Review the traffic, choose the country boundary, preview the visitor experience, then test both blocked and allowed access. That is the practical sequence for protecting a Shopify storefront from unwanted regional traffic without accidentally closing it to customers.
If your reports look cleaner but the same unwanted visitors can still browse, you have finished the reporting check and left the access decision open. This checklist carries that decision through ShieldLeaf, from one selected country to a tested storefront rule you can keep reviewing.
1. Give the rule a reason
Before selecting countries, compare a recent period with a similar earlier period. Look at sessions by country, referrers, campaign changes, orders, and customer enquiries. Record the pattern you want to address and the countries you need to keep open.
For example, an Italian store serving Italy, France, and Germany might find recurring unwanted visits from Peru, with no relevant campaign or customer demand. If the merchant decides to restrict that traffic, Peru becomes the first ShieldLeaf selection. The three customer countries stay open. This is an illustrative business decision; an unfamiliar country alone does not prove bot activity.
Check complete: you can explain the country choice and name a customer location that must remain unaffected.
2. Keep Shopify’s protections and reporting checks in place
Shopify’s built-in protection includes Cloudflare services and hCaptcha. Confirm hCaptcha is active, and keep your theme and apps current. Country access belongs alongside those protections.
Also check the report’s Human or bot session setting where available. Shopify’s September 2026 analytics update excludes identified bot sessions from session-related reports by default. Record the filter when comparing periods so a reporting change does not look like a protection result.
Filtering a report changes the figures you see. Your ShieldLeaf country rule determines the storefront experience matching regional traffic receives. Keep both checks on the list.
Check complete: your traffic comparison uses consistent filters, and you still have an explicit access decision to apply.
3. Turn the decision into one ShieldLeaf selection
Open Protection in ShieldLeaf. Search Available countries by name or country code, then review Selected countries before activating protection.
For the example, select Peru or PE. Check that Italy, France, and Germany remain unselected. Starting with one country makes the first result easy to assess; expanding the selection can follow once that rule works as intended.
The ShieldLeaf product page brings country selection, blocked handling, and private preview into the same workflow. You can keep the reason for restricting traffic close to the rule that implements it.
Check complete: the selected countries match your written decision, with customer countries left open.
4. Choose what a blocked visitor should see
Under Blocked visitor experience, choose a blocked-access page or a redirect.
For a blocked page, use Blocked message to give a short, calm explanation. “Access from your region is not available on this store” is clearer than accusing every visitor of being a bot. Include a support route if you want genuine customers to ask about access.
For a redirect, enter a useful Redirect URL, such as a regional distributor. Check that the destination opens and does not return the visitor to the same restriction.
Check complete: the ShieldLeaf outcome explains what happened or gives the visitor a useful next destination.
5. Preview before activating the rule
Keep protection off while checking ShieldLeaf’s private preview. Review the chosen experience on desktop and mobile. Read the full message, check any contact details, and follow the redirect if that is your selected mode.
Leafy’s Tip
Keep a four-line note beside your ShieldLeaf rule: selected country, reason, visitor outcome, and allowed customer country. Use the same note for preview, launch, and the next review.
Check complete: the private preview shows the experience you intend to publish.
6. Test the live boundary in both directions
Enable the ShieldLeaf app embed in your published theme and save it, then activate protection for the selected country. Shopify’s app embed guidance explains where to activate embeds; check the applicable market if you use theme overrides.
Use the normal storefront URL for live tests. A trusted tester or suitable test connection in Peru should receive the chosen blocked experience. An allowed connection should reach the homepage and a direct product link, browse, and add an item to the cart. Check desktop and mobile.
Changing a storefront country selector does not relocate your connection. Check its detected IP country if a result surprises you. Confirm shipping and checkout eligibility separately in Shopify.
Check complete: matching traffic receives the ShieldLeaf outcome, and customer browsing still works.
7. Review the rule after launch
Save the activation date with your note. Compare traffic using the same report filters, check customer enquiries, and repeat the affected access tests after changing countries, visitor handling, or the published theme. On ShieldLeaf Pro, use blocked-visit activity logs alongside those checks.
Judge success by the configured visitor outcome and continued customer access, rather than expecting every country row to disappear from analytics. That gives you a specific result to maintain.
ShieldLeaf’s Free plan covers one active blocked country, blocked-page or redirect handling, and preview. Pro adds unlimited countries, groups and presets, and blocked-visit activity logs. You can complete this first-country checklist on Free, then expand coverage when your evidence calls for it.
Check complete: you have one documented, previewed, tested ShieldLeaf rule and a clear reason to keep it. ShieldLeaf turns the traffic pattern that started the checklist into a country boundary you can manage.