Screening checkout for fake orders — and the line where it stops
Order screening advice usually skips the part where the tool runs out. This post starts from the boundary, because for e-commerce the boundary is unusually close.
Contents
Most order-screening advice tells you what to check and stops before the part you actually need, which is where the checking runs out. For e-commerce that boundary arrives unusually early, so it is worth starting there.
What this cannot answer
Whether the shipping address is real. Boundstone validates email addresses, phone numbers and IP addresses. It does not verify postal addresses, does not confirm a street exists, and does not check whether the delivery address matches the cardholder. If your fraud problem is parcels going to reshippers, that is an address-verification product and this is not one.
Whether the card is stolen. Not our layer, and never will be.
Whether the buyer is behind a VPN. The IP endpoint returns format, version and range classification. geolocation, asn, hosting_datacenter, proxy_vpn_tor and reputation all come back in checks.not_performed, because they need licensed data we do not ship.
Who the device belongs to. No fingerprinting, no behavioural scoring.
That is four of the six questions most order-fraud tooling is bought for. If those are your problem, buy a fraud platform and come back for the hygiene layer afterwards.
What it can answer
Three signals, each real and each narrow.
The email is a throwaway. disposable: true means the domain is on a maintained list of throwaway providers. On a physical-goods order, a burner inbox is a genuinely odd choice — the buyer normally wants the tracking number. This is the strongest of the three for e-commerce, precisely because the innocent explanation is weaker here than it is at a SaaS signup.
The phone is a designated VoIP range. line_type: "voip" on an order where you will send delivery updates is worth noting. Metadata catches designated ranges, not a VoIP service that has ported onto a mobile range; resolving that needs a live dip with hlr:true at 5 credits on a paid plan.
The source IP is not a plausible public address. A private, loopback or reserved classification on a public checkout means something is misconfigured or forged. It is rare, and when it appears it is worth acting on.
Combine, then route
None of these is a verdict on its own. A privacy-conscious buyer with a throwaway inbox and a VoIP number is a real customer, and blocking them costs you a sale you never learn about.
The useful shape is the same one that works at signup: count independent signals and let the count pick the response. One signal is worth logging. Two is worth a review before fulfilment — which for physical goods is a genuinely cheap intervention, because the parcel has not moved yet. Three, on a high-value order, is worth holding.
The advantage e-commerce has over SaaS here is time. You are not deciding in the 200 milliseconds before a page renders; you are deciding before a picker touches a shelf. Use it — a review queue that runs hourly is entirely sufficient, and it makes hard automatic blocks unnecessary.
Where the honest boundary helps you
A screening rule you cannot explain is a rule you will eventually disable during a busy week. Because every Boundstone response names what it did and did not check, the rule you write is auditable: this order was held because the address was on a disposable list and the line type was VoIP — not because an opaque score said 0.82.
When a customer disputes a hold, that is a sentence you can say out loud.
The short version
- Start with the boundary. No postal address verification, no card checks, no VPN or proxy detection, no device fingerprinting — four of the six questions order-fraud tooling is usually bought for.
- If parcels to reshippers are the problem, you need an address-verification product, not this one.
- Three real signals: disposable email, designated-VoIP line type, and a source IP classifying as private, loopback or reserved.
- Disposable email is the strongest for physical goods — a buyer expecting a parcel usually wants the tracking number.
- Count signals, then route. One is a log, two is a review before fulfilment, three on a high-value order is a hold.
- E-commerce has time that SaaS does not. Deciding before the picker moves means an hourly review queue beats an automatic block.
- An explainable hold survives a dispute. "Disposable domain plus VoIP line" is a sentence; "score 0.82" is not.