What is the __cf_bm cookie?
__cf_bm is an HTTP cookie generated by Cloudflare, the CDN, DNS and anti-DDoS provider used by a very large number of websites, including many Romanian ones. It is part of Cloudflare's Bot Management component.
The cookie appears automatically on any site that runs through the Cloudflare network, regardless of whether the site owner has explicitly added any Cloudflare script — it is set at the infrastructure level, typically on the first request to the domain.
What data it stores
The value of __cf_bm is an encrypted string generated and interpreted exclusively by Cloudflare's systems; its exact contents are not publicly documented and can vary between implementations. Broadly, it stores a behavioural score/signal used to assess whether a request comes from a bot.
The data is sent to Cloudflare's infrastructure (not to the website itself) and is used in real time for traffic-filtering decisions.
What it is used for
The cookie's purpose is to protect the website against bots, aggressive scraping and automated attacks by analysing visitor behaviour patterns. For the site owner, this reduces unwanted traffic and server load; for Cloudflare, it's part of the security service offered to its customers.
Does it require consent?
CookieFix classifies __cf_bm under preferences/functional, since it is not strictly necessary in the narrow ePrivacy sense (it is not indispensable for delivering the service the user explicitly requested). Under GDPR and the local ePrivacy transposition, prior consent is recommended before setting it, if the site uses Cloudflare features that trigger this cookie beyond baseline security protection.
- The site owner should list it in the cookie policy, with the provider (Cloudflare) and duration (approx. 30 minutes).
- If the site relies on Cloudflare modules that are not indispensable to service delivery, it's advisable to treat this cookie as requiring consent rather than assuming an automatic exemption.
How to block or delete __cf_bm
A visitor can delete or block the cookie manually from browser settings (Chrome, Firefox, Edge, Safari — per-site cookie management), though blocking it may affect access if the site relies on active Cloudflare bot protection.
For site owners who need to respect prior-consent requirements, a CMP platform like CookieFix can automatically block the scripts that trigger __cf_bm until the visitor gives consent for the preferences/functional category.
Frequently asked questions
No, it's a security cookie used by Cloudflare to detect bots and automated traffic, not to track browsing behaviour for marketing purposes.
Its typical duration is around 30 minutes, after which it expires automatically.
Generally yes, since it is not strictly necessary in the narrow ePrivacy sense; CookieFix classifies it as preferences/functional, so prior consent is recommended.
Because it's set automatically by Cloudflare's infrastructure when the site uses their CDN, DNS or protection services, not by code manually added by the site owner.