Country Shield user guide.

Follow the complete setup sequence, understand each rule, test safely, and resolve the most common storefront and billing issues.

Before you start

You need a Shopify account that can install apps and customize the active theme. Keep your permanent myshopify.com domain available; a custom storefront domain is not used for installation.

Country Shield is safest to launch with a small denylist. Move to allowlist or strict mode only after the basic storefront check is working.

Install Country Shield

1

Start from Shopify

Use the Country Shield App Store listing or enter your myshopify.com domain on the Country Shield website.

2

Review requested permissions

Shopify shows the app permissions before installation. Approve the install to open the embedded Country Shield admin.

3

Confirm the store shown in the header

The merchant app displays the permanent store domain and current plan. Stop and contact support if the domain is not the store you intended to configure.

Create your first protection rule

1

Open Protection rules

Choose Denylist to block only selected countries. Choose Allowlist to block every country except your selections.

2

Add countries

Free stores can add two countries. Pro and Premium remove the country limit. Paid plans can also add supported regions or states.

3

Choose an action and scope

Start with Block and Whole store. Redirect and challenge are paid actions. Checkout-only applies the rule only on checkout paths.

4

Save changes

The right-side preview summarizes the policy. Country Shield enforces plan limits on the server when you save.

Enable the theme app extension

Rules are not applied to storefront traffic until Shopify loads the Country Shield app embed.

1

Open the theme editor

In Shopify admin, go to Online Store → Themes, then choose Customize for the active theme.

2

Open App embeds

Choose the App embeds icon in the theme editor. Find Country Shield and switch it on.

3

Save the theme

Use Shopify's Save control. Return to Country Shield and confirm that you enabled the extension.

Changing or publishing a new theme can require you to check App embeds again. Verify Country Shield after any theme change.

Test without locking yourself out

  1. Open Protection rules and scroll to Test your rule.
  2. Select a country and use Preview decision. This evaluates the saved policy without creating a fake storefront request.
  3. Open the live storefront in a private browser window.
  4. Use a location you intentionally blocked and confirm the expected action.
  5. Return to Overview and confirm the setup checklist is complete.

When testing allowlist mode, include your own location before saving. When testing strict mode, confirm both an allowed and blocked location.

Understand actions and scope

Block

Matched visitors see the Country Shield interstitial. Paid plans may use a custom message.

Redirect

Matched visitors are sent to the HTTPS URL you enter. Verify that the target page does not redirect back to the blocked storefront.

Challenge

Matched visitors receive the supported verification path. This action is available on paid plans.

Whole store vs checkout only

Whole store checks every storefront path. Checkout only allows normal browsing and evaluates checkout paths.

Strict mode

Strict mode hides page content until an allow decision arrives. It fails open after a short timeout so a Country Shield outage does not leave the storefront permanently hidden.

Plans and Shopify billing

Open Billing inside Country Shield to compare plans. Shopify hosts plan selection and charge approval. Charges appear on the Shopify invoice, and merchants can upgrade or downgrade without reinstalling the app.

  • Free includes two countries and basic blocking.
  • Pro adds unlimited countries, regions, paid actions, analytics, strict mode, and custom messaging.
  • Premium adds ASN/IP rules, Cloudflare sync, and provider-dependent anonymous traffic controls.
VPN, proxy, Tor, and hosting-provider controls remain disabled until the licensed Premium threat database is connected. The merchant app shows the current availability.

Connect Cloudflare on Premium

  1. Create a restricted Cloudflare API token for the single zone Country Shield will manage.
  2. Copy the Cloudflare Zone ID and token into the Cloudflare page in Country Shield.
  3. Choose Connect and sync.
  4. Review the displayed zone name and last-sync state.

Country Shield encrypts the token at rest. Disconnecting performs a best-effort removal of the Country Shield WAF rule and deletes the stored connection.

Troubleshooting

The app says “Not active yet”

Save a ruleset, enable Country Shield under App embeds in the active theme, save the theme, and confirm the setup step in the embedded app.

Shopify asks me to reconnect

The store's rotating offline token may have expired or become invalid. Use the reconnect action and approve the same scopes again.

A paid plan still shows Free

Return from Shopify's hosted plan selection page and wait for verification. If the plan does not update, contact support with the store domain and approximate approval time.

The wrong country is detected

Country decisions rely on the visitor's public IP and the current GeoIP database. Corporate networks, mobile carriers, and VPNs can exit in another location.

VPN or Tor controls are unavailable

The Premium anonymous-IP provider database is not currently connected. Country and ASN rules remain available according to plan.