Decide who can reach your store, before they see a single product.Country, IP and bot blocking for Shopify
Zonify checks every visitor on every page. Block the countries you do not ship to — or allow only the ones you do. Stop a specific address. Keep Google in and scrapers out. Every visit that was turned away shows up in your admin with the reason.
Free to install · No code · Nothing is blocked until you say so
Store not available
Sorry, this store is not available in your country.
The problem
Every visitor you cannot serve still costs you something.
A checkout from a country you do not ship to.
The customer pays. You cannot deliver. Now there is a refund, a support ticket, a chargeback risk, and one more person who thinks your store is broken.
Scrapers copying your catalogue, prices, and images.
They look like visitors in your analytics. They never buy. And a competitor's crawler reading every product page you have is not something your theme can stop.
Shopify Markets tells the world where you sell. It does not stop anyone from walking in anyway.
Zonify is the door. Markets is the sign on it.
Comparison
A theme hack redirects. Zonify decides.
Most stores that block a country do it with a snippet pasted into the theme. It works until the theme updates, it knows nothing about IPs or bots, and it leaves no record of who it turned away.
Zonify
Block one country
Pick it from a list.
Allow only the countries you ship to
Add them to the allow list. Everywhere else is out.
Stop one troublesome IP address
Add it. Paste a whole list if you have one.
Keep Google, block a scraper
Search engines allowed by default. Scrapers blocked by default.
You block your own country by mistake (it happens)
Your own IP is on the allow list. It beats every other rule.
Who was blocked last week?
Every visit, with the country, the device, and the rule that stopped it.
A geo-redirect snippet
Block one country
Paste code into the theme.
Allow only the countries you ship to
Rewrite the snippet.
Stop one troublesome IP address
Cannot.
Keep Google, block a scraper
Cannot tell them apart.
You block your own country by mistake (it happens)
You are locked out with everyone else.
Who was blocked last week?
No record.
You should be able to see who was blocked and why — and let one address back in without touching code.
How it works
Live on your storefront in three steps
None of them need a developer, and nothing is blocked until the last one.
- 1
Install
One click from the Shopify App Store. The app asks for no permissions to your orders, products or customers — it does not need them.
- 2
Switch on the app embed
In your theme editor, turn on the Zonify app embed. That is the only change to your theme, and it is one toggle.
- 3
Add your own address, then your rules
Zonify shows you your IP and offers to allow it first, so a rule can never lock you out. Then block a country, allow a few, or stop an address.
From then on every page load asks Zonify first. Allowed visitors notice nothing. Blocked visitors see your message, or go where you send them.
Features
Everything the app does today.
Each of these is built and running. Country rules, IP rules, the bot list, content protection, and the visit log are all in the app now.
Block countries — or allow only some
Pick from 243 countries. Block the ones you choose, or flip it: allow a short list and everywhere else is out. Each rule can have its own redirect.
Block or allow IP addresses
IPv4 and IPv6. Add one, or paste a whole list from a spreadsheet or a server log. An allowed address beats every other rule, so you can never lock yourself out.
Bots sorted for you
Google, Bing and link previews are allowed by default, because blocking them takes you out of search. Scrapers and SEO crawlers are blocked. Change any of it with one click.
Content protection
Stop right-click, image dragging and copying on your storefront. Checkout fields stay usable, and pasting a discount code still works.
Your message, or your redirect
Blocked visitors see the message you wrote, or go to a page you choose. Per country, per address, or one setting for the whole store.
See every visit that was turned away
Country, device, browser, address, and the exact rule that stopped it. Export it as a spreadsheet. Tell a real block from a mistake in one look.
The rules
Four rules, checked in this order. The order is the point.
Every page load runs the same four checks. The first one that decides, decides — which is why your own address is checked before anything else.
Your allowed IPs win, always
An address on the IP allow list gets in no matter what the other rules say. This is your way back in if you ever block your own country by mistake.
Then the country
Blocked country? Out. Allow list with this country missing? Out. Country unknown? Let through — a visitor with a privacy setting is not caught by a rule aimed at someone else.
Then the IP address
Same idea, for addresses. Unknown address? Let through, for the same reason.
Then the bots
Matched against the user agent on every request — not against what the visitor claims to be. A scraper that says it is not a bot is still a scraper.
One allow-list entry flips that check from “block these” to “block everyone except these”. The admin says so on the page where you add it, because it is a big consequence for a small action.
FAQ
Questions merchants actually ask.
How does it know which country a visitor is in?
From the visitor's browser: its time zone first, then its language. That is a good guess for almost everyone and a wrong one for anybody using a VPN or a changed time zone. Country blocking is a shipping-policy tool — it keeps out people you cannot serve. It is not a security control, and we will not tell you it is.
Can I lock myself out?
Not if you follow the first step. Zonify shows you your own IP address and offers to add it to the allow list before you block anything. An allowed IP beats every other rule, so your own store is always open to you.
What happens if Zonify is down?
Your store stays open. The script fails open on purpose: if it cannot reach the app, it does nothing. An outage in this app must never become an outage in your shop.
Will it block Google?
No. Search engines and link-preview bots are allowed by default, because blocking them removes you from search and turns shared links into blank cards. You can change that, but you have to choose to.
What permissions does it ask for?
None to your orders, products or customers. The app does not need them and does not ask. It reads your store's name and domain, which every app can.
Does it slow my store down?
One small script, under 10 KB, and one request per page to check the visitor. There are no third-party lookups — the old approach of asking an outside service for each visitor's IP is exactly what this app does not do.
What does it store about my visitors?
The country, the IP address, the device and browser, the page, and whether they were blocked and why — for your own analytics. No names, no emails, no orders. Uninstalling deletes the visit log; Shopify's shop/redact request deletes everything.
Do I need a developer?
No. Install, switch on the app embed in your theme, add your rules.
Stop serving visitors you cannot serve.
Add to Shopify — FreeFree to install · No permissions to your data · Your store stays open if we go down