# How to Block an IP Address on Shopify {#post-title}

[X Shield](/blog/#blog-x-shield)

By [B2B Gold](/about/#how-we-write) Published 24 September 2026 Updated 26 September 2026

## Can you block an IP address on Shopify? {#can-you-block-an-ip-address-on-shopify}

Yes, at two layers. Shopify’s free Fraud Control app can block checkouts from an IP address if you use Shopify Payments, but that person can still browse your store. To turn away an IP, a range or a whole network at the storefront, you need an IP-blocker app, because the Shopify admin has no setting for it.

> **Note:** The Shopify settings, labels and plan rules on this page were checked against Shopify’s help documentation on 26 September 2026.

The two layers do different jobs, and an IP block that “doesn’t work” is often aimed at the wrong one:

|  | Checkout block | Storefront block |
| --- | --- | --- |
| Tool | Fraud Control checkout rules, made by Shopify | An IP-blocker app |
| What the person sees | An error saying the checkout couldn’t be completed and asking them to contact you | A blocked page instead of your store |
| Can they still browse? | Yes | No, as long as their browser runs the app’s script |
| Requirement | Shopify Payments | The app |
| Ranges and IPv6 | Not documented by Shopify | Depends on the app |

## How do I find the IP address to block? {#how-do-i-find-the-ip-address-to-block}

Start from an order if you have one. When Shopify has the IP address an order was placed from, it shows it in the order’s fraud analysis. For someone who only browses, Shopify’s reports won’t give you an IP address; you need a tool that logs visits.

### From an order {#from-an-order}

1. In your Shopify admin, go to **Orders** and open the order.
2. In the **Order risk** section, click **Order risk evaluation** (on some stores it reads **About this order**).
3. Find the IP address. Shopify lists it separately from the fraud indicators, and it is not a verdict on its own ([fraud analysis](https://help.shopify.com/en/manual/fulfillment/managing-orders/protecting-orders/fraud-analysis#view-the-fraud-analysis-for-an-order)).

Before you block it, read it the way Shopify’s [fraud prevention guide](https://help.shopify.com/en/manual/payments/fraud-prevention/preventing-fraud) suggests: is the IP far from where the buyer says they are, does it belong to a web-hosting company, or is it a proxy? If any answer is yes, Shopify’s advice is to contact the customer before trusting the order. Shopify Payments also flags customers who use a proxy service.

### From a visitor who never ordered {#from-a-visitor-who-never-ordered}

Shopify’s [Sessions by location report](https://help.shopify.com/en/manual/reports-and-analytics/shopify-reports/report-types/default-reports/acquisition-reports) shows the countries, regions and cities visits come from, not IP addresses. To see a browsing visitor’s IP, you need something that records it, such as a storefront security app’s visit log.

If what you’re seeing is hundreds of sessions rather than one person, single-IP blocks won’t keep up. Read [bot traffic from Singapore and China, explained](/blog/shopify-bot-traffic/) first.

## How do I block an IP from checking out? {#how-do-i-block-an-ip-from-checking-out}

Create a checkout rule in Shopify’s Fraud Control app. It’s free and made by Shopify, but its checkout rules are only available to stores using Shopify Payments. A checkout that matches the rule never becomes an order, so there’s no order to cancel.

1. Install **Fraud Control** from the Shopify App Store.
2. In your Shopify admin, go to **Apps** → **Fraud Control**, click **Rules**, then **Create rule**.
3. In the **Checkout conditions** section, add the IP address. A rule can combine conditions: Shopify’s own example pairs an IP address with a ZIP code to block orders with both.
4. Click **Save**. The rule turns on straight away, and Shopify names it after its conditions.

Blocked attempts appear in your abandoned checkouts. The buyer isn’t told they matched a fraud rule ([Fraud Control app](https://help.shopify.com/en/manual/payments/fraud-prevention/fraud-control-app#fraud-control-checkout-rules)).

Three limits to know:

- It stops checkouts, not browsing.
- Shopify’s documentation mentions IP address filters but doesn’t say whether ranges or IPv6 are accepted. Check what the rule editor takes before you rely on a range.
- Shopify warns that rules can block legitimate checkouts and don’t guarantee you against chargebacks.

