Fraud Module Strategy – Layered Security
The Principle:
No single fraud module is perfect. Effective fraud prevention uses multiple modules working together.
Recommended Configuration for Most Merchants:
- AVS Response: Moderate (require ZIP match)
- CVV Response: Block mismatches
- Velocity Control: IP-based, 10 transactions in 10 minutes
- Country Blocker: Block high-risk countries if not needed
- Duplicate Detection: 5-minute window
- Transaction Amount: Minimum $1, Maximum appropriate to business
Additional for High-Risk Merchants:
- Risk Score: If budget allows
- 3DS Verification: If selling high-ticket or digital goods
- IP Blocker: As needed for known fraud sources
- Email Blocker: Block disposable email domains
Testing Your Fraud Settings:
After configuration:
- Process test transaction that should pass
- Process test transaction that should be blocked
- Verify each module triggers correctly
- Monitor for false positives (legitimate customers blocked)
- Adjust thresholds as needed
Ongoing Management:
- Review blocked transactions daily/weekly
- Look for patterns in declined legitimate transactions
- Adjust overly aggressive rules
- Add new blocks as fraud sources are identified
