All field guidesTraffic classification · Protect demand

Unknown traffic surged after a CDN change. Do not label it as Bot yet

Human traffic appears stable, but the Unknown share rises immediately after cache or reverse-proxy settings are changed.

Updated 2026-08-16 · 6 min read
Written for
WordPress technical lead
Article format
Cause diagnosis
Take-away
evidence-led diagnostic table

Start with the symptom

Human traffic appears stable, but the Unknown share rises immediately after cache or reverse-proxy settings are changed.

Start with the symptom for “Unknown traffic surged after a CDN change. Do not label it as Bot yet”: Human traffic appears stable, but the Unknown share rises immediately after cache or reverse-proxy settings are changed. You must identify the real request path before a limit, webhook, or retry policy can be trusted.

List competing causes for “Unknown traffic surged after a CDN change. Do not label it as Bot yet”: A safe rollout needs evidence, reversible changes, and a recovery path that does not erase the incident.

List competing causes

Collect discriminating evidence for this case: Verify the request path and any lost identification signals before changing policy; Unknown means insufficient evidence, not proven abuse.

Test in the safest order for “Unknown traffic surged after a CDN change. Do not label it as Bot yet”: identify the evidence that would make this proposed action unsafe—Verify the request path and any lost identification signals before changing policy; Unknown means insufficient evidence, not proven abuse.

  • Evidence 1 for “Unknown traffic surged after a CDN change. Do not label it as Bot yet”: Human/Bot/Unknown share
  • Evidence 2 for “Unknown traffic surged after a CDN change. Do not label it as Bot yet”: requested path
  • Evidence 3 for “Unknown traffic surged after a CDN change. Do not label it as Bot yet”: repetition and velocity
  • Evidence 4 for “Unknown traffic surged after a CDN change. Do not label it as Bot yet”: orders and qualified inquiries

Collect discriminating evidence

Record the finding for this exact problem: the acceptable end state must resolve the original condition—Human traffic appears stable, but the Unknown share rises immediately after cache or reverse-proxy settings are changed.

evidence-led diagnostic table decision for “Unknown traffic surged after a CDN change. Do not label it as Bot yet”: Verify the request path and any lost identification signals before changing policy; Unknown means insufficient evidence, not proven abuse.

Test in the safest order

Build the evidence-led diagnostic table for “Unknown traffic surged after a CDN change. Do not label it as Bot yet.” List at least two competing causes. For each, name one observation that would support it and one that would rule it out. Test the least disruptive distinction first.

Record the finding

If “Unknown traffic surged after a CDN change. Do not label it as Bot yet” showed why a blunt stop can reject real demand, do not answer it with another blunt rule. Download the free plugin to establish a baseline, then use Pro Smart Protection when Human, Bot, Unknown, and revenue signals must shape control.

Next field guideHow much Bot traffic is too much? A single percentage cannot answer