Help · Bot Wars
Checkout bots and the hold
“I have a bad feeling about this.”
The checkout is where a bot does the most harm, because it walks out with your store’s own records behind it. This chapter covers the built-in segment that finds checkout bots, and the hold that keeps your marketing away from them.
How a checkout bot gets in
A bot fills in your checkout with an address, ticks the box to get your email, and leaves without paying. Your Shopify store reports the checkout and the consent, as it should, so the profile arrives with a verified identity and consent on. On paper it is a new customer who wants your news.
That is why a checkout bot gets past the two checks that stop most other bots: it is confirmed, because your store reported it, and it is subscribed, because it ticked the box. The bot check is the third question, and the one it fails.
What gives it away is the checkout itself. A bot skips the shopping and goes straight for the checkout, and your store’s own record of the checkout shows signs a machine made it. We learned those signs from real bot traffic and keep them private, so the bots cannot learn to avoid them. Telling a person from a bot lists every other fact the check reads, and what is never a sign: your storefront not seeing somebody who declined its cookies, one of Shopify’s own buy-now links, or an address filled in quickly.
A checkout only counts against somebody new to you. Anybody whose consent or verified identity your store already had before that checkout is never held because of it, so a stranger who types one of your customers’ addresses into a checkout cannot get that customer held.
“It’s a trap!”
The Checkout bots segment
Checkout bots is a built-in segment holding everybody the bot check describes right now. It is counted every time you open it, and a person leaves it the moment something lets them through. Your store has it already, and you never have to add it.
Open Audience → Segments to see who is in it. If your store was set up before it existed, it appears there the first time anybody on your team opens the segments screen; the hold does not wait for that.
Checkouts from before the app began keeping these details carry no signs, so nobody is held on one of those. The segment fills from your newer checkouts on.
Its rule is the app’s own, so you cannot edit, rename, label, copy or delete it, use it under Send to or Exclude in a campaign, or add its people to a list. You can act on the people in it: export them from its own page, and delete them from Settings → Delete profiles, which Deleting bots for good explains.
“Red alert. Shields up!”
Shields up: what the hold stops
Nobody in Checkout bots gets a marketing email or text from you. Every campaign and every automation message checks at the moment of sending, so you never have to exclude them anywhere. In an automation, the message is skipped and the person carries on to the next step.

It applies in every store, always, and there is no setting for it. A marketing email to a bot only ever harms the store that sends it, so there is nothing to switch.
Even a test you send to one of these profiles is refused, so a test shows exactly what a real send would do.
Nothing held is sent later. When a person is let through, your next campaign or automation message reaches them like anybody else’s, as their consent allows; the ones they missed stay missed. Somebody let through while a campaign is still sending may miss that campaign and get the next.
A campaign’s audience count still includes them. The count is who your rule describes; the hold applies at the moment of sending, the same way consent is checked again then.
What the hold never stops
The hold is about marketing only. Order updates, back-in-stock notices, the six-digit code somebody signing up with their phone number is sent, and your replies to a text somebody sends you are never held.
A back-in-stock notice answers a request the person made themselves, behind its own check that a person pressed Notify. A test sent to a team member is never held either, because a team member is not a profile.
Where you see it
Every message the hold stops is recorded, never silently dropped. On a campaign’s report it is under Not sent, by reason, in the group Protecting your sending, as Held as a checkout bot. An automation’s report counts it among the reasons a message was not sent, under the same name, and when you check one person’s path through an automation, the step reads Not sent: held as a checkout bot.
Open Analytics → Not sent to see every one, across every campaign and automation, with the people behind each.
A held person who also has no consent, or whom you paused, is recorded under that reason instead, because it is the first one the checks meet.
The sign-up check came first
Automations that start when somebody signs up had a bot check before the hold existed, and still do. A sign-up that looks like a bot is turned away at the start, so the welcome never begins.
A Shopify sign-up waits for the check only until your store’s report of the checkout arrives: almost always seconds, and never more than 5 minutes. A Shopify sign-up with no checkout at all, such as a new account in your store, waits the full 5 minutes, in case a checkout report is on its way.
The built-in segments Waiting for the bot check and Turned away as not a person show that check at work, and the What starts an automation page explains it. The hold reaches everything else: campaigns, and every automation whatever starts it, including ones you imported from another tool.
Checkout bots and Suspected bots
Suspected bots is another built-in segment, with a different job. It finds records with no Shopify tags, no email consent, any checkout and no order, and it is yours to clone and exclude from a campaign. Checkout bots needs a checkout with the signs of a bot, box ticked or not, and it is the one the hold reads.
The two overlap a great deal. A bot that never ticked the box is usually in both; a bot that did is in Checkout bots alone. A real shopper who never ticked the box and never bought can be in Suspected bots, which only asks for a checkout, and that is why it is a segment for you to review rather than a hold. Nobody who has bought from your Shopify store is ever in Checkout bots, whether your store reported the order or you imported it from another tool. The Segments page explains Suspected bots in full.