Small Businesses Battling Bot Traffic
Small business owners are experiencing significant spikes in website traffic, overwhelmingly attributed to bot activity. These bots inflate session counts, skew analytics, and require constant mitigation efforts, often proving ineffective despite attempts at solutions like Cloudflare. The problem is causing frustration and a need for more robust bot detection and prevention strategies.
SOURCES (60)
“I’ve encountered similar patterns in the past, and they often involve bot or crawler traffic rather than genuine listeners. A sudden surge in traffic from a single country, accompanied by numerous episodes and identical browser/device signatures, is definitely an unusual occurrence. I hope Captivate can…”
I am seeing a small but consistent number of spam accounts being created on my Discourse forum each day. Many appear to be using fake or invalid email addresses. I am looking…
“I can see my website recording with PostHog and can tell which cheap clicks are bots (very strange screen res and they have the same actions every time) vs real people. And Meta seems to enjoy spending money to send me these clicks and it is greatly hurting my ads. Any ideas on how to fix? submitted by /u/dsplusturtles [link] [comments]”
To me it looks like bot traffic. And that could be for many purposes.
“That iOS-Safari-only behaviour really smells like ITP (Intelligent Tracking Prevention). Safari aggressively partitions and clears client-side storage, so if your bot-check or rate-limiter leans on a cookie or localStorage token to remember "this visitor is fine," Safari keeps wiping it — every visit looks brand-new and slightly suspicious, and the captcha fires fast. Chrome and Android don't purge like that, so they rarely trip it. Worth checking whether that check can key off a f”
“When you see stuff like this (no matter who the host is) let them know about it. Bots are like the world's largest game of Whack-a-mole. You ID one, and another five show up. When I worked at Libsyn, I was amazed that the number of downloads was triple what you saw in your dashboard (so the dashboard showed 10, but the raw files showed 30, and 20 of those were bots). When you have any concern about your media host (as someone who worked for one) ALWAYS bring your concerns to the host. If the”
“Has anyone using Captivate for their podcast host had any unusual traffic recently? I've been with them for over 18 months now and never had a single issue with our stats. Over the past few weeks however, on certain days we've had some unusual download behaviour and I'm becoming more and more concerned that Captivate has an issue it can't control. I've spoken to them and they say they are looking into it. Today's traffic consisted of 31 downloads across 30 different episo”
“I would really appreciate any insight you guys could provide on why I have a sessions count over a 100000 in the last three days coming from Singapore? Is this something or someone preparing to copy my website for fraudulent purposes? submitted by /u/Individual-Dark-285 [link] [comments]”
“I want to advertise on Taboola, but i heard that if you dont spend a lot of money on taboola, they will give you bot traffic. Is it true? submitted by /u/Practical-Theme-9767 [link] [comments]”
“TLDR: Clients mostly just care about human visitors, but as a web dev, I want to know about all traffic I think we can all agree that some bots are "good", some are "bad", and most are somewhere in between. For years, I've tolerated Google's crawler / spider because it enabled Google search result pages that potentially brought traffic to my sites. But recently I think many of us have experienced all sorts of scraper bots hitting our sites with massive traffic with li”
“In building some stuff, I've noticed how much additional resources are needed to get through firewalls and Cloudflare stuff without a whitelist. Does anyone have any before/after results, experiences, do you make sure to always do it? submitted by /u/EverySecondCountss [link] [comments]”
“429 is usually rate limiting, so it may go away after the limit window resets, but I wouldn’t just wait if the agent was actively making changes. Pause the automation first so it doesn’t keep retrying and extend the problem. Then check server/CDN/WAF logs to see what endpoint got hammered, restore from backup if the site changed unexpectedly, and rotate any credentials the agent had access to if you’re not sure what it touched. If it’s WordPress admin/ajax traffic, a plugin or security layer may”
“Likely bots tearing into OP. Or retired Boomers who have the mission to continue to kindeff the world until they all die out. There’s some really twisted, nefarious botting happening in Reddit in all the professional/work related subs I’m in, from antiwork to managers, womenengineers… posts and comments that make me 😳🥴”
“Normal-ish. Ad platforms count clicks at their edge; your analytics counts people who actually survive redirects, blockers, consent banners, slow loads, duplicate clicks, etc. Use UTMs + server logs as the source of truth. The platform dashboard is more of a sales brochure with charts.”
