Features Pricing GDPR cookie banner Google Consent Mode v2 WordPress plugin Cookiebot alternative For Agencies GDPR ePrivacy About Contact
RO | EN
Start Free →
Preferences

__cf_bm Cookie (Cloudflare) – What It Is and What It Does

__cf_bm is a cookie set by Cloudflare as part of its Bot Management system, used to distinguish human visitors from bots and automated traffic. It is not strictly necessary in the technical sense for the website to function, so CookieFix classifies it under preferences/functional.

Name
__cf_bm
Provider
Cloudflare
Category
Preferences
Type
HTTP cookie
Lifetime
30 minutes
Consent
Yes, before it is set (GDPR / ePrivacy)
Prevalence
found on 3 Romanian sites scanned by CookieFix

What is the __cf_bm cookie?

__cf_bm is an HTTP cookie generated by Cloudflare, the CDN, DNS and anti-DDoS provider used by a very large number of websites, including many Romanian ones. It is part of Cloudflare's Bot Management component.

The cookie appears automatically on any site that runs through the Cloudflare network, regardless of whether the site owner has explicitly added any Cloudflare script — it is set at the infrastructure level, typically on the first request to the domain.

What data it stores

The value of __cf_bm is an encrypted string generated and interpreted exclusively by Cloudflare's systems; its exact contents are not publicly documented and can vary between implementations. Broadly, it stores a behavioural score/signal used to assess whether a request comes from a bot.

The data is sent to Cloudflare's infrastructure (not to the website itself) and is used in real time for traffic-filtering decisions.

What it is used for

The cookie's purpose is to protect the website against bots, aggressive scraping and automated attacks by analysing visitor behaviour patterns. For the site owner, this reduces unwanted traffic and server load; for Cloudflare, it's part of the security service offered to its customers.

Does it require consent?

CookieFix classifies __cf_bm under preferences/functional, since it is not strictly necessary in the narrow ePrivacy sense (it is not indispensable for delivering the service the user explicitly requested). Under GDPR and the local ePrivacy transposition, prior consent is recommended before setting it, if the site uses Cloudflare features that trigger this cookie beyond baseline security protection.

  • The site owner should list it in the cookie policy, with the provider (Cloudflare) and duration (approx. 30 minutes).
  • If the site relies on Cloudflare modules that are not indispensable to service delivery, it's advisable to treat this cookie as requiring consent rather than assuming an automatic exemption.

How to block or delete __cf_bm

A visitor can delete or block the cookie manually from browser settings (Chrome, Firefox, Edge, Safari — per-site cookie management), though blocking it may affect access if the site relies on active Cloudflare bot protection.

For site owners who need to respect prior-consent requirements, a CMP platform like CookieFix can automatically block the scripts that trigger __cf_bm until the visitor gives consent for the preferences/functional category.

Frequently asked questions

No, it's a security cookie used by Cloudflare to detect bots and automated traffic, not to track browsing behaviour for marketing purposes.

Its typical duration is around 30 minutes, after which it expires automatically.

Generally yes, since it is not strictly necessary in the narrow ePrivacy sense; CookieFix classifies it as preferences/functional, so prior consent is recommended.

Because it's set automatically by Cloudflare's infrastructure when the site uses their CDN, DNS or protection services, not by code manually added by the site owner.

Updated 7 September 2026 · Information comes from the provider’s public documentation and CookieFix scans; it is not legal advice.