### Not on Shopify Payments? {#not-on-shopify-payments}

Shopify then gives you no way to stop the checkout itself by IP, but you can deal with the order afterwards. [Shopify Flow](https://help.shopify.com/en/manual/shopify-flow), free on the Basic plan and above, can cancel or hold orders by the customer’s IP address, which Shopify’s [workflow examples](https://help.shopify.com/en/manual/shopify-flow/getting-started/workflow-examples) mention by name. Flow conditions support **Starts with** ([conditions](https://help.shopify.com/en/manual/shopify-flow/reference/conditions)), so an IP that starts with `203.0.113.` covers that whole block of 256 addresses. Include the final dot, or the condition also matches neighbouring ranges.

The order still exists by then. If you capture payments automatically, the buyer has already been charged, so cancelling means a refund, and card transaction fees aren’t returned when you refund ([cancelling orders](https://help.shopify.com/en/manual/fulfillment/managing-orders/canceling-orders)).

Apps that add a checkout rule under **Settings** → **Checkout** → **Checkout rules** can’t help here: Shopify’s [validation API](https://shopify.dev/docs/api/functions/latest/cart-and-checkout-validation) gives them the buyer’s email, customer tags and delivery address, but no IP address.

## How do I block an IP from seeing my store? {#how-do-i-block-an-ip-from-seeing-my-store}

Install an IP-blocker app. Shopify has no admin setting that keeps an IP address off your storefront. The other route, putting Cloudflare in front of your store, is a setup Shopify’s [domain troubleshooting page](https://help.shopify.com/en/manual/domains/troubleshoot-issues-with-domains) says it doesn’t support.

Whichever app you pick, check that it:

- accepts CIDR ranges and IPv6, not only single IPv4 addresses;
- can block a whole network by AS number, for data-centre traffic;
- has an allowlist for you and a way to test a rule before it goes live;
- says plainly what it can’t cover, such as Shopify’s hosted checkout.

### Blocking an IP in X Shield {#blocking-an-ip-in-x-shield}

X Shield, which we build, is one of these apps. In X Shield:

1. Check the app embed is on. If the **Overview** page shows an **Enable in theme** button, click it and save your theme; nothing is blocked until the embed is on.
2. Open **IP & Network** and turn on the switch at the top of the page, so it reads **On**.
3. Under **Access mode**, choose **Block listed**.
4. Under **IP addresses to block**, paste single IPs, CIDR ranges, start-to-end ranges or IPv6 addresses into the field, separated by commas, and click **Add**. Each entry appears in the list with its **Type**: **IP**, **CIDR** or **Range**.
5. Click **Save**. A toast confirms **Configuration saved successfully**, and the rule applies from the next page a visitor loads.

On the Enterprise and Plus plans you can also add **Networks to block (ASN)**, like the DigitalOcean entry above. The Free plan includes a limited number of IP entries, and a CIDR range counts as one ([plans and limits](/shopify/x-shield/#pricing)). Page targeting and the full field list are in [block IP ranges and networks in X Shield](/docs/x-shield/block-ip-addresses/).

What it can’t do: X Shield runs as JavaScript in the visitor’s browser, so scripts that never run your page’s JavaScript receive the HTML and never see the blocked page. It also can’t control Shopify’s hosted checkout, so a blocked person can still reach checkout through a direct checkout link or a page cached before the block. Keep the Fraud Control rule for that layer.

> **Tip:** [X Shield, a free country and bot blocker for Shopify](/shopify/x-shield/), includes IP rules on its Free plan, and its free dry run evaluates a rule without blocking anyone.

## Should I block one IP, a range or a whole network? {#should-i-block-one-ip-a-range-or-a-whole-network}

Block the smallest thing that stops the problem. A single IP suits a fixed address you’ve seen misbehave, a range suits addresses that change within one block, and a network (ASN) suits data-centre traffic that real shoppers don’t use. Large ranges of home or mobile addresses turn away customers.