“Seeing a 100% increase in cpms since April anyone else facing same issue submitted by /u/Admirable_Orchid_789 [link] [comments]”
“that screenshot is exactly it, same domain but look at the usernames. tu877 ari639 um408 nobody types like that, theyre generated. domain checks wont help here because the domain is real. the pattern in the username is what gives it away”
“mostly bots indexing stack. had same traffic on blank domain with default nginx screen, they just run IP ranges looking for vulnerabilities.”
“> There are ways to tell the difference — the bots usually do not fetch images or CSS, for example — but, by the time that determination is made, the address in question will not be used again. Blocking the address at that point is just a waste of time.Maybe there's no point for the scanned server to block the address, but couldn't collective / shared block lists help with sites that may get scanned by the same address after the initial one?The main problem becomes managing lists of millions of”
“>There are ways to tell the difference — the bots usually do not fetch images or CSS, for example — but, by the time that determination is made, the address in question will not be used again. Blocking the address at that point is just a waste of time.I don't get it. Don't we keep blacklists of this stuff? And if they hammer thousands of requests per site per second and never reuse an IP, they'd run out of addresses in a few weeks.Then they'd switch to IPv6, and... well, are we using IPv6 for an”
“Hi all. My CPM has dropped really low lately. Sounds cheap and the traffic quality went down with it, LPV dropping, basically trash traffic. It was way healthier before. Anyone who knows what to do in such cases and how to root cause it? submitted by /u/Abject_Plastic4525 [link] [comments]”
way i did it was seal off the login page to its own /url route and block anyone from accessing it without a confirmed captcha token they get from home page. so…
“I later implemented behavioural pattern analysis based blocking Please tell us more about what you did.”
“So it is a story from few months ago when i was working on something and i suddenly got a mail that my project is having 2000+ users now , so i thought that it got viral somehow. Then i opened my admin dashboard and the emails were like abc1@gm .... , abc2@gm .... and all were unverified so i was sure it is a bot attack! But it was my first time seeing something like this , at first i got panicked that what is happening this way my database storage will be over soon. Then i calmed down a bit and”
“Yeah. That company’s spammy. A client of mine got the emails and was then offered money to take a demo. No idea if he ever got the money, but he said their CEO claims to have been a GC but never was.”
“Remove the item from your store or make it very expensive and turn on manual capture for payments”
“Hey Folks, One of my clients is getting a huge surge of traffic according to GSC... but it's all weird mispellings of clearly another brand. I'll make up fake names but if my clients name was CleanGood(dotcom) Starting in May, they started getting a ton of traffic from branded search queries for businesses that don't exist or obvious odd misspellings to simple words in the company's brandname. Some clear mispellings like CleanGiod or including the (.com) with another weird spelli”
Does nothing. They just visit your checkout through the myshopify domain.
“As a start, turn payment capture to "manuali" or "capture on fulfillment". This will prevent you from having to do refunds and losing the fees. You can have flow look at each order and either a) capture funds if it is a good order b) cancel the order if fraudulent. (They may stop testing in your store if they are unable to successfully test cards)”
“I've been seeing massive spikes over the last three days. I've looked around to see if we got mentioned in some national media article (it's happened before) but it's very likely that it's bots. So annoying.”
“I am having a similar problem. One day, about 50 orders came in that were high risk. I also use authorize.net. Any update on the possible resolution?”
“have not heard of 500 orders in a day from a bot. that's awful. make sure you are set to manually accept the funds so you don't have to refund all the money and lost the payment processing fees.”
“Omfg what happened to the comment section. Sorry you’re dealing with this OP. Maybe install an IP blocker app. You’ll see the IP of the attack from a specific country or the IP will be static. Maybe that’ll help. The one I used I think was MIDA Fraud Filter IP Blocker. It’s free. Amazing for free.”
ok i think i found that app https://apps.shopify.com/fraud-control
“Yup, last two days have each had about 1000 extra reporting as web browser listens that I'm just discounting fully. Which I think also means that this usually isn't hitting any charts. Odd part is its certain episodes getting hit hundreds of times.”
“This has happened to me as well (spike, all within a v short span of time, single ep, Chrome). I figured it was bot/scraping.”
“Blockify: Fraud Filter works really well to block most direct attacks, at least for me so far. It stops "fake" checkouts, card testing bots and proxy/VPN nonsense fairly effectively.”
