Protection

Blocklist and protection log

Add blocklist entries manually and review caught orders.

Protection log

The Protection log on the Store Protection overview lists recent events:

  • Order name and time
  • Rule that tripped (blocklist, velocity, one-per-IP)
  • Action taken (cancelled, flagged, or enforcement failed)
  • IP, email, phone
  • COD badge when applicable

Use this daily while tuning rules. If good orders are flagged, loosen velocity thresholds or switch actions to Flag.

Blocklist

The blocklist catches repeat offenders before velocity rules need to fire.

Entry types

TypeMatches
IPExact IP address
EmailExact email on the order
PhoneNormalized phone number
Address keywordKeyword in shipping street + postal code

Add manually

  1. Open Store Protection.
  2. In the blocklist section, choose type and value.
  3. Optional note (for example "Manual block — chargeback").
  4. Save.

Auto-blocklist

When Auto-blocklist is enabled on the velocity rule, identifiers from a tripped velocity event are added automatically so the next attempt is caught by the blocklist immediately.

Remove entries

Delete manual entries when you have unblocked a customer. Auto entries can be removed the same way.

What happens on Shopify

ActionOn Shopify
CancelOrder cancelled; optional customer email
FlagOrder tagged for review; you fulfil or cancel manually

If Shopify API access fails (for example token expired), the event is still logged with action failed so you can act manually.

FAQ

Protection FAQ →