CIDR notation is a starting address plus a slash and a number. The number says how much of the address is fixed, so the smaller it is, the bigger the range. The examples below use address blocks reserved for documentation ([RFC 5737](https://www.rfc-editor.org/rfc/rfc5737.html), [RFC 3849](https://www.rfc-editor.org/rfc/rfc3849.html)), so none of them belongs to a real visitor.

| You enter | What it covers | Addresses |
| --- | --- | --- |
| `203.0.113.7` | One IPv4 address | 1 |
| `203.0.113.7/32` | The same single address, written as a range | 1 |
| `203.0.113.0/24` | `203.0.113.0` to `203.0.113.255` | 256 |
| A `/16` | Every address sharing the first two numbers | 65,536 |
| `2001:db8::1` | One IPv6 address | 1 |
| `2001:db8:0:1::/64` | One IPv6 subnet, usually one home network or one phone’s connection | About 18 quintillion |

### Why IPv6 needs a range {#why-ipv6-needs-a-range}

Phones and laptops change their own IPv6 address. The privacy addresses defined in [RFC 8981](https://www.rfc-editor.org/rfc/rfc8981.html) are replaced about once a day by default, while the first half of the address, the /64 prefix, stays with the connection. Block the /64, not the single address.

### When to block a whole network {#when-to-block-a-whole-network}

An autonomous system number (ASN) identifies one operator’s network, written like `AS64500` (a number reserved for examples by [RFC 5398](https://www.rfc-editor.org/rfc/rfc5398.html)). One entry covers every address that operator announces, including ones it adds later. Use it for hosting and cloud providers that send scrapers, never for a home broadband provider or mobile carrier, where one number can cover every customer they have.

### Shared IPs: the false-positive trap {#shared-ips-the-false-positive-trap}

Many people can share one public IPv4 address. Mobile carriers and some broadband providers put subscribers behind carrier-grade NAT, which [RFC 6888](https://www.rfc-editor.org/rfc/rfc6888.html) defines as one address shared among several subscribers; offices, schools, hotels and public Wi-Fi do the same. [RFC 6269](https://www.rfc-editor.org/rfc/rfc6269.html), which catalogues the problems with shared addresses, notes in section 13.1 that penalising a shared address also locks out everyone else behind it, even on their first attempt. A block on one mobile IP can turn away strangers and still miss your target the moment they switch to Wi-Fi.

## How do I make sure my own IP is never blocked? {#how-do-i-make-sure-my-own-ip-is-never-blocked}

Put your IP on an allowlist that overrides every rule, and keep a second way in, because your IP changes as soon as you switch networks. In X Shield that means **Whitelisted IPs** for the office and a private access link for everywhere else.

- **Global bypass** → **Whitelisted IPs**: click **Add my IP**, give it a label such as “Office”, and save. Anything on this list skips every protection, so add only networks you control.
- **Safety & testing** → **Your private access link**: click **Create link**, then save. Opening your store with that link skips every rule on any network and any device. Treat it like a password.
- While you edit rules, a **These rules would block you** warning appears if your current connection matches one. Customers on the same connection would be blocked too.

Don’t use **Allow only listed** on the **IP & Network** page to let yourself in. In that mode only the listed addresses get through, and every other visitor is blocked.

Before a new rule blocks anyone, run it in **Dry run** (**Observe only**), which records who would have been blocked without blocking them (paid plans list each one in Analytics), and check your connection with **Test my own connection**. The details are in [dry run and your private access link](/docs/x-shield/safety-and-testing/).

## Why didn’t blocking the IP work? {#why-didnt-blocking-the-ip-work}

Usually because the person’s IP changed, or because they never passed through the layer you blocked. Work through these in order:

1. **Their address changed.** Home connections are reassigned new IPs, phones switch between Wi-Fi and mobile data, and IPv6 privacy addresses rotate daily. Block the range or network, or add a checkout rule on their email instead.
2. **They’re on a VPN or proxy.** Each session can come from a new exit IP. Blocking VPN networks as a whole turns away honest privacy-minded shoppers too; [VPN, proxy and scraper-network blocking](/docs/x-shield/vpn-proxy-scraper-blocking/) explains the trade-off.
3. **They went straight to checkout.** A storefront block doesn’t cover Shopify’s hosted checkout. Add a Fraud Control rule for that layer.
4. **It’s a script, not a browser.** Anything that doesn’t run JavaScript never sees a storefront blocker’s page.
5. **Your test was bypassed.** A whitelisted IP, a tab opened with a private access link, or dry run left on will let you through. Test in a new private window on mobile data.
6. **The app isn’t running.** In X Shield that is usually the app embed; [X Shield isn’t blocking](/docs/x-shield/not-blocking/) lists every check.

