Skip to content

Whitelist & Blacklist Rules

A rule is made up of three parts:

  1. Conditions – What to check (IP, country, region, ISP, user agent, referral URL).
  2. Scope – Where to apply (Global, URL-specific).
  3. Action – What happens if the conditions match (Allow, Block, Redirect).

Whitelist and Blacklist rules allow you to control who can access your Shopify store by defining trusted or restricted visitors based on conditions such as IP address, country, email, phone number, or other customer information.


A Blacklist rule blocks or restricts visitors who match the conditions you configure.

Visitors that do not match the rule can continue browsing your store normally.

  • Add 192.168.1.1 to the Blacklist → Only visitors using this IP address will be blocked.
  • Block a specific email address → Customers using that email will not be able to access your store.

Use Blacklist rules to prevent known fraudulent visitors, abusive users, or unwanted traffic from reaching your storefront.


A Whitelist rule explicitly allows trusted visitors to access your store.

Visitors who match a Whitelist rule bypass other protection rules and are always allowed to continue.

  • Add [email protected] to the Whitelist → This customer will always be allowed to access your store, even if other protection rules would normally block them.

Whitelist rules are recommended for:

  • Trusted customers
  • Business partners
  • Internal team members
  • Testing accounts

If you have any questions, feel free to contact us via Crisp Chat or email us at [email protected].