How to block fraudulent orders in WooCommerce
WooCommerce does not provide the same fraud-blocking tools on every hosting setup. Use your payment gateway and any available WooCommerce fraud controls first, then block confirmed bad email addresses, phone numbers, addresses, or IPs with a dedicated blacklist plugin.
- 01Review the suspicious order
- 02Turn on available fraud controls
- 03Add a narrow manual block
- 04Protect the checkout from bots
- 05Test and monitor the rules
- 06Use a dedicated blacklist when needed
What you need
- A WooCommerce store with a working payment gateway
- Administrator access to WordPress and your payment provider
- A recent fraudulent order or checkout attempt to investigate
- A staging site or test customer account if you will change checkout rules
Review the suspicious order
Start with the order record and your payment gateway dashboard. Check the email address, phone number, billing and shipping details, IP address, payment result, order value, and whether several failed attempts happened close together. A high-risk order should be held for review rather than fulfilled automatically.
Do not treat one signal as proof of fraud. Shared IP addresses, mismatched billing details, travel, VPN use, and a first order can all belong to legitimate customers. Confirm the chargeback, gateway warning, or repeated abuse before adding a permanent block.
Turn on available fraud controls
Check WooCommerce → Settings for a fraud-prevention section. On eligible WordPress.com stores running on WP Cloud, WooCommerce includes fraud prevention that can record checkout attempts and automatically block attempts it flags. Review the recorded attempts before enabling automatic blocking, then monitor the results for false positives.
Also review your payment gateway's fraud, card-testing, 3-D Secure, verification, and dispute settings. WooCommerce's built-in or hosted controls are not available in the same way on every hosting platform, and fraud prevention does not replace the controls supplied by your payment provider.
Add a narrow manual block
For a confirmed repeat offender, add the smallest useful rule: usually the exact email address, followed by a phone number or address when the evidence supports it. Use an IP block cautiously because an IP can belong to a household, office, school, mobile carrier, or VPN and may block unrelated shoppers. Exact-value rules also will not catch a fraudster who changes email addresses or connects from another network.
If your store has no built-in blacklist controls, the honest manual route is operational rather than automatic: place suspicious orders on hold, cancel confirmed fraud, record the identifiers in your fraud log, and add them to the payment gateway's block or risk rules. This works for occasional abuse, but it becomes slow and inconsistent when attackers rotate their details.
Protect the checkout from bots
Repeated failed payments in a short period may indicate card testing rather than ordinary abandoned carts. Add checkout CAPTCHA or an equivalent bot check, and use order or payment-attempt limits where your gateway or fraud extension supports them. Set thresholds from your normal order volume instead of choosing an aggressive number that blocks genuine customers.
Test every checkout path you actually use, including classic checkout, block checkout, express payment buttons, saved payment methods, and any custom or headless flow. A heavily customised checkout may not be covered by the same fraud controls as the standard WooCommerce checkout.
Test and monitor the rules
Place a low-value test order with a permitted account and confirm that normal customers can still reach payment. Then check that a blocked test identifier is stopped before the payment is captured. Keep a support route visible because a false positive needs a way back into the store.
Review blocked attempts and chargebacks regularly. Delete stale rules, add allow rules only for genuinely trusted customers, and never assume that blocking one IP permanently removes the problem. WooCommerce rules generally apply to future attempts, not orders that already exist.
Use a dedicated blacklist when needed
If you need one place to block customers by email, phone, name, address, or IP, with logs and temporary rules, consider Aelia Blacklister for WooCommerce. It is a better fit than maintaining a spreadsheet and manually checking every order when fraud is recurring or targeted.
Install it through Plugins → Add New → Upload Plugin, activate it, then configure its blacklist settings. Start with confirmed identifiers, keep IP rules narrow, and review its blocked-attempt logs after launch. Test the checkout and your legitimate customer journey before relying on the rules during a busy sales period.
Let Aelia Blacklister for WooCommerce do it
Blocks buyers by identity, contact details, address, or IP, with logs and temporary rules for targeted fraud prevention.
Sources
- woocommerce.com /document/woocommerce-anti-fraud/?utm_source=openai
- woocommerce.com /document/fraud-protection/?utm_source=openai
- woocommerce.com /document/anti-fraud-protection-for-woocommerce/?utm_source=…
Questions
- Can WooCommerce block fraudulent customers by itself?
- Not on every WooCommerce installation. WooCommerce has fraud-prevention features for eligible WordPress.com stores running on WP Cloud, while other stores usually depend on their payment gateway, a fraud extension, or manual order review. Core WooCommerce alone is not a universal email, address, phone, and IP blacklist, so check which controls your hosting and payment setup actually provide.
- Should I block a fraudulent customer's IP address?
- Only when the IP is strong evidence and the risk of collateral blocking is acceptable. IP addresses can be shared by households, offices, schools, mobile networks, and VPN users. If you have a choice, blocking the confirmed email address or another specific identifier is usually narrower. Review the rule later and remove it if legitimate customers are affected.
- How do I stop card-testing orders in WooCommerce?
- Use several moderate controls: payment-gateway fraud tools, checkout CAPTCHA, limits on repeated payment attempts, and monitoring for bursts of failed orders. Card testers often rotate email addresses, so a single blacklist entry will not be enough. Test the controls on every checkout route, especially express payments and custom checkout flows, before enabling strict blocking.
- Should fraudulent orders be cancelled or put on hold?
- Put a suspicious order on hold while you investigate, then cancel confirmed fraud before fulfilment. Do not ship because an order appears paid: payment authorisation can still be reversed, disputed, or flagged by the gateway. Record the reason, gateway evidence, and identifiers so you can apply a narrow future block instead of guessing from one unusual customer detail.
- Will blocking one email address stop the same fraudster?
- No. An exact email block stops future attempts using that address, but the same person may change email, phone, payment details, IP address, or shipping information. Combine narrow identity blocks with gateway fraud checks, velocity limits, CAPTCHA, and order review. Keep the rules small and current because a large, stale blacklist is difficult to audit.