Block VPNs Without Killing Conversions
VPN traffic hides fraud — but plenty of real shoppers use VPNs too. Learn when to challenge versus hard-block, how to allow legitimate VPN users, and how to measure the impact.

Blocking VPNs feels like an easy fraud win. Anonymizing traffic does hide a disproportionate amount of card testing and fraud — but here is the uncomfortable truth: millions of ordinary shoppers browse with a VPN always on. Privacy-conscious users, corporate laptops, travelers, and people in regions where VPNs are simply the default. Hard-block all VPN traffic and you will stop some fraud and quietly delete real revenue.
The goal is not to block VPNs. The goal is to neutralize the risk VPNs carry while keeping legitimate VPN users buying. That is a tuning problem, not an on/off switch.
Why "block all VPNs" backfires
- VPN adoption is mainstream. A meaningful slice of everyday traffic is on a consumer VPN at any given moment. Blocking it blocks paying customers.
- VPN alone is a weak fraud signal. A shopper on NordVPN with a matching billing address and a normal cart is not a fraudster. The VPN is the least interesting thing about that order.
- Hard blocks are invisible losses. A blocked legitimate customer rarely emails you — they just leave and buy elsewhere. You never see the cost, which makes over-blocking dangerously easy to ignore.
The mistake is treating "uses a VPN" as a verdict. It is one input among many.
Challenge versus hard-block
The single most useful distinction in VPN handling is challenge versus hard-block.
- Hard-block — the order or checkout is stopped outright. Reserve this for traffic that is almost never legitimate: Tor exit nodes, known anonymizing proxies, and datacenter IPs. These belong to infrastructure, not shoppers. Blocking them costs you almost nothing.
- Challenge — you allow the shopper to proceed but apply extra scrutiny: flag the order for review, require verification, or lean on the rest of the risk signals before fulfilling. This is the right default for consumer VPNs.
Put simply: hard-block the anonymizers, challenge the VPNs. A tool like Shieldy — Fraud Filter distinguishes VPN, proxy, Tor, and datacenter traffic separately, so you can hard-block the genuinely-bad categories at checkout while treating consumer VPNs as a flag rather than a wall.
How to let legitimate VPN users through
A VPN order that clears every other check should sail through. Combine the VPN flag with corroborating signals and only act when several line up.
Treat a VPN order as low-risk when:
- Billing and shipping addresses match.
- It is a returning customer with prior clean orders.
- The AOV is normal for your store.
- The email and name look legitimate and consistent with the card.
- There is no velocity anomaly (not one of ten rapid orders from the same source).
Escalate a VPN order to review only when the VPN stacks with:
- A billing/shipping country mismatch.
- An unusually high AOV or multiple high-value items.
- Multiple failed payment attempts before success (card testing).
- A shipping address flagged as a freight forwarder or reshipper.
- A brand-new customer expediting shipping on a large first order.
One flag plus a VPN is usually fine. Two or more plus a VPN earns a hold-and-verify.
Segment before you decide
Not every store should treat VPNs the same way. Look at your own data first:
- High-VPN, low-fraud stores (privacy-focused audiences, tech products) should lean toward *challenge* and almost never hard-block VPNs.
- High-AOV stores can afford a bit more friction — a verification email on a VPN order is cheap insurance on a $600 cart.
- Low-margin, high-volume stores should minimize friction; over-blocking a few percent of checkouts can erase the month's profit.
Pull your last 90 days: what share of orders came from VPN IPs, and what was the chargeback rate on those specifically? If VPN orders charge back at the same rate as everything else, you have no reason to block them at all.
Measuring the conversion impact
Any VPN rule change is an experiment. Measure it, or you are guessing.
Before you change anything, record your baseline:
- Overall checkout conversion rate.
- Conversion rate on VPN-flagged sessions specifically.
- Chargeback rate on VPN orders.
- Support tickets mentioning "can't check out" or "payment declined."
After the change, watch for:
- A drop in overall conversion → your rule is catching real customers. Loosen it.
- A rise in "can't check out" tickets → same signal, from a different angle.
- No change in chargeback rate but lower conversion → you added friction with zero fraud benefit. Reverse it.
- Lower chargebacks with steady conversion → the change is working. Keep it.
Change one rule at a time and give it at least two weeks. If you flip five settings at once, you will never know which one moved the numbers.
A sensible default configuration
If you want a starting point to tune from:
- Hard-block: Tor, anonymizing proxies, datacenter/hosting IPs, and countries you do not ship to.
- Challenge (flag for review): Consumer VPN + any one additional risk signal.
- Allow: Consumer VPN on an otherwise-clean order from a returning customer with matching addresses.
- Velocity guard: Cap orders per IP regardless of VPN status to catch card testing.
This stops the traffic that is almost always malicious, scrutinizes the genuinely-ambiguous, and gets out of the way of real shoppers who happen to value their privacy.
The takeaway
VPN handling is about precision, not aggression. Hard-block the infrastructure that no real shopper uses, challenge the consumer VPNs by stacking them against other signals, and measure every change against conversion — not just chargebacks.
If you want checkout-level control that separates VPN, proxy, Tor, and datacenter traffic so you can block the right categories and merely flag the rest, Shieldy — Fraud Filter is built for exactly that. Start on the free plan and see the pricing options as you dial in your rules.
Protect your Shopify store today
Install Shieldy free — block fraud, bots, and VPNs in under 5 minutes.
Install on Shopify — Free


