FraudToad help

Getting started

FraudToad watches every new order for card testing: someone running stolen cards through cheap orders to find the ones that work. It links orders that share a card, IP address, email, account or browser, and stops them before any money is taken.

1. Turn on manual capture

In your Shopify admin, go to Settings › Payments › Payment capture method and choose Manually. A card payment is then only authorized at checkout, so the app can void it before it's charged. A voided card test leaves no sale, no refund, no card fees and no chargeback.

With automatic capture the app can still cancel fraud, but only by refunding it, and the card fees aren't returned. The review queue shows a red note while your recent orders are captured automatically.

2. Start in shadow mode

The app starts in shadow mode (Settings › Strongest automatic action › "Hold for review, and show what would have been cancelled"). It scores every order but never cancels anything. Orders it would cancel or block are put on a fulfillment hold, tagged fraud-review and fraud-shadow-cancel or fraud-shadow-block, and listed in the review queue for you to approve or reject. Observe mode goes further: it scores orders and changes nothing in Shopify.

Use Test on past orders to see what the app would have done with your last 60 days of orders, and the Dashboard to see what it has flagged since you installed it.

3. Switch to enforce mode when you trust it

In Settings › Strongest automatic action, pick one of the enforce options once shadow mode's holds match what you'd have done. With "Cancel, void, and block", orders are handled by score:

ScoreWhat happens
Under 30Allowed. Payment is captured 2 hours later, after the order is checked again, so a burst that shows up in the meantime can still be voided.
30 to 59Held for review: fulfillment hold, fraud-review tag, not captured.
60 to 79Cancelled and voided, tagged fraud-cancelled.
80 or moreCancelled and voided, and its card, IP, email and customer go on the blocklist for 30 days. Earlier uncaptured orders that share them are swept (cancelled too).

"Hold for review only" or "Cancel and void the payment" stop short of that, so nothing goes further without you. Settings › Sensitivity moves the score thresholds (Conservative, Balanced, Strict, or your own).

4. Review held orders

A held order waits in the review queue. Approve and capture releases the hold and takes payment. Cancel and void cancels it without charging the card, and Cancel and block also blocklists it. A hold nobody reviews within 48 hours is settled for you: by default, tiny orders and orders scoring 45 or more are cancelled and the rest are released and captured. You can change that in Settings › Holds.

Running a sale?

A rush of cheap first orders looks like a botnet. Turn on sale mode in Settings before a planned sale so attack mode stays off. The card, IP and email rules keep running, so a card tester hitting your sale is still caught.

Support

Use the contact details on the app's Shopify App Store listing. Include your store's address (yourstore.myshopify.com) and the order number if it's about an order.