Skip to content
MyStoreKit
Fraud prevention

How to stop fraudulent Shopify orders: building rules that block them before payment

Updated:

Stores that sell limited products know the pattern: the moment a release goes live, resale orders flood in. Add prank orders to fake addresses, orders from throwaway email domains, and regular customers wandering into wholesale price lines. None of these look dramatic on their own, but left alone they quietly eat your inventory and your reputation.

The damage isn’t limited to payments you can’t collect. Limited items bought for resale never reach your real customers. When a problem only surfaces after shipping, you pay for it in support tickets and resends. And even when you cancel an order after payment, the processing fee stays behind. The smaller the store, the harder each of these hits.

The right place to handle bad orders is not cleanup after the fact but refusal at the door. In this article, I’ll lay out how to stop fraudulent orders at Shopify checkout, before payment completes. I built one of the tools I mention here, so you know where I’m coming from.

The four most common fraud patterns

Before picking countermeasures, be clear about what you’re blocking. Frequency varies by store, but these four cover most cases.

The first is bulk buying for resale. Limited collaborations and popular items get bought out right after release. Resellers often rotate multiple accounts and addresses, and when genuine customers can’t buy, trust in the store itself erodes. The core countermeasure is a quantity cap, and I wrote up that approach separately in the purchase quantity limits article.

The second is prank and harassment orders. Orders to nonexistent addresses, or with contents the “customer” never meant to buy, and the kind you only notice when fulfillment starts. Returns, resends, and shipping costs turn straight into losses. Serious cases repeat from the same person, and on COD stores they connect to the refused-delivery problem.

The third is orders from disposable email addresses. An order placed with a throwaway email domain can’t receive follow-up messages, so cancellation and confirmation exchanges go nowhere. Because the email domain is a clean signal, these are among the easiest orders to stop with a rule.

The fourth is general customers leaking into B2B lines. Regular shoppers finding their way into wholesale-priced collections or company-only sales channels. The price leak is damage on its own, and it breaks the terms you agreed to with your B2B customers.

How far Shopify’s built-in tools go

Shopify includes a built-in feature called Fraud Analysis. It shows you how risky each order looks after it comes in, and as a judgment aid it’s genuinely useful. But what it shows is a post-purchase risk score; the order itself is not stopped. Even with a high score, the order exists until you cancel it, and the payment completes. You’re left with the cancellation work and the processing fee.

In other words, the built-in tool can find suspicious orders, but it can’t refuse them. To refuse them, you need a mechanism that checks conditions during checkout, before payment completes, and stops the order there. Shopify Functions’ Cart & Checkout Validation API is the foundation for that, and Validify Checkout Guard, the app I built, is a single-purpose app that plugs rules into it.

The thinking behind rule-based blocking

The design rests on two pillars.

The first is block-only behavior. The app does exactly one thing: stop orders that match a rule. There is no warn-only mode and no flag-for-review mode. Every intermediate state makes operations harder to reason about, so I left them out from the start. Behavior stays predictable, and settings stay simple.

The second is failing open. If the app itself errors, checkout keeps working. A fraud-prevention app whose outage stops real customers from buying would defeat its own purpose, so it’s designed not to.

When you build rules, the baseline is to stack simple ones. Rather than one giant rule covering every pattern, combine single-purpose rules like “total quantity per order” and “number of orders this customer has placed”. When something over-blocks, the reason is easier to trace, and rules are easier to revisit later. Checkout Guard offers 36 criteria and 18 operators, covering the cart, customer, line items, shipping destination, and B2B areas. You can combine up to 25 rules per policy and 25 conditions per rule. When an order matches several rules at once, each matched rule raises its own separate error, so you can see exactly which rules tripped and spot an over-eager one quickly.

Concrete rule examples

Every rule is written in the same shape: criterion + operator + value. Here are three examples.

To cap the total quantity per order, use the criterion “total quantity” + the operator “greater than” + the value 6. The moment an order’s total quantity exceeds 6 items, checkout stops. This works as the first wall against resale buy-outs. Finer designs, like narrowing it to specific products or being stricter with first-time customers, are covered in the purchase quantity limits article.

To block disposable email domains, use the criterion “email domain” + the operator “matches regex” + a pattern of throwaway domains as the value. Regexes are case-insensitive, capped at 200 characters, and compiled with a check when you save, so typos get caught. Ten criteria accept regexes, and email domain is the main one. When simply listing domains is enough, the operator “is one of” with a list does the same job.

To block countries you don’t ship to, use the criterion “shipping country” + the operator “is none of” + the countries you can ship to as the value. The shipping country criterion picks from a picker of 249 countries. If your cross-border store can’t ship somewhere, stopping the order at checkout is easier for both sides than declining after the order arrives. A domestic-only store needs a single condition: block any shipping country other than your own. Other address-side trouble, like postal code formats and PO Box addresses, is covered in the address validation article.

The message blocked shoppers see

When a rule stops an order, blocking with no explanation is unkind to the person trying to buy. Checkout Guard lets you write a message that shows the shopper why the block happened. Messages support 36 languages and display in the shopper’s language, and you can write up to 500 characters.

The trick is to state both what tripped and what to change. Something like: “To prevent resale, we limit purchases to 6 items per customer. Please adjust your quantity.” When the next step is clear, legitimate customers adjust and buy again. One note: the multilingual support covers this shopper-facing message only. The settings screen itself is in English, and the message you write is what shoppers see.

Getting started

There’s a 7-day free trial. My recommendation is to start with a single rule, then spend the trial comparing its behavior against your store’s order history: is it over-blocking anything, is anything slipping through. The app is $5 a month, and your rules are stored inside your own store’s Shopify data. If you’re unsure how to assemble a rule, you can have Shopify’s AI assistant Sidekick draft one in plain words. Tell it something like “I want to limit orders to 6 items to prevent resale” and a draft opens in the app’s rule builder. Saving is always a step you confirm yourself; the AI never changes your settings on its own. And if setup gives you trouble, I answer support myself within 24 hours. You can check the app details here.