence. Repeated traffic from the same unserved country, across comparable periods, gives you a clearer basis for a country rule.
Shopify’s guide to identifying bot activity recommends checking for legitimate causes too, including publicity, campaigns, integrations, and performance testing.
3. What outcome do you actually want?
If the traffic is only making a report harder to read, filter the report to human sessions. If you want visitors from that country prevented from browsing the storefront, reporting filters are not the final step; you need a country-access rule.
Leafy’s Example
A merchant sees a recurring session spike from a country outside their market. Shopify’s human-or-bot dimension shows that much of it is automated, and there is no matching campaign or order activity. Filtering to human sessions clarifies performance; adding a ShieldLeaf country rule addresses the separate storefront-access problem.
Where ShieldLeaf fits
It is designed for the point where geography becomes the action you want to take. Once the pattern is clear:
- Choose the country or countries you want to handle.
- Select a blocked-access page or a redirect URL.
- Preview the visitor experience before turning protection on.
- Review blocked-visit activity after launch when your plan includes activity logs.
The app uses Shopify’s app-embed setup, so normal installation does not require theme-code edits. The Free plan supports one active blocked country; Pro adds unlimited countries, country groups and presets, and activity logs for blocked visits.
The useful connection is simple: Shopify helps you identify the traffic pattern; the app helps you act when that pattern points to unwanted country access.
Keep the rule focused
Not every automated visit calls for a country block. Shopify describes search indexers and accessibility tools as beneficial automation, and legitimate shoppers can also travel or use networks that affect location signals.
Use the evidence to choose the smallest response that matches the problem: filter the metric when the issue is reporting; apply a country rule when repeated unwanted traffic from a country you do not serve has become a storefront-access problem.