Protection
Blocklist and protection log
Add blocklist entries manually and review caught orders.
Protection log
The Protection log on the Store Protection overview lists recent events:
- Order name and time
- Rule that tripped (blocklist, velocity, one-per-IP)
- Action taken (cancelled, flagged, or enforcement failed)
- IP, email, phone
- COD badge when applicable
Use this daily while tuning rules. If good orders are flagged, loosen velocity thresholds or switch actions to Flag.
Blocklist
The blocklist catches repeat offenders before velocity rules need to fire.
Entry types
| Type | Matches |
|---|---|
| IP | Exact IP address |
| Exact email on the order | |
| Phone | Normalized phone number |
| Address keyword | Keyword in shipping street + postal code |
Add manually
- Open Store Protection.
- In the blocklist section, choose type and value.
- Optional note (for example "Manual block — chargeback").
- Save.
Auto-blocklist
When Auto-blocklist is enabled on the velocity rule, identifiers from a tripped velocity event are added automatically so the next attempt is caught by the blocklist immediately.
Remove entries
Delete manual entries when you have unblocked a customer. Auto entries can be removed the same way.
What happens on Shopify
| Action | On Shopify |
|---|---|
| Cancel | Order cancelled; optional customer email |
| Flag | Order tagged for review; you fulfil or cancel manually |
If Shopify API access fails (for example token expired), the event is still logged with action failed so you can act manually.