- Job title
- QA Tester
- Sector
- Freight
- Organization type
- 300-person organization
- Joined
- Aug 2025
- Message
- 143
Doki · KVKK compliance consulting · 2023
We run an e-commerce site offering a B2B spare parts catalog. We get around 4,000 unique visitors and roughly 25,000 pageviews a day. Over the last two months, our server costs skyrocketed from 4,500 TL to 11,000 TL. When we checked the logs, we noticed suspicious bots constantly scraping product prices and stock levels. As a fix, we set up honeypot traps using CSS-hidden fake links in our contact form and at the bottom of the page.
During a three-week test, we logged 1,400 distinct IP addresses that clicked these hidden links or filled out the form. Looking at the list, though, it seems some corporate proxy IPs, company security scanners, and even search engine cache bots fell into the trap too.
We're worried that if we trust these honeypot logs and block the IPs outright at the firewall, we might lose actual customers or hurt our SEO visibility. What is the proper way to filter this captured bot traffic, weed out the actual threats, and take safe action?