Fraud Module Strategy – Layered Security

The Principle:

No single fraud module is perfect. Effective fraud prevention uses multiple modules working together.

Recommended Configuration for Most Merchants:

  1. AVS Response: Moderate (require ZIP match)
  2. CVV Response: Block mismatches
  3. Velocity Control: IP-based, 10 transactions in 10 minutes
  4. Country Blocker: Block high-risk countries if not needed
  5. Duplicate Detection: 5-minute window
  6. Transaction Amount: Minimum $1, Maximum appropriate to business

Additional for High-Risk Merchants:

  1. Risk Score: If budget allows
  2. 3DS Verification: If selling high-ticket or digital goods
  3. IP Blocker: As needed for known fraud sources
  4. Email Blocker: Block disposable email domains

Testing Your Fraud Settings:

After configuration:

  1. Process test transaction that should pass
  2. Process test transaction that should be blocked
  3. Verify each module triggers correctly
  4. Monitor for false positives (legitimate customers blocked)
  5. Adjust thresholds as needed

Ongoing Management:

  • Review blocked transactions daily/weekly
  • Look for patterns in declined legitimate transactions
  • Adjust overly aggressive rules
  • Add new blocks as fraud sources are identified