To stop one particular person rather than an address, combine several signals, as in [block a specific customer](/blog/block-customer-shopify/).

## Frequently asked questions {#frequently-asked-questions}

### Can I ban an IP address from my Shopify store permanently? {#can-i-ban-an-ip-address-from-my-shopify-store-permanently}

A rule lasts until you delete it, but the address doesn’t stay with one person. Providers reassign IPs, so an old ban can end up blocking a stranger while the person you meant has moved on. Review IP rules every few months and use networks, not single IPs, for data-centre traffic.

### Does Shopify have an IP whitelist? {#does-shopify-have-an-ip-whitelist}

Not for the storefront. If only certain people should see the store at all, Shopify’s **Private mode** (**Online Store** → **Preferences**, under **Store access**) puts the whole storefront behind a password and hides it from search engines ([password protection](https://help.shopify.com/en/manual/online-store/themes/password-page)). In a blocker app, an allowlist such as X Shield’s **Whitelisted IPs** lets chosen addresses past every rule.

### Why is a customer’s IP on a temporary blocklist? {#why-is-a-customers-ip-on-a-temporary-blocklist}

Shopify’s fraud analysis blocks an IP address for a while when many orders or failed payments come from it in a short time. The block lifts by itself within 6 to 24 hours, you can’t remove it sooner, and every new attempt restarts the timer. To take the order meanwhile, create a draft order ([troubleshooting fraud analysis](https://help.shopify.com/en/manual/fulfillment/managing-orders/protecting-orders/fraud-analysis#troubleshooting-fraud-analysis)).

### Can I see whether a blocked IP still places orders? {#can-i-see-whether-a-blocked-ip-still-places-orders}

Yes, if your blocker checks orders as well as visits. X Shield’s [order protection](/docs/x-shield/order-protection/), on paid plans, flags new orders whose IP your storefront rules blocked in the past seven days and adds that evidence to the order’s fraud analysis in Shopify. It never cancels an order for you.

[X Shield: IP Country Blocker](/shopify/x-shield/)

X Shield is a Shopify app that blocks visitors by country, IP address or network, and turns away the bots, VPNs and spy extensions it detects, showing them a blocked page instead of your store. Googlebot and Bingbot, checked against their published IP ranges, still get in, and dry run lets you test every rule before it blocks anyone.

[Install free on the Shopify App Store](https://apps.shopify.com/x-shield-store-guard?utm_source=b2bgold.app&utm_medium=referral&utm_campaign=blog&utm_content=blog/block-ip-address-shopify&utm_term=post-cta) [Plans and pricing](/shopify/x-shield/#pricing) [X Shield docs](/docs/x-shield/) [How X Shield compares with Blockify](/compare/x-shield-vs-blockify/)

Need help with X Shield? Email [support@b2bgold.app](mailto:support@b2bgold.app).

## More on X Shield {#related-heading}

- 24 September 2026 **[How to Block a Customer on Shopify](/blog/block-customer-shopify/)** Shopify has no block button. Stop a problem customer with Fraud Control rules, Shopify Flow, account settings and IP blocks, and see which they can get around.
- 24 September 2026 **[Should You Block VPN Traffic on Your Shopify Store?](/blog/block-vpn-shopify/)** Blocking VPNs stops some fraud and some honest shoppers. How Shopify treats VPNs, what iCloud Private Relay changes, and a narrower option: scraper networks.
- 24 September 2026 **[Does Blocking Countries Hurt SEO on Shopify?](/blog/geo-blocking-seo-shopify/)** Googlebot crawls from the US and beyond, and Google says to treat it like a visitor from that country. When geo-blocking is safe for Shopify SEO, and when not.
