Skip to content
Order Editing

Fraud Prevention

Configure address-risk rules, review blocked edits, and allow a legitimate address when needed.

6 min read

How Fraud Prevention works

Order Editing checks a proposed post-purchase shipping address against anonymous address-risk evidence before saving the change. The evidence can include:

  • orders assessed as high or medium risk by Shopify;
  • orders associated with a chargeback;
  • known freight-forwarding destinations maintained by Order Editing.

The address is normalized before matching, so differences such as capitalization and common street suffixes do not create separate records. Unit or suite details are not used to identify the destination.

Fraud Prevention is always available. It does not depend on the retired payment-card last-four-digits setting.

A match is a risk signal, not proof of fraud. Keep a staff review path for legitimate customers whose change is blocked.

Default protection

Two read-only system rules apply during Address Editing:

  • Review known high-risk addresses allows a proposed address that matches a Shopify high-risk order or a known freight-forwarder address. After the change is saved, Order Editing adds a Medium risk assessment for your team to review. It does not block medium-risk evidence by default.
  • Block addresses with past chargebacks blocks a proposed address when it appeared on a past order with a credit card chargeback, even if Shopify did not mark that order high risk.

When the review rule matches, the address change is saved. The Medium assessment does not apply a fraud hold or tag, and it is not added to the shared address-risk evidence.

When an error rule blocks a save because of historical address evidence alone, Order Editing keeps the original address, records the blocked attempt in Address Validation analytics, and adds a Medium assessment. It does not add a fraud tag or direct fulfillment hold. If the current order is independently high risk, the block instead receives a High assessment and Fraudulent Edit tag; configured tag-based hold rules may then hold the order.

A block caused only by This order is high risk is not listed as a blocked address because it has no address-specific evidence to review or allow. Review that block through the order's risk assessment and the warning shown in the Shopify admin.

Order Editing stores an irreversible fingerprint for matching and may retain a formatted shipping or billing address, Shopify-validated coordinates, and risk-fact descriptions for a risk-evidence order. These readable values can identify a person or residential location. Source merchant and order identifiers remain protected by keyed fingerprints.

Create a merchant rule

Use an Instant Address Validation rule when your store needs stricter behavior. Merchant error rules are the only way to block a HIGH- or MEDIUM-risk address match. You can also block edits on an order Shopify already assesses as high risk, or require both signals.

  1. In the Shopify admin, go to Apps > Order Editing.
  2. Select Address Validation.
  3. Open the validation rules area and create an Instant Address Validation rule.
  4. Add Known high-risk address as a condition.
  5. Select the past risk levels your rule should match, including Past credit card chargebacks when you want that signal in a merchant rule.
  6. Optional: select This order is high risk to use the order's existing Shopify risk assessment, even when the proposed address has no historical risk evidence.
  7. Add any other conditions that should narrow the rule.
  8. Set the rule to block the save, then activate it.

> This order is high risk applies to the entire order. Allowing one address does not override an independent high-risk assessment from Shopify or another risk provider.

Selecting historical risk levels and This order is high risk inside the same Known high-risk address condition uses either-signal behavior. To require both signals:

  1. Add one Known high-risk address condition with only the historical risk levels selected.
  2. Add a second Known high-risk address condition with only This order is high risk selected.
  3. Set the rule to require All conditions.

The rule editor shows system rules separately. System rules are read-only and cannot be deleted.

Review blocked address edits

Open Address Validation > Analytics to review blocked risky address edits. The list shows the order, time, rule reason, and risk level without revealing shared network data.

After more than one unique risky address has been blocked, the home page also shows a fraud-prevention summary card with the number of affected addresses and orders.

Allow a legitimate address

If your team verifies that a blocked destination is legitimate, select Allow address beside the blocked attempt in Address Validation analytics.

The exception applies only to your store. It does not delete or change anonymous risk evidence for other merchants. Future lookups for your store omit that address while the allow decision is active.

Historical coverage

Order Editing refreshes risk evidence from Shopify each day. Stores that grant access to all orders can contribute up to one year of order history during a full import. Stores without that access use a shorter history window.

Once a high-risk or medium-risk assessment is recorded, a later lower-risk assessment does not remove that historical evidence. Each destination observed with the recorded risk remains available for matching, even if the order's shipping address later changes. Recorded evidence is retained for up to three years from its latest observation.

If a historically flagged address is legitimate, use Allow address to exclude it from future historical address matches for your store.

What customers see

For a default high-risk review, customers can save the address and see that the store will review the change. They do not see the underlying risk level, source merchant, prior order, chargeback, or network evidence.

When a merchant error rule or the chargeback rule blocks a save, customers see that the address change could not be completed. They do not see the underlying risk level, source merchant, prior order, chargeback, or network evidence.

Your staff can review the risk assessment and reason in Shopify before deciding whether to change the address manually.

Verify the setup

  1. Open the system rules in Address Validation and confirm the high-risk review rule and the past-chargebacks rule are active.
  2. Review any merchant error rules and confirm HIGH risk, medium risk, chargebacks, and This order is high risk are selected only where your store intends to block them.
  3. Open an existing eligible order and confirm a normal address correction can still be saved.
  4. If you have an approved internal high-risk fixture, confirm the address change saves and the order receives a Medium risk assessment without a hold or fraud tag.
  5. If you have configured a merchant error rule, confirm a matching save is blocked and the original address remains unchanged.
  6. For an error-rule block, review Address Validation analytics and the order risk assessment. For a current-order-only block, review the order risk assessment and admin warning.

Do not manufacture a chargeback or use another customer's payment details to test this feature.

Related articles

Compliance & Risk

Tax Recalculation

Choose how Order Editing handles tax-rate changes when customers update a shipping address.