I want to make it so that my friend from England has access to my website, but I want only him to have access without being blocked by the rules I will show in the picture below.
yes, they should type their email, for them to receive the code in their inbox so that it can verify that the user owns that email, that way it can only let your friend access the site, verifying your friend's email
You have to make them request access by turning on the justification.
How did you make the bypass policy
It isn't possible to have bots bypass access. If you just want to allow based on IPs and no sign in then just make a WAF rule that allows the IPs you want and known bots
Facebook has a range of IP addresses. You can block Facebook IP address ranges to stop people on your local network from accessing the social media giant.