Set the Right Fraud Friction at Online Checkout Without Losing Good Customers
Online merchants face a constant challenge: stopping fraud without frustrating legitimate customers at checkout. Industry experts have identified specific strategies that strike this balance, protecting revenue while maintaining a smooth purchase experience. These targeted approaches help businesses reduce chargebacks and false declines by focusing fraud prevention efforts where they matter most.
Trust Familiar Devices With Proven History
With digital products, where fulfillment is instant and irreversible, I draw the line by risk score. I run a dynamic assessment on each order and sort it into one of three outcomes: wave it through, apply one targeted check, or hold it for a human to review. The gray-area middle is where the extra steps go.
The single most useful signal I use is device recognition tied to a customer account with purchase history. A known device on a known account gets waved straight through, whatever the order size. That one input removes friction from the bulk of my good traffic and frees up the budget and attention for scrutiny on the small slice that needs it, like cross-border orders from high-risk geolocations, new accounts placing unusually large first orders, and mismatched billing details. I place the friction there, where it protects the checkout for the buyers I already trust.

Track Email Domain Velocity
We got hammered with fraud when my e-commerce brand started scaling past seven figures. Chargebacks spiked to 2.8% one month, and our payment processor threatened to drop us. I was terrified of adding friction because our checkout conversion was already sitting at 68%, and every point mattered.
The breakthrough came when I stopped thinking about fraud prevention as a gate and started thinking about it as a filter. We implemented address verification as our primary signal, but here's what nobody tells you: we didn't make it a hard stop. If AVS failed, we flagged the order for manual review instead of declining it outright. That one change was massive. About 40% of our flagged orders turned out to be legitimate customers who'd moved recently or were shipping to a business address that didn't match their billing.
The single safeguard that actually worked? Velocity checks on email domains. We started tracking how many orders came from the same email domain within a 24-hour window. Fraudsters love to use temporary email services, and they're lazy about rotating them. When we saw three orders from different cards but all ending in the same obscure domain, that was our red flag. It cost us nothing to implement and caught about 60% of our fraud attempts.
Here's what I learned running fulfillment too: the 3PLs who obsessed over preventing every fraudulent order were the ones bleeding customers. The smart ones accepted that 0.5% fraud is just cost of doing business and optimized for speed instead. One of our clients at ShipDaddy was losing $30K monthly to fraud, but they were also doing $4M in revenue. When they added too much friction, revenue dropped 12% in three weeks. They rolled it back immediately.
The real answer is you need a human in the loop for edge cases. Automation catches the obvious stuff, but good customers do weird things all the time. Set your threshold where machines handle 95% and a person reviews the sketchy 5%. That's your line.
Use Value-Based Verification
We kept the standard checkout untouched and used order value as the line for additional verification. Orders above the normal range were briefly held for manual review, while ordinary purchases continued automatically. We then watched both sides: fraudulent orders that passed and legitimate orders delayed by the safeguard, adjusting the threshold when necessary. The principle was simple: add friction only where the potential loss becomes materially higher, not for every customer entering the checkout.
Pause Suspicious Transactions
The signal I trust most is not a fraud score by itself; it is whether an order looks rushed or mismatched, like a shipping address that does not match the billing information or an order size that does not fit the buyer's history. Those are the orders worth a second look before they ship, not every transaction across the board. Adding friction to every checkout to catch a small number of bad orders ends up punishing good customers far more often than it stops fraud.
The safeguard that has worked best for us is a manual review step triggered only by specific red flags, not a blanket verification step for every order. That way, most customers move through checkout without ever noticing extra steps, and the orders that actually look off get a real second look before they go into production. In a made-to-order business, catching a problem before production starts matters more than catching it after the fact, since the cost of a bad order is not just money; it is time we cannot get back.

Compare Billing and Shipping ZIP Codes
We started seeing a spike in chargebacks on orders that looked normal on the surface. High-value carts, real-looking addresses, cards that passed AVS. My team wanted to add CAPTCHA, mandatory account creation, and extra verification steps across the board. I pushed back because we sell across multiple channels and I knew from experience that every extra click at checkout costs real orders from real people.
The single thing that helped us draw the line was watching the gap between billing and shipping ZIP codes on flagged orders. When those two numbers diverged by more than a certain distance and the order value hit a threshold, we routed it to a short manual review queue. Everything else passed through untouched.
That one filter caught the majority of the fraudulent charges within the first few weeks, and our checkout completion rate for legitimate customers stayed flat. The cost of a quick manual review on a small batch of flagged orders was far less than the chargeback fees and lost inventory we had been absorbing.
Require 3D Secure for Cards
As Co-founder & Product designer at looch, I decided the line should be simple: Every card-not-present purchase gets 3D Secure, which is the extra check that confirms the shopper is really authorized to use that card. We don't try to guess which order looks suspicious. Risk-based rules can miss fraud and yes, they can make a good customer jump through hoops for no clear reason.
The exception is Apple Pay and Google Pay. Those wallets already have their own protection built in, so adding another check would slow someone down without buying the merchant much. That gave us a clean safeguard rather than a pile of rules: Cards get the check. Wallets don't. A shopper with a looch Pay account can also use a passkey to securely bring saved cards with them across looch businesses, which keeps checkout moving for returning customers.