“Im seeing numbers i havent seen in 10 years doing facebook ads on campaigns that are winners. Atcs and conversions basically zero today. Traffic quality is the worst ive seen, bounces. There has to be an outage today submitted by /u/Huge_Kaleidoscope_40 [link] [comments]”
“This happens every few months sometimes longer but I'll see a huge spike in downloads and I have no idea why. Yesterday, I got over 1000, and today, over 300. We're not big by any means, we just barely got over 10k downloads since we started doing this over 5 years ago so I'm just wondering where these huge spikes are coming from? I've read in previous posts that it's probably bots scraping your RSS or something, but to have it happen like this two days in a row, it can't”
“What is the point of knowing the limit? Unless they're paying or adding value of some sort, bots aren't real visitors.”
“seems to be. compare the visitors to page views, it shows a likelihood of bots since clearly most "visitors" are only accessing one page at most”
“Another day of over 1K bots from Ashburn hitting my site. Am I paying for this? submitted by /u/FeedDirect [link] [comments]”
“Every couple weeks or so, Aline sends me unsolicited marketing emails. Now, it's totally normal to get marketing emails, but what's not at all normal is that Aline sends emails from a different domain every single time so you can't ever effectively block them by email address. I was annoyed at first, but after the 3rd or 4th time, I turned this spam into a research project for the benefit of anyone who might be facing this problem too. The domains they've used to date include (li”
“I've been getting hit by a constant barrage of bots scrapping my website, i've tried all sorts of cloudflare waf rules, nothing seems to be stopping them, they rotate country, ip and stuff and keep hitting me back as soon as i block them using the rules. It's tanking my cpm, this is so fustrating. I've completely blocked off china, hongkong and singapore and sometimes somehow they manage to slip through even with full country block submitted by /u/lordchickenburger [l”
“I feel like it would happen to nearly anyone who self host. I think it's pretty standard to block China and Russia.”
“Sounds like a bot farm tbh. The jump from web browser + a single country that doesn't speak the language is pretty textbook. Someone's running scripts to inflate numbers, probably testing their setup on random small podcasts before selling the "service" to people who actually want fake streams. If you dig into the city-level data on Spotify for Podcasters you'll probably see it's all coming from one or two IP blocks. Nothing to worry about, but the stats are useless now”
“Read and follow reddiquette; no excessive self-promotion. Please refer to the Reddit 9:1 rule when considering posting self promoting materials.”
“These are bots might be cloudflare or others AI or something trying to cache your website.”
“Ok great man, then the US traffic is bots, probably AI scrapers from microsoft, meta, ect, no need to get offended I'm just telling you a lot of direct traffic from countries like India, China, and the U.S. are usually bots.”
“I’m a bit new to analytics so this could be totally false information - but I’m pretty sure need to add dedicated UTMs to places you are dropping your URL so attributing traffic source is a little easier. For example, people reaching your URL via social media organically will show up as direct as they won’t add the source with link creation automatically… example truckpacker.com/?utm_source=instagram&utm_medium=social&utm_campaign=truckpacker_instagram_profile&utm_content=truckpacker”
“I've been consistently getting 60% of my traffic from no source, every analytics dashboard says Direct. and I've tried them all. I simply can't imagine people typing in website URL directly since it's a two-month old SAAS. So can anyone help me with this? submitted by /u/BackpackerBaba [link] [comments]”
“Ive seen these data center bots before but last few days they're hiting my site every other day for several hours. Anyone seeing this more lately? submitted by /u/Huge_Kaleidoscope_40 [link] [comments]”
“Does anyone else have to request blocks in their region? This started a couple of months ago, I would assume thanks to those who cheat the system for blocks, it’s been incredibly hard for me to obtain a block. Is there a something I could be doing differently to get a request accepted? submitted by /u/Comfortable-Dare-797 [link] [comments]”
“I read the Huntress 2026 threat report ( https://www.huntress.com/resources/2026-cyber-threat-report ) and the RMM abuse stat stuck with me, 277% increase YEAR OVER YEAR. TL;DR for people who dont wanna read: attackers are increasingly not bothering with malware, they just hijack the remote monitoring and management tools your IT team already uses, because that activity blends into normal admin stuff and most detection doesnt flag it. So I naturally went digging into our own setup afterward and”
