Overview
SecurEcommerce lets you control store access through multiple blocking methods. This guide covers setting up your first blocking rules.
Before You Start
Consider:
- Where do you ship? Block countries you don’t serve
- Fraud patterns: Are attacks coming from specific regions?
- VPN policy: Do you want to block anonymized traffic?
- Known bad actors: Any specific IPs to block?
Step 1: Access Blocking Settings
- Open SecurEcommerce in your Shopify admin
- Click Blocking in the sidebar
- You’ll see options for different blocking types
Step 2: Configure Country Blocking
To block entire countries:
- Click Country Blocking
- Choose your approach:
- Blocklist: Block specific countries, allow others
- Allowlist: Allow specific countries, block others
- Select countries to block/allow
- Click Save
Tip: Start with blocklist mode, adding countries as needed.
Step 3: Set Up VPN/Proxy Blocking
To block anonymized traffic:
- Click VPN/Proxy Blocking
- Toggle Enable VPN Detection
- Choose your action:
- Block completely
- Show warning message
- Allow but flag
- Click Save
Tip: Start with “Show warning” to see impact before blocking.
Step 4: Configure TOR Blocking
TOR traffic is higher risk than VPNs:
- Click TOR Blocking
- Toggle Block TOR Exit Nodes
- TOR traffic will be blocked automatically
- Click Save
Recommendation: Most stores should block TOR.
Step 5: Add IP Blocks (Optional)
To block specific IPs:
- Click IP Blocking
- Click Add IP
- Enter the IP address or CIDR range
- Optionally add a note explaining why
- Click Save
Use this for known bad actors you’ve identified.
Step 6: Customize Block Messages
Make your block messages helpful:
- Go to Block Message Settings
- Write a clear, professional message:
Example:
“Access to our store is restricted from your location. If you believe this is an error, please contact support@yourstore.com”
- Optionally configure redirect URL
- Click Save
Testing Your Configuration
After setup, verify blocks are working:
- Country blocks: Use a VPN to appear in a blocked country
- VPN blocks: Connect via VPN and check response
- IP blocks: Check from blocked IP if possible
Monitoring Blocked Traffic
Track your blocks:
- Go to Analytics in SecurEcommerce
- View Blocked Visitors report
- See breakdown by block type
- Identify patterns
Adjusting Over Time
Blocking is iterative:
- Review regularly: Check if blocks are appropriate
- Monitor feedback: Are legitimate customers blocked?
- Add new blocks: Respond to emerging threats
- Remove old blocks: Clean up unnecessary rules
Best Practices
- Start conservative - Add blocks gradually
- Document reasons - Know why each rule exists
- Monitor impact - Watch for unintended blocks
- Clear messaging - Help blocked users understand
- Regular review - Adjust as patterns change
Common Configurations
Ship to US/Canada Only
- Enable country allowlist
- Allow: United States, Canada
- Block all others
Fraud Prevention Focus
- Block high-fraud countries
- Enable VPN blocking
- Enable TOR blocking
Maximum Access
- Minimal country blocks
- VPN: Warn but allow
- Block only specific IPs
Troubleshooting
Legitimate customers blocked?
- Check country/region accuracy
- Review VPN blocking settings
- Provide customer service contact
Blocks not working?
- Verify rules are saved
- Check for conflicting rules
- Clear browser cache when testing
Too many false positives?
- Loosen VPN settings
- Narrow country blocks
- Switch from blocklist to allowlist