Calibrate Thresholds Via False Positives
We initially set fraud rules based on industry benchmark thresholds, which sounded reasonable but turned out to be poorly calibrated to our specific customer base and product mix.
The signal that recalibrated everything was pulling our payment processor's historical false-positive data, specifically how many legitimate transactions had been declined or flagged under our existing rules over the previous six months.
That number was considerably higher than we'd assumed; somewhere around 4 per cent of legitimate transactions were experiencing friction or decline that had nothing to do with actual fraud risk.
We adjusted our fraud scoring thresholds specifically against that false-positive baseline rather than against generic industry fraud rates, accepting a slightly higher fraud tolerance in exchange for meaningfully lower false-positive impact on real customers.
Legitimate transaction friction dropped from roughly 4 per cent to about 1.2 per cent. Fraud losses increased marginally, about 0.3 percentage points, which we judged worth the trade given the revenue recovered from previously blocked good customers.
According to research from the Merchant Risk Council, false-positive rates in fraud prevention average roughly 2 to 3 times higher than actual fraud rates across most ecommerce categories, meaning most businesses are losing considerably more revenue to over-blocking than to fraud itself.

Flag High-Value Customer Mismatches
Add Friction Only Where the Risk Actually Is
Fraud screening isn't one-size-fits-all when you're selling furniture rather than low-cost impulse items. Most of our orders are repeat or planned purchases with a normal billing-to-shipping match, so we didn't want to slow every checkout down with extra verification steps that punish good customers for the behavior of a small minority.
The signal that mattered most was the mismatch between order value and account history: a first-time customer placing a large order with a shipping address that didn't match billing, especially with a request for expedited delivery, was the pattern worth a manual look. Everything else moves through checkout without added steps. That kept friction targeted at the handful of orders that actually needed a second look, instead of taxing every legitimate customer to catch a small number of bad ones.

Verify Brand-New Account Purchases
We added friction to exactly one place: the first purchase from a new account. Everyone else kept the checkout they already had.
The reasoning came from looking at where the abuse actually clustered rather than where it felt like it should. When we pulled the fraud cases apart, the overwhelming share were first orders from identities that had existed for minutes, often from the same small block of network addresses and the same disposable email providers. Repeat customers were almost never the problem. Adding a step for them would have taxed the people paying us to protect against the people who were not.
So the safeguard is asymmetric. A brand-new account gets a verification step and a short hold before the first order goes live. A returning customer with a paid history gets nothing new. The friction lands where the risk is, and the revenue is not asked to carry it.
Two measurements decided the design, and I would suggest both to anyone facing this.
First, we reconstructed the fraud rate by hand from raw orders before trusting the dashboard. Our instrument had been counting rows rather than distinct accounts, which made a handful of repeat abusers look like a broad population and would have pushed us toward blanket friction. Rows are not people.
Second, we tracked completion rate for good first-time customers through the new step, not just fraud caught. A safeguard that stops abuse and also stops a fifth of legitimate first orders is a net loss, and the second number is the one nobody volunteers to measure.
The honest caveat: the abuse pattern moves. The signals that worked last quarter — network block, email provider — degrade as people adapt, so the rule is reviewed against fresh cases monthly rather than set once. Friction that made sense in March can be pure cost by September.

Target Repeat Abusers by Account
Some market context first, because it changes the answer. I founded iFit, a Taiwanese content-commerce brand, and ran it from 2012 to 2022. In Taiwan, the dominant checkout options for most of that period were cash on delivery and convenience-store pickup-and-pay, not card-on-file. So the loss that actually accumulates is not chargebacks from stolen cards—it is orders that are placed and then never collected. You are out the shipping, the handling, and the return leg, on goods nobody paid for.
That reframes the friction question, because you cannot add a card verification step to a payment method that has no card. Almost every safeguard sold for this problem was built for a card-fraud market and did not apply.
The safeguard that works in that setting sits at the account level, not the checkout. A very small number of accounts produce most of the loss, and they are visible through repeat behaviour over time rather than through anything you can score in a single order. So identify those accounts, handle them individually with tiered treatment—restrict payment options, require prepayment, or simply decline—and leave the checkout untouched for everyone else.
The single principle I would give anyone setting this line: friction at checkout is charged to every good customer, while the abuse comes from a fraction of a percent. Any safeguard that taxes the many to stop the few is a bad trade, almost regardless of the fraud number. It is the same logic I applied to returns—we never degraded the policy for everyone because of a handful of people abusing it—and it held up in both places.
The practical test is easy to state: if a proposed safeguard cannot be aimed at the specific accounts causing the problem, it is not a safeguard, it is a tax on conversion.
Limitations: this is the Taiwan market between 2012 and 2022, where payment mix and fraud patterns differ substantially from card-led markets, and it predates my current business. I am not quoting fraud or chargeback rates.

Inspect Atypical Custom Requests
The safeguard I trust most is not adding friction to every customer. It is adding a manual check only when something in the order does not match the normal pattern.
For Packur, custom packaging orders have natural signals: delivery country, order size, product type, artwork file, billing details, and whether the customer's questions match what they are buying. If a small cafe is ordering branded cups and the details are consistent, I do not want to slow them down with unnecessary steps.
But if the order value, destination, contact details, or urgency feels unusual, we pause and review before production. That protects us without making honest customers feel punished.
The line I use is simple: friction should follow risk, not fear. If every customer has to prove they are trustworthy, the checkout experience starts to feel broken.





