Skip to content
GPLWP Guides

How to block fraudulent orders in WooCommerce

Security Time About 30 minutes 6 steps Updated 9 Oct 2026

SECURITY
The short answer

WooCommerce does not provide the same fraud-blocking tools on every hosting setup. Use your payment gateway and any available WooCommerce fraud controls first, then block confirmed bad email addresses, phone numbers, addresses, or IPs with a dedicated blacklist plugin.

The route
  1. 01Review the suspicious order
  2. 02Turn on available fraud controls
  3. 03Add a narrow manual block
  4. 04Protect the checkout from bots
  5. 05Test and monitor the rules
  6. 06Use a dedicated blacklist when needed

What you need

  • A WooCommerce store with a working payment gateway
  • Administrator access to WordPress and your payment provider
  • A recent fraudulent order or checkout attempt to investigate
  • A staging site or test customer account if you will change checkout rules

Review the suspicious order

Start with the order record and your payment gateway dashboard. Check the email address, phone number, billing and shipping details, IP address, payment result, order value, and whether several failed attempts happened close together. A high-risk order should be held for review rather than fulfilled automatically.

Do not treat one signal as proof of fraud. Shared IP addresses, mismatched billing details, travel, VPN use, and a first order can all belong to legitimate customers. Confirm the chargeback, gateway warning, or repeated abuse before adding a permanent block.

Turn on available fraud controls

Check WooCommerce → Settings for a fraud-prevention section. On eligible WordPress.com stores running on WP Cloud, WooCommerce includes fraud prevention that can record checkout attempts and automatically block attempts it flags. Review the recorded attempts before enabling automatic blocking, then monitor the results for false positives.

Also review your payment gateway's fraud, card-testing, 3-D Secure, verification, and dispute settings. WooCommerce's built-in or hosted controls are not available in the same way on every hosting platform, and fraud prevention does not replace the controls supplied by your payment provider.

Add a narrow manual block

For a confirmed repeat offender, add the smallest useful rule: usually the exact email address, followed by a phone number or address when the evidence supports it. Use an IP block cautiously because an IP can belong to a household, office, school, mobile carrier, or VPN and may block unrelated shoppers. Exact-value rules also will not catch a fraudster who changes email addresses or connects from another network.

If your store has no built-in blacklist controls, the honest manual route is operational rather than automatic: place suspicious orders on hold, cancel confirmed fraud, record the identifiers in your fraud log, and add them to the payment gateway's block or risk rules. This works for occasional abuse, but it becomes slow and inconsistent when attackers rotate their details.

Protect the checkout from bots

Repeated failed payments in a short period may indicate card testing rather than ordinary abandoned carts. Add checkout CAPTCHA or an equivalent bot check, and use order or payment-attempt limits where your gateway or fraud extension supports them. Set thresholds from your normal order volume instead of choosing an aggressive number that blocks genuine customers.

Test every checkout path you actually use, including classic checkout, block checkout, express payment buttons, saved payment methods, and any custom or headless flow. A heavily customised checkout may not be covered by the same fraud controls as the standard WooCommerce checkout.

Test and monitor the rules

Place a low-value test order with a permitted account and confirm that normal customers can still reach payment. Then check that a blocked test identifier is stopped before the payment is captured. Keep a support route visible because a false positive needs a way back into the store.

Review blocked attempts and chargebacks regularly. Delete stale rules, add allow rules only for genuinely trusted customers, and never assume that blocking one IP permanently removes the problem. WooCommerce rules generally apply to future attempts, not orders that already exist.

Use a dedicated blacklist when needed

If you need one place to block customers by email, phone, name, address, or IP, with logs and temporary rules, consider Aelia Blacklister for WooCommerce. It is a better fit than maintaining a spreadsheet and manually checking every order when fraud is recurring or targeted.

Install it through Plugins → Add New → Upload Plugin, activate it, then configure its blacklist settings. Start with confirmed identifiers, keep IP rules narrow, and review its blocked-attempt logs after launch. Test the checkout and your legitimate customer journey before relying on the rules during a busy sales period.

The fast route

Let Aelia Blacklister for WooCommerce do it

Blocks buyers by identity, contact details, address, or IP, with logs and temporary rules for targeted fraud prevention.

Get Aelia Blacklister for WooCommerce

Sources

  1. woocommerce.com /document/woocommerce-anti-fraud/?utm_source=openai
  2. woocommerce.com /document/fraud-protection/?utm_source=openai
  3. woocommerce.com /document/anti-fraud-protection-for-woocommerce/?utm_source=…

Questions

Can WooCommerce block fraudulent customers by itself?
Not on every WooCommerce installation. WooCommerce has fraud-prevention features for eligible WordPress.com stores running on WP Cloud, while other stores usually depend on their payment gateway, a fraud extension, or manual order review. Core WooCommerce alone is not a universal email, address, phone, and IP blacklist, so check which controls your hosting and payment setup actually provide.
Should I block a fraudulent customer's IP address?
Only when the IP is strong evidence and the risk of collateral blocking is acceptable. IP addresses can be shared by households, offices, schools, mobile networks, and VPN users. If you have a choice, blocking the confirmed email address or another specific identifier is usually narrower. Review the rule later and remove it if legitimate customers are affected.
How do I stop card-testing orders in WooCommerce?
Use several moderate controls: payment-gateway fraud tools, checkout CAPTCHA, limits on repeated payment attempts, and monitoring for bursts of failed orders. Card testers often rotate email addresses, so a single blacklist entry will not be enough. Test the controls on every checkout route, especially express payments and custom checkout flows, before enabling strict blocking.
Should fraudulent orders be cancelled or put on hold?
Put a suspicious order on hold while you investigate, then cancel confirmed fraud before fulfilment. Do not ship because an order appears paid: payment authorisation can still be reversed, disputed, or flagged by the gateway. Record the reason, gateway evidence, and identifiers so you can apply a narrow future block instead of guessing from one unusual customer detail.
Will blocking one email address stop the same fraudster?
No. An exact email block stops future attempts using that address, but the same person may change email, phone, payment details, IP address, or shipping information. Combine narrow identity blocks with gateway fraud checks, velocity limits, CAPTCHA, and order review. Keep the rules small and current because a large, stale blacklist is difficult to audit.