Skip to main content

Bots in Cloudflare: Bot Fight Mode and Verification

Cloudflare · 29.09.2026

Part of any site's traffic is not people but automated programs: search crawlers, price scrapers, password-guessing scripts, email harvesters. Cloudflare splits them into two groups — verified bots that are trusted by a request signature, and everything else, whose behavior has to be analyzed separately.

Bot management lives under Security → Bots. The feature set depends on the plan: Bot Fight Mode is available on Free and Pro, Super Bot Fight Mode with more flexible rules on Business, and full Bot Management with score-based scoring on Enterprise.

How to enable Bot Fight Mode

Basic protection turns on in a few clicks and needs no condition setup.

  1. Open Security → Bots in the domain dashboard.
  2. Turn on the Bot Fight Mode or Super Bot Fight Mode switch.
  3. For Super Bot Fight Mode, set a mode for each bot category separately.
  4. Save the settings and monitor traffic over the next day.
  5. If false positives appear, add an exception through WAF Custom Rules.

Bot categories and handling modes

Super Bot Fight Mode splits traffic into categories and lets you set a reaction for each.

CategoryExampleTypical mode
Verified botsGooglebot, BingbotAllow
Automated trafficScripts, headless browsersBlock or Challenge
Likely automatedSuspicious patternsManaged Challenge
Static resource protectionCache bypass on static filesChallenge

Verified bots: how not to block the ones you need

Cloudflare confirms a crawler's authenticity by reverse DNS and a signature, not just by the User-Agent string — it is easy to fake, so trusting one header alone is not safe.

  • Googlebot and Bingbot pass as verified bots and should not fall under a general Block.
  • Payment system and uptime monitoring bots should be added to the allow list manually.
  • Your own integrations and webhooks are better passed through a separate condition with a secret header rather than relying on reputation.

Bot Management and other protection tools

When the problem is not bots in general but a specific IP or country, WAF Custom Rules with a condition on that trait will work more precisely. If the task is to stop more than N requests in a row from one address regardless of whether it is a bot or a person, you need Rate Limiting.

Bot Fight Mode and such rules run at the same time without conflicting — Cloudflare applies them in the common order of security phases.

How to test the trigger and check the logs

Send a request with an obviously automated User-Agent and check the reaction.

curl -I -A "python-requests/2.31" https://example.com/

Events for each bot appear in Security → Events with the category and block reason shown. To estimate bot traffic volume over a period, use Cloudflare Analytics — it has a separate Bot traffic tab.

Checklist before enabling bot protection

  • It is confirmed which verified bots the site needs: search, payments, monitoring.
  • Super Bot Fight Mode is configured per category, not with one general switch.
  • Your own integrations are protected by a secret header, not just an IP.
  • After enabling, search crawler traffic was checked in Search Console.
  • The event log was checked for false positives during the first day.
← Back to Knowledge Base Ask Support