A policy model merchants can explain
Every store has one active ruleset. Denylist mode blocks only selected locations. Allowlist mode serves selected locations and blocks all others. Merchants can apply the rule to the whole storefront or to checkout paths.
Location controls
- Country rules use ISO country codes and are available on every plan.
- State, province, and region rules are available on Pro and Premium.
- Free stores can select up to two countries; paid plans remove that limit.
Choose what happens on a match
Block
Show a storefront interstitial with the merchant's configured message. Free stores use the standard Country Shield message; paid stores can customize it.
Redirect
Send the visitor to a merchant-provided HTTPS URL. Redirect is available on Pro and Premium.
Challenge
Apply the supported verification action for a matched request. Challenge is available on Pro and Premium.
Strict mode
Strict mode hides storefront content while the decision is pending. It reduces visual exposure to blocked visitors but should be tested for perceived loading behavior.
Features are enforced on the server
The merchant interface explains plan limits, but the decision API and ruleset save endpoint enforce them independently. Editing browser requests cannot unlock paid features or exceed country limits.
- Free: two country rules, basic blocking, standard message.
- Pro: unlimited countries, regions, redirects, challenges, analytics, strict mode, and custom messaging.
- Premium: Pro features plus ASN/IP controls, Cloudflare sync, and provider-dependent anonymous traffic controls.
Useful activity without visitor profiles
Country Shield records aggregate counts by hour, country, reason, and action. Pro and Premium merchants can review recent activity and country totals without browsing individual visitor records.
Optional Cloudflare edge enforcement
Premium merchants can connect a restricted Cloudflare API token and zone. Country Shield verifies access, stores the token encrypted, and mirrors supported rules to a managed WAF rule.
- Cloudflare is optional; Country Shield can operate through the Shopify theme app extension without it.
- A failed edge sync is recorded and shown to the merchant and operator.
- Disconnect removes the Country Shield edge rule on a best-effort basis and deletes stored connection credentials.
Current availability
The merchant app reports this capability directly. Country Shield does not silently present unavailable threat signals as active protection.