Platform

Cloudflare edge block

DataCops catches the bots that look human enough to get past edge protection. On the Organization plan, it hands the repeat offenders back to your Cloudflare, so they are stopped before they reach your site next time.

What it is

You connect your Cloudflare account with one scoped API token. DataCops creates an IP list and a firewall rule in your Cloudflare. Every 10 minutes it adds any IP that showed up as a bot on your site 2 or more times in the last 24 hours. Cloudflare then challenges those IPs (or blocks them, if you choose) for 30 days.

Detection and blocking usually live in two separate tools that never talk. DataCops sees the bot on your page, Cloudflare guards the door. The edge block joins them, so what DataCops learns becomes a rule Cloudflare enforces.

Why at the edge

Cloudflare is very good at stopping obvious bad traffic. But some automation is built to look human. It runs a real browser, comes from a clean-looking network and passes the first checks. DataCops catches much of that on the page, by reading the browser and the behaviour behind the visit.

Catching a bot after it lands keeps it out of your reports and your ad platforms. Stopping it at the edge goes one step further: it never loads your pages again, never clicks through your funnel and never fills your forms. That saves server load and keeps junk away from every tool behind Cloudflare, not just DataCops.

How it works

  1. Connect. You paste a Cloudflare API token with permission for your zone. DataCops creates a managed IP list and one firewall rule that points at it.
  2. Watch. DataCops scores every visit for bots as usual, using IP intelligence, browser fingerprint and behaviour.
  3. Pick repeat offenders. Every 10 minutes, DataCops looks at the last 24 hours and finds IPs with 2 or more separate bot visits. One odd visit is not enough. A pattern is.
  4. Push. New IPs are added to the list in your Cloudflare. The rule applies straight away.
  5. Expire. After 30 days, each IP is taken off the list again, both in Cloudflare and in DataCops. IPs change hands, so nothing stays blocked forever.

If one run is still going when the next one is due, DataCops simply skips that tick and catches up on the following one, so runs never pile on top of each other.

The rules

SettingValue
Who goes on the listAn IP with 2 or more bot visits on your site in the last 24 hours.
How often it updatesEvery 10 minutes.
How long an IP stays30 days, then it is removed from your Cloudflare automatically.
What Cloudflare doesManaged challenge by default. You can switch it to block.
What is never pushedPrivate and local network addresses.
PlanOrganization.

A managed challenge is the safe default. Cloudflare decides how to test the visitor, and a real person who happens to share an IP with a bot can still get through. If you would rather shut the door completely, switch the action to block.

Set it up

  1. Make sure your site runs through Cloudflare and you are on the DataCops Organization plan.
  2. In Cloudflare, create an API token scoped to your site's zone, with three permissions: Account Filter Lists Edit, Zone Read and Zone WAF Edit, on your zone only.
  3. In the DataCops dashboard, open the Cloudflare bot block section and paste the token.
  4. DataCops creates the IP list and the rule for you. Choose challenge or block.

That is the whole setup. There is nothing to install on your site and no rule to write by hand.

Stay in control

  • See every IP. The dashboard lists recently pushed IPs and how many bot visits each one had.
  • Unblock one IP. If an address should not be there, remove it with one click. It comes off your Cloudflare list too.
  • Change the action. Switch between challenge and block whenever you like.
  • Disconnect. Disconnecting removes the list and rule DataCops created, leaving the rest of your Cloudflare setup untouched.

Safety checks built in

Pushing IPs into a firewall is serious, so the edge block is careful about what it touches. These checks run on every connect and every sync.

CheckWhat it means for you
Zone found from your domainDataCops looks up the Cloudflare zone that matches the domain on your DataCops site. If the token cannot see that zone, connect stops with a clear message and nothing is created.
Your own rules are keptIf your zone already has custom firewall rules, the DataCops rule is added next to them. Your existing rules are not replaced.
One named listThe list is called datacops_bots_ followed by your site ID, and the rule is labelled as managed by DataCops, so you can always spot it in Cloudflare.
Private addresses skippedLocal and private network ranges (such as 10.x, 192.168.x and 127.x) are never pushed, even if a bot visit carried one.
No half setupsIf connect fails partway, DataCops removes the list or rule it already created, so a retry starts clean.
Token kept encryptedYour API token is stored encrypted and is only used to manage the DataCops list and rule.
Errors shown, not hiddenIf a sync fails, for example because the token was revoked, the dashboard shows the last error and the last successful sync time.

Only IPs not already on your list are added on each run, so the same address is never pushed twice. When an IP expires after 30 days, DataCops looks it up in your Cloudflare list and removes it there as well as in its own records, so the two always match.

How it fits with the rest of DataCops

The edge block does not make its own bot decisions. It reuses the verdict DataCops already puts on every visit. That verdict comes from bot and fraud detection, which draws on IP intelligence and what the browser shows on the page.

The same verdict powers three other things. Real people only keeps bot conversions away from the ad platforms you choose. Your reports stay clean because bot sessions are marked as such. And refund evidence turns bot clicks from Google Ads into a file you can send to Google. The edge block is the last step in that chain: once an IP keeps coming back as a bot, it stops reaching your site at all.

If you also send events through the Cloudflare Worker, the two work side by side. The Worker handles first-party tracking on your domain, and the edge block handles firewall rules. They use separate setup and you can run either on its own.

Good to know before you start

  • It runs on your Cloudflare. Your site needs to be on Cloudflare for the edge block to apply.
  • It updates every 10 minutes. A new repeat bot is on your list within minutes, not hours.
  • It is for the Organization plan. Detection and Real people only work on every plan.
  • It works with refund evidence. The same bot visits also feed your Google Ads refund evidence export.
Was this page helpful?