Part of any site's traffic is not people but automated programs: search crawlers, price scrapers, password-guessing scripts, email harvesters. Cloudflare splits them into two groups — verified bots that are trusted by a request signature, and everything else, whose behavior has to be analyzed separately.
Bot management lives under Security → Bots. The feature set depends on the plan: Bot Fight Mode is available on Free and Pro, Super Bot Fight Mode with more flexible rules on Business, and full Bot Management with score-based scoring on Enterprise.
How to enable Bot Fight Mode
Basic protection turns on in a few clicks and needs no condition setup.
- Open Security → Bots in the domain dashboard.
- Turn on the Bot Fight Mode or Super Bot Fight Mode switch.
- For Super Bot Fight Mode, set a mode for each bot category separately.
- Save the settings and monitor traffic over the next day.
- If false positives appear, add an exception through WAF Custom Rules.
Bot categories and handling modes
Super Bot Fight Mode splits traffic into categories and lets you set a reaction for each.
| Category | Example | Typical mode |
|---|---|---|
| Verified bots | Googlebot, Bingbot | Allow |
| Automated traffic | Scripts, headless browsers | Block or Challenge |
| Likely automated | Suspicious patterns | Managed Challenge |
| Static resource protection | Cache bypass on static files | Challenge |
Verified bots: how not to block the ones you need
Cloudflare confirms a crawler's authenticity by reverse DNS and a signature, not just by the User-Agent string — it is easy to fake, so trusting one header alone is not safe.
- Googlebot and Bingbot pass as verified bots and should not fall under a general Block.
- Payment system and uptime monitoring bots should be added to the allow list manually.
- Your own integrations and webhooks are better passed through a separate condition with a secret header rather than relying on reputation.
Bot Management and other protection tools
When the problem is not bots in general but a specific IP or country, WAF Custom Rules with a condition on that trait will work more precisely. If the task is to stop more than N requests in a row from one address regardless of whether it is a bot or a person, you need Rate Limiting.
Bot Fight Mode and such rules run at the same time without conflicting — Cloudflare applies them in the common order of security phases.
How to test the trigger and check the logs
Send a request with an obviously automated User-Agent and check the reaction.
curl -I -A "python-requests/2.31" https://example.com/Events for each bot appear in Security → Events with the category and block reason shown. To estimate bot traffic volume over a period, use Cloudflare Analytics — it has a separate Bot traffic tab.
Checklist before enabling bot protection
- It is confirmed which verified bots the site needs: search, payments, monitoring.
- Super Bot Fight Mode is configured per category, not with one general switch.
- Your own integrations are protected by a secret header, not just an IP.
- After enabling, search crawler traffic was checked in Search Console.
- The event log was checked for false positives during the first day.