What is the __cf_bm cookie?
Cloudflare bot-management cookie that distinguishes humans from automated traffic to protect the site. Classed as strictly necessary.
Strictly necessary No consent needed
| Cookie name | __cf_bm |
|---|---|
| Set by | Cloudflare |
| Category | Strictly necessary |
| Typical duration | 30 minutes |
| Domain | first-party |
| Consent required? | No — strictly necessary |
Does __cf_bm need consent?
No. __cf_bm is treated as strictly necessary — it exists so the site can function securely (sessions, security or fraud prevention), not to track you across the web. Strictly necessary cookies are exempt from the consent requirement under ePrivacy, so a site may set __cf_bm without asking first. It should still be listed in the site's cookie policy.
Is __cf_bm a tracking cookie?
Required for the site to work — sessions, security, load balancing, cart state. Exempt from consent under ePrivacy.
How to see and remove __cf_bm
- See it: open your browser's developer tools → Application (Chrome/Edge) or Storage (Firefox) → Cookies, and look for
__cf_bm. - Remove it: clear cookies for the site, or use your browser's "Clear browsing data" for cookies. It will reappear if you keep using the site and consent is in place.
- Stop it being set: decline non-essential cookies on the site's banner. On a compliant site, clicking "Reject all" prevents non-essential cookies (this one is necessary, so it may still appear).
Want to know which cookies your site sets — and whether any fire before consent? Scan it free and get the full list, categorised, with the ones that load too early flagged.
Fixing pre-consent cookies
If a scan shows tracking cookies loading before the visitor consents, the fix is a consent management platform (CMP) that blocks non-essential tags until the visitor agrees. Cookies.ie is our GDPR / ePrivacy CMP — EU-hosted, with a real one-click "Reject all" and consent logging. See the fix guide for pre-consent trackers.
Related cookies
cf_clearance— Cloudflare__stripe_mid— StripePHPSESSID— PHP (generic)JSESSIONID— Java / Jakarta (generic)
Cookie purposes and durations reflect vendor documentation and common consent databases as of 2026-06-25; a specific site may configure __cf_bm differently. This is general information, not legal advice.