As we progress into the future, with the rise of advanced, powerful AI systems becoming a daily reality for all, we have constantly seen a rise in autonomous spam traffic sent by large botnets working in a way that makes them look like humans.
As a result, even our advanced bot detection and mitigation system is also unable to distinguish them from legitimate human users. This leads to these bad botnet requests reaching your website, increasing your server resource usage, and being used by these botnets to either scrape your website or train other autonomous systems.
What is Visitor Verification?
Visitor Verification is a security feature on the Boost plan (Cloudflare Enterprise) that helps ensure the traffic reaching your site is from real people. Automated traffic from botnets that mimic human browsers is held back at the edge, unable to pass the challenge, before it ever reaches WordPress.
It is off by default and can be turned on or off per site.
Why might you need it?
Modern bot traffic no longer comes from obvious sources. A large share now arrives through residential ISP addresses, thousands of them, each making only a handful of requests with normal-looking browser signatures. Because it looks and behaves like real visitors, automated detection (including Cloudflare's own) cannot reliably separate it from genuine readers.
If you are seeing any of the following, Visitor Verification is likely to help:
A spike in recorded visits that does not match your analytics or ad revenue
Automated traffic that returns from a new country each time you block one
Server load or 502s driven by traffic you cannot account for
It is the most effective tool we have for this pattern, because it verifies each visitor at the door rather than trying to identify bad traffic after it is already in.
What do your visitors see?
When a visitor arrives, their first request is met with a brief check. A blurred snapshot of the page they requested loads in the background while a small pop-up confirms they are a real browser. Once it passes, the real page opens.
For a genuine visitor, the whole thing clears in about a second and requires nothing from them. Because they see your site coming into focus behind the check rather than a separate security screen, it reads as the page loading, not an interruption. A reader should never feel they have left your site.
What still gets through?
The challenge is aimed at traffic pretending to be a human browser. It is not applied to everything. The following continue to work normally while it is on:
Verified search crawlers such as Googlebot and Bingbot, so your indexing and rankings are unaffected
Static files and core site functions
A large, maintained allowlist of legitimate third-party services
That allowlist already covers the tools most sites use, including the major ad and ad-verification vendors, analytics and SEO crawlers, social and publishing integrations, and common WordPress and WooCommerce services. In most cases, there is nothing you need to do before turning the feature on.
If a specific tool you rely on is not yet covered, we can add it quickly. See the section below.
What if a tool has an issue after enabling?
Most services are already accounted for, so the majority of sites see no side effects. If something you depend on stops working after you enable Visitor Verification, do not disable the feature first. Submit a ticket, and we will confirm whether it is already on the allowlist and add it if it is not. Adding a service is fast and does not require turning the feature off.
How to enable the feature?
Open the WPO Portal and select the website for which you want to enable it
Once you have opened the domain for which you want to enable it, go to the Cloudflare tab
Under the Cloudflare tab, choose the Enterprise Settings section
Within the Enterprise Settings section, scroll down to the Security Settings, where you will see the option to enable the Visitor Verification feature.
What happens after enabling?
Give it a little time and then compare your traffic dashboard against your analytics. If the feature is doing its job, your recorded visits should move closer to the real audience you see in your own reporting, and any load driven by that traffic should ease.
If a tool or service stops working after you enable Visitor Verification, submit a ticket. Do not disable the feature first. In most cases, the fix is simply adding that service to your allowlist, and we can guide you through the best course of action.
FAQ
Will my readers have to pass this every time they visit?
Will my readers have to pass this every time they visit?
No. Once a visitor is verified they are not challenged again for the remainder of their visit.
Will this hurt my SEO?
Will this hurt my SEO?
No. Verified search crawlers such as Googlebot and Bingbot are excluded from the challenge and continue to access your site normally.
Will it affect my ad revenue?
Will it affect my ad revenue?
It should not. The major ad and ad-verification vendors are already on our allowlist and pass through without being challenged. If you use a less common ad service and want to be sure, mention it in a ticket, and we will confirm it is covered.
Can I turn it off?
Can I turn it off?
Yes. It is a per-site toggle and can be disabled at any time.
Is there any impact on legitimate visitors?
Is there any impact on legitimate visitors?
The check adds roughly a second to a visitor's first request and requires no action from them. After that, browsing is normal.



