Knowledge base

Bot fight mode: what it does, and what it can block

Bot fight mode challenges automated traffic at the edge before it reaches your site. It is off unless you switch it on, and it can block uptime monitors, payment callbacks and some crawlers — verified search crawlers such as Googlebot and Bingbot still get through.

Bot fight mode is a setting on your site's edge network. It looks at every request before it reaches your site and challenges traffic that behaves like an automated program rather than a person — scrapers, content thieves, spam tools and vulnerability scanners.

Is it on for my site?

It is off unless you switch it on. We never switch it on for you, on any hosting plan.

To check, open Sites, choose the site, open the CDN tab and look at Security and bot control → Bot fight mode. The switch shows the setting that is actually in force at the edge, read back each time you open the card.

What can it block?

Anything automated. Before you switch it on, think about what reaches your site that is not a person with a browser:

  • Uptime monitors that fetch your pages on a schedule — including ones you pay for elsewhere.
  • Payment providers' callbacks and other services that post to your site to tell it
  • something happened.

  • Some crawlers. Search engines' verified crawlers, such as Googlebot and Bingbot, are
  • recognised and let through, but SEO tools, link checkers, feed readers and smaller crawlers may be challenged.

  • Scripts or tools you run yourself against your own site.

If one of these stops working after you switch bot fight mode on, that is the likely cause — switch it off again.

How do I switch it on or off?

Open the site's CDN tab, find Bot fight mode under Security and bot control, and use the switch. The change is made at the edge straight away and the card reads it back.

The switch is greyed out or refused

  • "We could not read your bot settings" — our access to that setting on the part of the edge
  • network your site uses is being upgraded. Nothing is wrong with your site; try again later.

  • The site uses a shared preview address — a site that is still on its preview address shares
  • its edge settings with every other site on that address, so they cannot be changed for one site. Connect your own domain and the controls become available.

  • You do not have permission — changing security settings needs the manage CDN permission
  • in your organisation. Ask an owner of the organisation.

Latest from the blog

What we have been writing about hosting, SEO and running sites at scale.

SEO and Link Building from the Hosting Layer: A 2026 Operator's View

How hosting shapes indexing and link equity in 2026: keeping pages indexed, vetting aged domains before you build on them, link building without a footprint, and an honest line on what infrastructure can and cannot do for SEO.

Read the post

Making WordPress Fast and Secure: A Performance and Plugin Checklist

A practical checklist for fast, secure WordPress: server-level caching, a per-site object cache, the handful of plugins worth running, keeping the stack current, and the WooCommerce pages you must never cache.

Read the post

How to Choose Managed Web Hosting in 2026: A Buyer's Guide

What actually separates good managed hosting from a cheap box with a control panel — migrations, backups, isolation, real caching and honest scaling — and how to judge it before you commit.

Read the post

Read the blog

Still stuck?

Support is included on every plan, the desk is open 24 hours a day, and you can write to us in any of our 58 languages — we answer you in yours.

Contact support All articles