Blocking bad actors

The blocklist stops checkouts that match rules you set, before any charge is attempted. It is your first line of defense against repeat fraud and abuse. Find it under Settings, then Blocklist & allowlists.

How the blocklist works

  • Every checkout is checked against your rules before the payment is attempted.
  • If a checkout matches a rule, it is declined and no charge is made.
  • Rules follow the mode you are in, so rules you add while testing apply in sandbox, and live rules apply to live payments.

Adding a rule

  1. Open Settings, then Blocklist & allowlists.
  2. Click Add rule.
  3. Under Block by, choose what to match on (see the list below).
  4. Enter the value.
  5. Optionally add a label to remember why you added it.
  6. Click Add block rule.

You can also block straight from a payment: open a suspicious transaction and use Block at checkout to build a rule from its details.

What you can block by

  • Email address. One exact email.
  • Email domain. Everyone at a domain, like example.com.
  • Phone number.
  • IP address.
  • Billing country. Block a whole country.
  • Postal or ZIP code.
  • Street address.
  • Card BIN. The first six digits of a card, which identify the issuing bank.
  • Card brand. For example Visa or Mastercard.
  • Specific card. A single card, by its last four digits and brand.
  • Bank account. A single bank account, by routing and account number.

Global rules vs customer-scoped rules

  • Most rules are global: they block that value for everyone.
  • Two rules are customer-scoped: Specific card and Bank account. Because many people can share the same last four digits, these ask for a customer email or name, so you block that one person's card or account without blocking those digits for everyone else. Scoped rules show a Customer only badge in the list.

Labeling and removing rules

Add a label to any rule to note why you blocked it. It shows in the list, so your team has context later.

To remove a rule, click the trash icon next to it and confirm. Any checkouts that matched it are allowed again right away.

What a blocked customer sees

A blocked checkout is declined before any charge is attempted, so no money moves and there is nothing to refund. The customer sees a standard decline and cannot complete the purchase.

Tips

  • Blocking is powerful. A domain or country rule can stop legitimate customers too, so use broad rules with care.
  • The blocklist prevents charges, which also helps prevent disputes. Pair it with a clear descriptor and receipts. See Disputes and chargebacks.