Skip to main content

Setting Up Fraud Protection

TL;DR
  • Turn on AVS and CVV. Free, catches obvious fraud
  • Set up velocity limits. Blocks card testing attacks
  • Fix your billing descriptor. It'll stop friendly fraud before it starts
  • Consider 3D Secure for high-risk transactions. It'll shift fraud liability to the issuer

You know what fraud looks like. Now turn on your defenses. Most of the effective ones are free. They're already sitting in your processor dashboard.

123
Payments
Chargebacks
Fraud
Operations
Costs
Pathway 3: Fraud · Lesson 2 of 3
8 min read

Step 1: Enable AVS and CVV (Free)

AVS checks the billing address against the issuer's records. That's Address Verification Service. CVV checks the 3-4 digit code on the card. Both are free.

What to do:

  1. Log into your processor dashboard
  2. Find fraud rules or risk settings
  3. Enable CVV requirement for all transactions
  4. Enable AVS checking

Where to find it by processor:

  • Stripe: Dashboard > Radar > Rules (AVS/CVV are on by default)
  • Square: Dashboard > Account & Settings > Risk Manager
  • Shopify Payments: Settings > Payments > Fraud analysis (basic fraud analysis is automatic)
  • Braintree: Control Panel > Fraud Management

How to use the results:

SignalWhat to Do
CVV doesn't matchDecline. The card isn't present. This is almost always fraud.
AVS full match (address + zip)Good signal. Process normally.
AVS partial match (zip only)Moderate risk. Fine for most orders.
AVS no matchHigher risk. Review the order manually if it's large.
AVS unavailable (international cards)Don't auto-decline. 40-60% of non-US cards can't check AVS. Use other signals.
Don't Hard-Decline on AVS Alone

About 20-30% of legitimate customers fail AVS checks. They've moved recently. They typed the address differently. Their bank's records are stale. Decline every AVS mismatch and you'll lose sales. More than you save in fraud.

Step 2: Set Up Velocity Limits (Free)

Velocity limits cap transactions from one card, IP or device. You set the window. They're your best defense against card testing.

Start with these limits:

RuleThresholdWhy
Transactions per card per hour3Normal customers don't buy 4+ times in an hour
Transactions per IP per hour5Catches automated testing
Failed authorizations per card (10 min)3Fraudsters test until one works
Unique cards per device per day5One person doesn't normally use 6 cards

Where to set these:

  • Stripe: Dashboard > Radar > Rules > Add rule (e.g., "Block if :card_count_for_ip: > 5")
  • Square: Dashboard > Account & Settings > Risk Manager > Velocity rules
  • Shopify Payments: Settings > Payments > Fraud analysis (limited built-in; use Shopify Flow for custom rules)
  • Braintree: Control Panel > Fraud Management > Advanced Fraud Tools
Test Before You Block

Run rules in "shadow mode" first, if your processor supports it. Flag transactions without blocking them. After 2 weeks, check how many flags were actually fraud. Under 30% and your rule's too aggressive.

Step 3: Fix Your Billing Descriptor (Free)

It's the highest-impact change on this list. Your billing descriptor is what shows on the customer's statement.

Bad descriptors that cause disputes:

  • PAY*ACME LLC
  • SP * JOHN DOE
  • STRIPE 8472910

Good descriptors that prevent disputes:

  • ACME WIDGETS (your recognizable business name)
  • PETSTORE.COM (your website URL)
  • ACME 800-555-0199 (name + phone number)

How to fix it:

  • Stripe: Dashboard > Settings > Public details > Statement descriptor
  • Square: Dashboard > Account & Settings > Business information > Statement descriptor
  • Shopify Payments: Settings > Payments > Statement descriptor
  • PayPal: Settings > Payment preferences > Statement descriptor

Set it to your recognizable business name or website URL. If your processor allows it, add your phone number.

Test it: make a $1 purchase on your own card. Check your statement in 2-3 days. Can't immediately tell what the charge is for? Your customers can't either.

Step 4: Send Purchase Confirmations (Free)

Email or SMS confirmations immediately after purchase do two things:

  1. Remind the customer what they bought (prevents "I don't recognize this" disputes)
  2. Give them a way to contact you instead of their bank

Your confirmation should include:

  • Your business name (matching the billing descriptor)
  • What they bought (specific items, not just "Order #12345")
  • The amount charged
  • Your contact information for questions
  • How to request a refund

Step 5: Consider 3D Secure for High-Risk Orders

3D Secure is the prompt you sometimes get at checkout. "Visa Secure" or "Mastercard Identity Check." The older names were "Verified by Visa" and "Mastercard SecureCode." It's powerful because it shifts fraud liability to the card issuer. A fraud chargeback on a 3DS-authenticated transaction? The issuer eats it, not you.

The tradeoff: 3DS adds friction to checkout. Expect a 2-5% drop in authorization rate at first.

When 3DS is worth it:

  • Your fraud rate is above 0.5%
  • You sell digital goods (no shipping address to verify)
  • You're approaching chargeback warning thresholds. Acquirers often act well below the 1.5% VAMP line
  • Individual orders are high value

When to skip 3DS:

  • Your fraud rate is low
  • You sell low-value items where chargebacks are cheaper than lost sales
  • Your customers are mostly repeat buyers, so they're low risk

How to enable it:

  • Stripe: Dashboard > Settings > Payments > 3D Secure rules (or use Radar rules to trigger selectively)
  • Square: Not available for most SMB accounts
  • Shopify Payments: Enabled automatically for high-risk transactions
  • Braintree: Control Panel > Processing > 3D Secure

How to roll it out:

  1. Start with your highest-risk segment only. New customers, plus orders above your average fraud amount
  2. Run for 2-4 weeks. Measure the impact on auth rate and fraud
  3. Auth rate drops more than 5% with no fraud improvement? Scale it back

Your Protection Setup Checklist

Do these in order, this week:

□ Enable CVV requirement (5 minutes)
□ Enable AVS checking (5 minutes)
□ Set velocity limits on your processor (15 minutes)
□ Fix your billing descriptor (10 minutes)
□ Set up purchase confirmation emails (30 minutes)
□ Make a test purchase and check your own statement (2 days to verify)
□ Review if 3DS makes sense for your risk level (15 minutes)

Next Steps