Hello, over the past couple of weeks, we’ve noticed a huge and unusual spike in traffic on our HubSpot site. Normally, our daily page views are in the range of 500–1,000 per day, but suddenly this jumped to nearly 13,000 per day.
Looking at the analytics, the majority of this traffic is coming from China (over 59k sessions in the last 30 days), which is not typical for us since we rarely had traffic from that region before. The targeted pages were our tutors listing page and some tutor profile pages (all populated from HubDB). We are getting similar results on our Google Analystics.
We have since unpublished those pages, but the traffic has now shifted to the 404 error page. It’s worth noting that the tutors pages were always set with noindex headers, so they shouldn’t have been appearing in search results.
We already have bot filtering enabled in HubSpot and all relevant settings turned on, but clearly this isn’t catching everything. On other subdomains (hosted outside of HubSpot).
At this point, we’re looking for advice on:
Better bot filtering in HubSpot – is there anything beyond the built-in options?
Country-level blocking or filtering (especially for China, in this case).
Integrations or workarounds that might allow something like Cloudflare protections on HubSpot-hosted content.
Has anyone dealt with a similar spike, especially with traffic concentrated in one unexpected country?
The built-in options focus on analytics filtering (bot filtering and excluding IPs/referrers). HubSpot doesn’t offer native country-level blocking.
You can block abusive IP(s) by adding them under IP Addresses to Exclude on Advance tracking page (same as bot filtering). This removes their visits/submissions from analytics (it does not block access). Exclude traffic from your site analytics
With Cloudflare Enterprise: Implement geo-blocking with Cloudflare WAF for your HubSpot domain, and create a rule to block the target country.
If this helps, feel free to mark it as the solution and give it an upvote !
Hello @Jigar_Thakker, thanks for sharing the resources about reverse proxies — that’s good to know.
Unfortunately, I don’t have Cloudflare Enterprise, so I won’t be able to implement firewall/WAF rules. Unless I’m missing something in Cloudflare, I don’t see this as possible even with a Pro account.