# Screening checkout for fake orders — and the line where it stops

_2026-09-29 · Boundstone (https://boundstone.io/blog/screening-checkout-for-fake-orders)_


Most order-screening advice tells you what to check and stops before the part you actually need, which is where the checking runs out. For e-commerce that boundary arrives unusually early, so it is worth starting there.

## What this cannot answer

**Whether the shipping address is real.** Boundstone validates email addresses, phone numbers and IP addresses. It does not verify postal addresses, does not confirm a street exists, and does not check whether the delivery address matches the cardholder. If your fraud problem is parcels going to reshippers, that is an address-verification product and this is not one.

**Whether the card is stolen.** Not our layer, and never will be.

**Whether the buyer is behind a VPN.** The IP endpoint returns format, version and range classification. `geolocation`, `asn`, `hosting_datacenter`, `proxy_vpn_tor` and `reputation` all come back in `checks.not_performed`, because they need licensed data we do not ship.

**Who the device belongs to.** No fingerprinting, no behavioural scoring.

That is four of the six questions most order-fraud tooling is bought for. If those are your problem, buy a fraud platform and come back for the hygiene layer afterwards.

## What it can answer

Three signals, each real and each narrow.

**The email is a throwaway.** `disposable: true` means the domain is on a maintained list of throwaway providers. On a physical-goods order, a burner inbox is a genuinely odd choice — the buyer normally wants the tracking number. This is the strongest of the three for e-commerce, precisely because the innocent explanation is weaker here than it is at a SaaS signup.

**The phone is a designated VoIP range.** `line_type: "voip"` on an order where you will send delivery updates is worth noting. Metadata catches designated ranges, not a VoIP service that has ported onto a mobile range; resolving that needs a live dip with `hlr:true` at 5 credits on a paid plan.

**The source IP is not a plausible public address.** A `private`, `loopback` or `reserved` classification on a public checkout means something is misconfigured or forged. It is rare, and when it appears it is worth acting on.

## Combine, then route

None of these is a verdict on its own. A privacy-conscious buyer with a throwaway inbox and a VoIP number is a real customer, and blocking them costs you a sale you never learn about.

The useful shape is the same one that works at signup: count independent signals and let the count pick the response. One signal is worth logging. Two is worth a review before fulfilment — which for physical goods is a genuinely cheap intervention, because the parcel has not moved yet. Three, on a high-value order, is worth holding.

The advantage e-commerce has over SaaS here is time. You are not deciding in the 200 milliseconds before a page renders; you are deciding before a picker touches a shelf. Use it — a review queue that runs hourly is entirely sufficient, and it makes hard automatic blocks unnecessary.

## Where the honest boundary helps you

A screening rule you cannot explain is a rule you will eventually disable during a busy week. Because every Boundstone response names what it did and did not check, the rule you write is auditable: this order was held because the address was on a disposable list and the line type was VoIP — not because an opaque score said 0.82.

When a customer disputes a hold, that is a sentence you can say out loud.

## The short version

- **Start with the boundary.** No postal address verification, no card checks, no VPN or proxy detection, no device fingerprinting — four of the six questions order-fraud tooling is usually bought for.
- **If parcels to reshippers are the problem**, you need an address-verification product, not this one.
- **Three real signals:** disposable email, designated-VoIP line type, and a source IP classifying as private, loopback or reserved.
- **Disposable email is the strongest for physical goods** — a buyer expecting a parcel usually wants the tracking number.
- **Count signals, then route.** One is a log, two is a review before fulfilment, three on a high-value order is a hold.
- **E-commerce has time that SaaS does not.** Deciding before the picker moves means an hourly review queue beats an automatic block.
- **An explainable hold survives a dispute.** "Disposable domain plus VoIP line" is a sentence; "score 0.82" is not.
