FraudToad help

What each rule means

Every order gets points from each rule it matches. The total is its score (capped at 100), and the score decides what happens (see Getting started). A hard block cancels the order whatever its score. The order's details in the review queue list every rule that fired and why. Points and thresholds below are the defaults; you can change them in Settings.

C1Card used by several accounts

When
The same card paid for orders from 3 or more different accounts (customers or emails) within an hour. During attack mode, 2 is enough.
Why it matters
Card testers try one stolen card under a fresh account each time. Real people rarely share a card across accounts in an hour.
Can catch
A family or office sharing one card, each with their own account.
Points
+60

C1bCard used by many accounts in a day

When
The same card on 5 or more accounts within 24 hours.
Why it matters
This is the pattern of a slow card tester who spaces orders out to avoid a burst.
Can catch
Very rare. It's a hard block: the order is cancelled whatever its score.
Points
+80, hard block

C2Card on many orders

When
The same card on 4 or more orders in an hour, or 8 or more in 24 hours.
Why it matters
Testing many small charges on one card to find one that goes through.
Can catch
A customer placing several separate orders in a day, such as a reseller or someone fixing a mistake.
Points
+40

C3Tiny order

When
The order total is 2.00 or less, or under 10% of your usual order value, whichever is larger.
Why it matters
Card testers buy the cheapest thing in the store to check a card works.
Can catch
Every cheap order gets this. On its own it never holds an order; it only adds up with other signals.
Points
+15

C4Card already on a tiny order

When
This is a tiny order, and the same card was on another tiny order within 24 hours.
Why it matters
A tester checking the same card again, or several testers sharing a list.
Can catch
A customer buying two cheap items in separate orders.
Points
+20

E1Many cards from one BIN on tiny orders

When
5 or more different cards starting with the same 6 digits (the BIN, which identifies the bank) on tiny orders within an hour.
Why it matters
Stolen cards are often sold in batches from one bank, so a list of them shares a BIN.
Can catch
A popular bank's BIN during a sale. A BIN that was on 5% or more of your orders in the week before is skipped once you have 50 orders that week.
Points
+40

E2IP used by several accounts or cards

When
3 or more accounts, or 3 or more cards, from the same IP address within an hour.
Why it matters
One machine running through a list of cards and accounts.
Can catch
An office, school or mobile network where many people share one IP.
Points
+35

E3Brand-new account

When
The customer account was created less than 30 minutes before this, its first order.
Why it matters
Testers make a throwaway account for each card.
Can catch
Every genuine new customer who signs up at checkout. Worth little on its own.
Points
+10

E4Disposable or numbered email

When
The email is on a disposable-email domain, or 3 or more emails that differ only by numbers or dots (pat1@, pat2@…) ordered within 24 hours.
Why it matters
Throwaway and generated addresses are how testers make accounts quickly.
Can catch
Someone who uses plus or numbered addresses on purpose.
Points
+15

E5Same browser on several accounts

When
The same browser fingerprint on tiny orders from 3 or more accounts within an hour.
Why it matters
One bot posing as several shoppers.
Can catch
A very common phone and browser. Like E1, one that was on 5% or more of last week's orders is skipped.
Points
+15

E6CVV or AVS mismatch

When
The card's security code (CVV) didn't match, or the billing address (AVS) didn't match what the bank has.
Why it matters
Someone who has the card number but not the rest of the card details.
Can catch
A typo, or an address the bank has in a different format.
Points
+25 CVV, +10 AVS

E7Shopify's risk recommendation

When
Shopify's own fraud analysis recommended cancelling or investigating the order.
Why it matters
Shopify sees signals across all stores that this app doesn't.
Can catch
Shopify's analysis has its own false positives.
Points
+40 cancel, +15 investigate

E8Billing and shipping countries differ

When
The billing country and shipping country are different.
Why it matters
Stolen cards are often shipped to an address far from the cardholder.
Can catch
Gifts sent abroad, and people living away from home.
Points
+10

E9IP is TOR, a VPN or a datacenter

When
The order came from a TOR exit node, a known VPN provider, or a hosting or datacenter network rather than a home or mobile connection. The lists are free public ones, refreshed daily, and cover IPv4 addresses only.
Why it matters
Card-testing bots run on rented servers and hide behind proxies; real shoppers mostly use home broadband or a phone.
Can catch
Privacy-minded shoppers on a VPN, and some office networks. iCloud Private Relay is not counted. Kept low so it never holds an order on its own.
Points
+10 TOR, +5 VPN, +10 datacenter

A1Attack mode

When
More than 5 tiny orders in 15 minutes, and at least 5 times your usual rate. For the next 2 hours every tiny order gets extra points, C1 needs fewer accounts, and you get an alert. Tiny orders placed in the 15 minutes before the surge count too when they're checked again before payment is taken.
Why it matters
A botnet spreads an attack over many cards, IPs and accounts so no single order looks linked. The surge is what gives it away.
Can catch
A sale or a viral post bringing in a rush of cheap first orders. Turn on sale mode in Settings before a planned sale.
Points
+30 to tiny orders

BLOCKLISTOn the blocklist

When
The card, IP, email, customer, phone or address is on your blocklist. An address only holds the order; the rest cancel it.
Why it matters
An earlier order was blocked, or you added it yourself.
Can catch
A shared IP from a blocked order. See the blocklist guide for how to remove an entry.
Points
hard block (address: hold)

SWEEPSwept

When
An order placed earlier was cancelled after a later order was blocked, because they share a card, IP, email or account.
Why it matters
The first orders of an attack often look clean until the pattern shows up. Uncaptured ones can still be voided.
Can catch
An earlier order that shared only a busy IP.
Points
cancel

Other labels

IGNOREDNot scored: a point-of-sale or draft order, a $0 order, an order paid without a card (cash, bank transfer, gift card…), or one matching a tag or sales channel you chose to ignore in Settings.
HOLD_EXPIREDNobody reviewed the hold within 48 hours, so it was cancelled or released (Settings › Holds).
AllowlistedA known-good customer, card or email. It's still scored, but never cancelled: at most held for you.

Support

Use the contact details on the app's Shopify App Store listing. Include your store's address (yourstore.myshopify.com) and the order number if it's about an order.