<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>Posts on Block Bad Bot</title><link>https://blockbadbot.com/posts/</link><description>Recent content in Posts on Block Bad Bot</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Mon, 14 Sep 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://blockbadbot.com/posts/index.xml" rel="self" type="application/rss+xml"/><item><title>Singapore Bot Traffic: Why a Country Block Isn't Enough</title><link>https://blockbadbot.com/posts/singapore-bot-traffic-country-block-isnt-enough/</link><pubDate>Mon, 14 Sep 2026 00:00:00 +0000</pubDate><guid>https://blockbadbot.com/posts/singapore-bot-traffic-country-block-isnt-enough/</guid><description>&lt;p&gt;Search &amp;ldquo;Singapore bot traffic&amp;rdquo; and you&amp;rsquo;ll land on a &lt;a href="https://support.google.com/analytics/thread/413401406/massive-traffic-spike-from-singapore-600-real-time-users-in-ga4-ghost-spam-or-bot-attack?hl=en"&gt;Google Analytics community thread&lt;/a&gt; that&amp;rsquo;s become a rite of passage: a site owner watching GA4&amp;rsquo;s real-time report fill up with hundreds of &amp;ldquo;users&amp;rdquo; from Singapore, out of nowhere, and asking the two questions everyone asks next — is this ghost spam, or an actual bot attack, and either way, how do I make it stop?&lt;/p&gt;
&lt;p&gt;That distinction matters more than it looks. &lt;strong&gt;Ghost spam&lt;/strong&gt; never touches your site at all — it&amp;rsquo;s a fake hit fired straight at your GA measurement ID, so your real server or CDN logs show nothing unusual, and no firewall rule will fix it (you need a GA-side hostname filter instead). &lt;strong&gt;Real bot traffic&lt;/strong&gt; actually requests your pages, which means it shows up in your own logs too — and that&amp;rsquo;s the case a firewall can do something about.&lt;/p&gt;</description></item><item><title>Why a 200 OK Beats a 403 for Blocking Bots</title><link>https://blockbadbot.com/posts/why-a-200-beats-a-403/</link><pubDate>Mon, 14 Sep 2026 00:00:00 +0000</pubDate><guid>https://blockbadbot.com/posts/why-a-200-beats-a-403/</guid><description>&lt;p&gt;Most WordPress security plugins handle bad bot traffic the same way: detect it, then slam the door with a &lt;code&gt;403 Forbidden&lt;/code&gt;.&lt;/p&gt;
&lt;p&gt;That feels like the right move, but it has two problems.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;It tells the bot operator they&amp;rsquo;ve been caught.&lt;/strong&gt; A &lt;code&gt;403&lt;/code&gt; is an unambiguous signal — &amp;ldquo;this fingerprint is blocked.&amp;rdquo; A scraper running at any scale reacts to that signal: rotate the User-Agent, rotate the IP, try again. The block becomes a game of whack-a-mole instead of a fix.&lt;/p&gt;</description></item></channel></rss>