Bypassing bot protection for Lemwatch checks

Configure bot-management platforms (Cloudflare, DataDome, PerimeterX, Akamai) so Lemwatch checks succeed without weakening security.

Quick answer

Add Lemwatch's IP ranges and Lemwatch/1.0 User-Agent to your bot-management platform's allow-list. Every major vendor supports IP + UA rules; you do not need to disable protection globally.

What this fixes

Where to find it in Lemwatch

Copy IPs and UA from Settings → Monitoring → Probe IPs. All rule creation happens in the vendor dashboard.

How to configure each vendor

  1. Cloudflare: WAF → Custom Rules → Skip rule matching Lemwatch UA + IPs.
  2. DataDome: Management → Allowlist → add Lemwatch CIDRs and UA.
  3. PerimeterX / HUMAN: Console → Allowlist → IP + User-Agent entries.
  4. Akamai Bot Manager: Add Lemwatch IPs to the "Known Bots" allow category.
  5. Run Check now in Lemwatch to verify the real page loads.

FAQ

Won't attackers spoof the Lemwatch User-Agent?

Only if they also come from our published IPs — which are locked to our infrastructure.

Do I still need to whitelist the IPs at the firewall?

Yes — bot management and firewalls are separate layers. See IP whitelisting.

Related