How to Block Tor Traffic on Shopify (and Why You Should)
Block Tor exit-node traffic on your Shopify store in 2 minutes. Stop card-testers, scrapers, and anonymous fraud at the source.

Tor traffic on a Shopify store is rarely legitimate. Almost no real customer uses Tor to shop — but card-testers, fraud rings, and scrapers love it because it cycles through thousands of exit nodes globally, making them nearly untraceable.
If your store has even occasional Tor traffic, blocking it is one of the highest-yield, lowest-risk fraud controls you can deploy. This guide explains how.
Why Tor visitors are usually fraud
Tor (The Onion Router) routes traffic through three randomly chosen relay nodes before reaching the destination. The final hop — the exit node — is what your Shopify store sees as the visitor IP.
Legitimate Tor users exist (journalists, dissidents, privacy researchers). But the legitimate-to-fraud ratio on e-commerce stores is roughly 1 to 50. Common Tor patterns we see in merchant data:
- Card testing. Tor cycles IPs every few minutes, allowing fraudsters to test stolen cards without rate-limit triggers.
- Chargeback fraud. Buyers in countries with strict consumer-protection laws use Tor to mask their location while still shipping to a real address.
- Scraping. Competitor data-harvesters use Tor when residential proxies fail.
- Account abuse. Bot accounts using Tor for newsletter / referral / coupon abuse.
The economic case is clear: blocking Tor costs you near-zero legitimate sales and prevents a meaningful percentage of chargebacks.
How to block Tor on Shopify in 2 minutes
- Install Shieldy Fraud Filter.
- Open the app → Bot Killer.
- Toggle Auto block Tor to ON.
- Save.
That is it. The block goes live in under a minute. Shieldy's database refreshes the Tor exit-node list every 30 minutes from the public Tor directory, so newly added exit nodes are blocked within half an hour of joining the network.
Tor blocking is part of the Enterprise plan at $8.99/month. The Free and Premium plans do not include it because Tor specifically targets stores that already see significant fraud — usually merchants who have already moved past free protection.
What about Tor bridges and obfuscated relays?
Tor bridges are "hidden" relays not listed in the public directory — used by people in countries that censor Tor itself. Bridges are harder to enumerate, but recent advances in network fingerprinting can identify Tor traffic at the protocol level.
Shieldy detects bridges via:
- TLS handshake fingerprinting
- Traffic pattern analysis (Tor has a distinctive request cadence)
- Known bridge IP allocations
In practice, ~95 % of Tor traffic hitting a Shopify store comes through standard exit nodes — bridges are a marginal case.
Blocking Tor without breaking your store
A few precautions:
Whitelist your team. If you use Tor for security research, add your team's exit-node patterns to the whitelist before flipping the switch.
Set the action to "Block", not "Challenge". A captcha challenge does not stop Tor — fraudsters solve them with cheap services. Hard block is the only effective action.
Pair with checkout-level rules. Some Tor users land on your store via a referrer that strips Tor, then complete checkout from a clean IP. Combine Tor blocking with VPN/Proxy detection for full coverage.
Do not redirect Tor traffic to your help page. Tor users do not need help — they need to be blocked. Redirects just waste your server cycles.
What you see in the dashboard
After enabling Tor blocking, Shieldy's Visitor Analytics logs every Tor visitor with:
- Exit-node IP and location
- Risk score (typically 0.9+)
- Page they attempted to access
- Whether checkout was attempted
This data is valuable on its own — many merchants do not realize how much Tor traffic they get until they enable the log.
Card-testing protection: a special case
Tor is the preferred infrastructure for card-testing operations — automated tools that submit stolen card numbers in tight loops. Defenses:
- Enable Auto block Tor in Shieldy.
- Set Auto-block order based on subtotal to flag orders under $5 (test pattern).
- Enable Auto-cancel high-risk order at threshold 0.7.
- In Shopify Payments → Settings → enable Manual capture so failed payments do not get charged.
Together these four settings eliminate ~95 % of card-testing without manual intervention.
How Tor blocking differs from VPN blocking
| Category | Block rate | False positive risk | Action |
|---|---|---|---|
| Tor exit nodes | Near-zero legitimate use | ~1 % | Hard block always |
| Commercial VPN | ~15-25 % legitimate use | 10-15 % | Block at checkout, allow browsing |
| Residential proxy | Mostly automated | 5-8 % | Hard block at checkout |
| Datacenter IPs | ~80 % bot | 8-12 % | Block at checkout |
Tor sits at the safest end of the spectrum — almost no downside to blocking.
What if I want to allow some Tor traffic?
Edge case: stores that explicitly cater to privacy-conscious buyers (VPN-friendly digital goods, security tools). For these:
- Block Tor at storefront level.
- Allow Tor only at the
/accountand/cartpaths. - Require Shop Pay or Apple Pay for Tor checkouts (digital signatures reduce fraud).
Shieldy supports path-level rules in the Enterprise plan.
Frequently asked questions
Will blocking Tor affect my SEO?
No. Search engine crawlers (Googlebot, Bingbot) do not use Tor.
Can I block Tor for free?
The Free and Premium plans focus on IP/country and VPN blocking. Tor blocking is in the Enterprise plan at $8.99/month. For stores with frequent Tor traffic this typically pays for itself in the first prevented chargeback.
How accurate is Tor detection?
The public Tor exit-node list is comprehensive and updated continuously. Shieldy's database has ~99.5 % coverage with <0.5 % false positives.
Does Tor blocking slow my store?
No. The check runs at Shopify's edge with <200 ms response.
What about Tor over a VPN?
Same network fingerprint — caught by Tor detection. The VPN layer hides the user from their ISP but the Tor protocol is still visible to your store.
Will Tor users see an error page?
Yes, with your custom message. Or you can configure a silent 403 if you do not want to acknowledge the block.
Wrapping up
Tor blocking is one of the simplest, safest, and highest-impact fraud controls available to Shopify merchants. If you process more than a handful of fraud orders a month, Tor blocking is the first thing to turn on.
Install Shieldy free on the Shopify App Store → · See plans →
Protect your Shopify store today
Install Shieldy free — block fraud, bots, and VPNs in under 5 minutes.
Install on Shopify — Free


