# X Shield Blocked a Real Customer? Find Out Why {#doc-title}

By [B2B Gold](/about/#how-we-write) Updated 26 September 2026 [X Shield page](/shopify/x-shield/) [X Shield on the Shopify App Store](https://apps.shopify.com/x-shield-store-guard?utm_source=b2bgold.app&utm_medium=referral&utm_campaign=docs&utm_content=docs/x-shield/customer-blocked&utm_term=docs-header)

## Why was a real customer blocked? {#why-was-a-real-customer-blocked}

When X Shield blocks a real shopper on your Shopify store, it is usually one of four things: a country rule they don’t pass, a VPN or data-centre network, a browser extension on the spy-extension list, or an IP rule matching an address they share. Find their visit in X Shield Analytics: it names the protection and the reason.

While you investigate, you can switch to dry run (**Safety & testing** → **Observe only** → **Save**) so nobody else is turned away. It pauses all blocking until you switch back.

## How do I find their visit? {#how-do-i-find-their-visit}

Look it up in X Shield’s **Analytics**, by time or IP address. It helps to ask the customer when it happened and for a screenshot: unless you turned off **Show blocking reason**, the blocked page shows the reason X Shield recorded.

1. Open **Analytics**.
2. On paid plans, go to **Events**, change the **All events** filter to **Blocked**, and type their IP address in **Search IP** if you have it. On the Free plan, use **Recent blocked visitors**, which lists your latest 200 blocked visitors.
3. Click the row. **Event details** shows their IP address, network, country, city and page, and a **Detail** line with the reason.

Can’t find the visit? Ask for their public IP address (searching “what is my IP” shows it) and their country. Enter both in **Safety & testing** → **Test your rules** and click **Test**. That checks your country and IP rules only.

## What does each block reason mean? {#what-does-each-block-reason-mean}

The **Detail** line tells you which rule fired. “(B)” means the rule is in **Block listed** mode and “(A)” means **Allow only listed**. The examples use documentation addresses.

| Detail | What happened | Usual fix |
| --- | --- | --- |
| `Access denied from FR (B)` | Their country, or city, is on your block list | Remove it if you sell there |
| `Access denied from FR (A)` | Their country isn’t on your allow list | Add it if you sell there |
| `IP 203.0.113.7 is blocked` | Their address is on your IP list, or inside a range on it | Narrow or remove the entry |
| `IP 203.0.113.7 is not allowed` | **IP & Network** is set to **Allow only listed** | Switch back to **Block listed** unless you mean it |
| `Access denied from AS64500 (B)` | Their whole network is on your list | Remove the network |
| `VPN ASN (64500)`, `VPN/Proxy cloud ASN (64500)` or `TOR browser detected` | **VPN/Proxy protection** caught a VPN, proxy, data centre or Tor | [Narrow VPN blocking](#narrow-vpn-blocking) |
| `Scraper network ASN (64500)` | **Scraper network blocking** caught a scraping-prone data centre | Add their IP to **Global bypass** |
| `Spy extension detected: …` | An extension in their browser is on the detection list | Ask them to turn it off while they shop |
| `Developer tools detected - security policy violation` | **Developer tools protection**: they opened developer tools | Usually staff: give them your private access link |

Two causes surprise merchants. Mobile carriers and offices put many people behind one IP address, so blocking it blocks them all. And the spy-extension list includes general Shopify, SEO and tag-debugging tools, such as *DataLayer Checker Plus* and *Shopify Developer Tools*, which agencies and staff use.

## How do I let them in without weakening the rule? {#how-do-i-let-them-in-without-weakening-the-rule}

Fix the cause where you can: if a rule catches people you sell to, loosen it. To let one person in while the rule stays, add their IP address to **Global bypass** → **Whitelisted IPs**, the list that gets through every protection.

In order of preference:

1. **Loosen the rule.** Add the country to your allow list, remove a range that is too wide, or narrow VPN blocking; [block or allow countries](/docs/x-shield/block-countries/) and [block IP ranges and networks](/docs/x-shield/block-ip-addresses/) cover each setting. On paid plans, **Event details** in **Allow only listed** mode offers **Allow** buttons that add the country or address to your list.
2. **Exempt the address from country rules only.** Add it to the **IP whitelist** on **GEO control**: “These IPs always get in, even from a blocked country.”
3. **Exempt the address from everything,** using **Global bypass** as below.

### Add their IP to Global bypass {#add-their-ip-to-global-bypass}

1. Open **Global bypass**.
2. Under **Whitelisted IPs**, paste their address, for example `203.0.113.7`, and a label such as their order number. Click **Add**.
3. Click **Save** in the save bar. The toast reads **Configuration saved successfully**.
4. Check it in **Safety & testing** → **Test your rules**: enter the address and click **Test**. The result reads **Let through**.

> **Important:** Don’t switch **IP & Network** to **Allow only listed** to let someone in. That mode doesn’t add an exception: it admits only the addresses and networks on its list, and in the app’s words, “Everyone else is blocked.”

Home and mobile IP addresses change, so an exception can stop working later. Never send customers your private access link, which skips every rule for whoever holds it. Keep it for staff and agencies, and for yourself: [get back in with your private access link](/docs/x-shield/safety-and-testing/#locked-out).

### Narrow VPN blocking {#narrow-vpn-blocking}

**VPN/Proxy protection** is the protection most likely to turn away paying customers, because many people browse through work VPNs and privacy services. If it is catching real customers:

1. On the **Overview**, turn off **VPN/Proxy protection** and turn on **Scraper network blocking** instead. It blocks a short list of networks, “Alibaba, Tencent and Huawei clouds, and scraper hosting”, without touching consumer VPNs.
2. If a home broadband or mobile network is being treated as a VPN, send support the **Detail** line. Consumer and mobile networks aren’t meant to be on X Shield’s list, and support can add an exception.
3. Try the new setup in dry run before you rely on it.

## How do I stop it happening again? {#how-do-i-stop-it-happening-again}

Test every new rule in dry run before you enforce it, keep **VPN/Proxy protection** off unless anonymous traffic is costing you orders, and use **Allow only listed** only if every country you sell to is on the list.

- Keep **Show blocking reason** on (**Blocked page** → **Message**), so customers can tell you why they were blocked.
- Not sure what went wrong? On the **Overview**, click **Contact support** under **Need help?** and choose the topic **Real customers are blocked**.

## Related {#related}

- [Test rules in dry run with the rule tester](/docs/x-shield/safety-and-testing/)
- [VPN and scraper-network blocking](/docs/x-shield/vpn-proxy-scraper-blocking/)
- [Spy-extension protection](/docs/x-shield/spy-extensions/)
- [X Shield Analytics and email reports](/docs/x-shield/analytics/)

[X Shield: IP Country Blocker](/shopify/x-shield/)

X Shield is a Shopify app that blocks visitors by country, IP address or network, and turns away the bots, VPNs and spy extensions it detects, showing them a blocked page instead of your store. Googlebot and Bingbot, checked against their published IP ranges, still get in, and dry run lets you test every rule before it blocks anyone.

[Install free on the Shopify App Store](https://apps.shopify.com/x-shield-store-guard?utm_source=b2bgold.app&utm_medium=referral&utm_campaign=docs&utm_content=docs/x-shield/customer-blocked&utm_term=card) [Plans and pricing](/shopify/x-shield/#pricing) [How X Shield compares with Blockify](/compare/x-shield-vs-blockify/)

Need help with X Shield? Email [support@b2bgold.app](mailto:support@b2bgold.app).
