What each rule means
Every order gets points from each rule it matches. The total is its score (capped at 100), and the score decides what happens (see Getting started). A hard block cancels the order whatever its score. The order's details in the review queue list every rule that fired and why. Points and thresholds below are the defaults; you can change them in Settings.
C1Card used by several accounts
- When
- The same card paid for orders from 3 or more different accounts (customers or emails) within an hour. During attack mode, 2 is enough.
- Why it matters
- Card testers try one stolen card under a fresh account each time. Real people rarely share a card across accounts in an hour.
- Can catch
- A family or office sharing one card, each with their own account.
- Points
- +60
C1bCard used by many accounts in a day
- When
- The same card on 5 or more accounts within 24 hours.
- Why it matters
- This is the pattern of a slow card tester who spaces orders out to avoid a burst.
- Can catch
- Very rare. It's a hard block: the order is cancelled whatever its score.
- Points
- +80, hard block
C2Card on many orders
- When
- The same card on 4 or more orders in an hour, or 8 or more in 24 hours.
- Why it matters
- Testing many small charges on one card to find one that goes through.
- Can catch
- A customer placing several separate orders in a day, such as a reseller or someone fixing a mistake.
- Points
- +40
C3Tiny order
- When
- The order total is 2.00 or less, or under 10% of your usual order value, whichever is larger.
- Why it matters
- Card testers buy the cheapest thing in the store to check a card works.
- Can catch
- Every cheap order gets this. On its own it never holds an order; it only adds up with other signals.
- Points
- +15
C4Card already on a tiny order
- When
- This is a tiny order, and the same card was on another tiny order within 24 hours.
- Why it matters
- A tester checking the same card again, or several testers sharing a list.
- Can catch
- A customer buying two cheap items in separate orders.
- Points
- +20
E1Many cards from one BIN on tiny orders
- When
- 5 or more different cards starting with the same 6 digits (the BIN, which identifies the bank) on tiny orders within an hour.
- Why it matters
- Stolen cards are often sold in batches from one bank, so a list of them shares a BIN.
- Can catch
- A popular bank's BIN during a sale. A BIN that was on 5% or more of your orders in the week before is skipped once you have 50 orders that week.
- Points
- +40
E2IP used by several accounts or cards
- When
- 3 or more accounts, or 3 or more cards, from the same IP address within an hour.
- Why it matters
- One machine running through a list of cards and accounts.
- Can catch
- An office, school or mobile network where many people share one IP.
- Points
- +35
E3Brand-new account
- When
- The customer account was created less than 30 minutes before this, its first order.
- Why it matters
- Testers make a throwaway account for each card.
- Can catch
- Every genuine new customer who signs up at checkout. Worth little on its own.
- Points
- +10
E4Disposable or numbered email
- When
- The email is on a disposable-email domain, or 3 or more emails that differ only by numbers or dots (pat1@, pat2@…) ordered within 24 hours.
- Why it matters
- Throwaway and generated addresses are how testers make accounts quickly.
- Can catch
- Someone who uses plus or numbered addresses on purpose.
- Points
- +15
E5Same browser on several accounts
- When
- The same browser fingerprint on tiny orders from 3 or more accounts within an hour.
- Why it matters
- One bot posing as several shoppers.
- Can catch
- A very common phone and browser. Like E1, one that was on 5% or more of last week's orders is skipped.
- Points
- +15
E6CVV or AVS mismatch
- When
- The card's security code (CVV) didn't match, or the billing address (AVS) didn't match what the bank has.
- Why it matters
- Someone who has the card number but not the rest of the card details.
- Can catch
- A typo, or an address the bank has in a different format.
- Points
- +25 CVV, +10 AVS
E7Shopify's risk recommendation
- When
- Shopify's own fraud analysis recommended cancelling or investigating the order.
- Why it matters
- Shopify sees signals across all stores that this app doesn't.
- Can catch
- Shopify's analysis has its own false positives.
- Points
- +40 cancel, +15 investigate
E8Billing and shipping countries differ
- When
- The billing country and shipping country are different.
- Why it matters
- Stolen cards are often shipped to an address far from the cardholder.
- Can catch
- Gifts sent abroad, and people living away from home.
- Points
- +10
E9IP is TOR, a VPN or a datacenter
- When
- The order came from a TOR exit node, a known VPN provider, or a hosting or datacenter network rather than a home or mobile connection. The lists are free public ones, refreshed daily, and cover IPv4 addresses only.
- Why it matters
- Card-testing bots run on rented servers and hide behind proxies; real shoppers mostly use home broadband or a phone.
- Can catch
- Privacy-minded shoppers on a VPN, and some office networks. iCloud Private Relay is not counted. Kept low so it never holds an order on its own.
- Points
- +10 TOR, +5 VPN, +10 datacenter
A1Attack mode
- When
- More than 5 tiny orders in 15 minutes, and at least 5 times your usual rate. For the next 2 hours every tiny order gets extra points, C1 needs fewer accounts, and you get an alert. Tiny orders placed in the 15 minutes before the surge count too when they're checked again before payment is taken.
- Why it matters
- A botnet spreads an attack over many cards, IPs and accounts so no single order looks linked. The surge is what gives it away.
- Can catch
- A sale or a viral post bringing in a rush of cheap first orders. Turn on sale mode in Settings before a planned sale.
- Points
- +30 to tiny orders
BLOCKLISTOn the blocklist
- When
- The card, IP, email, customer, phone or address is on your blocklist. An address only holds the order; the rest cancel it.
- Why it matters
- An earlier order was blocked, or you added it yourself.
- Can catch
- A shared IP from a blocked order. See the blocklist guide for how to remove an entry.
- Points
- hard block (address: hold)
SWEEPSwept
- When
- An order placed earlier was cancelled after a later order was blocked, because they share a card, IP, email or account.
- Why it matters
- The first orders of an attack often look clean until the pattern shows up. Uncaptured ones can still be voided.
- Can catch
- An earlier order that shared only a busy IP.
- Points
- cancel
Other labels
IGNORED | Not scored: a point-of-sale or draft order, a $0 order, an order paid without a card (cash, bank transfer, gift card…), or one matching a tag or sales channel you chose to ignore in Settings. |
HOLD_EXPIRED | Nobody reviewed the hold within 48 hours, so it was cancelled or released (Settings › Holds). |
| Allowlisted | A known-good customer, card or email. It's still scored, but never cancelled: at most held for you. |
Support
Use the contact details on the app's Shopify App Store listing. Include your store's address (yourstore.myshopify.com) and the order number if it's about an order.