Velocity Checks: Catching Rapid-Fire Fraud
Velocity checks flag suspicious bursts of activity — the same IP, card, or email hammering your checkout. Learn the signals that matter and how to set thresholds that stop fraud without hurting real shoppers.

Fraudsters rarely place a single order. When they get a stolen card or a working script, they test it fast — dozens of attempts in minutes, hopping between products, addresses, and payment methods until something sticks. Velocity checks are the counter-move: they watch how *often* a given signal appears in a short window and flag anything that spikes past a sane threshold.
If you run a Shopify store, velocity is one of the highest-signal, lowest-effort fraud controls you can add. Here's how it works and how to tune it.
What a velocity check actually measures
A velocity check counts occurrences of a shared attribute across a rolling time window. The classic example: five checkout attempts from the same IP address in ten minutes. A normal shopper doesn't do that. A card-testing bot does.
The two knobs are always the same:
- The signal — what you're counting (IP, card, email, etc.)
- The window and limit — how many events, over how long
Everything else is just picking good combinations of those two.
The velocity signals that matter
Different signals catch different attacks. The strongest programs layer several.
- IP velocity. Many orders from one IP in a short span usually means scripted card testing or a single bad actor churning accounts. Watch for both raw order counts and *failed payment* counts — card testers generate a flood of declines before a success.
- Card / payment velocity. The same card number (or fingerprint) trying multiple orders, or one order cycling through several cards, both scream fraud. A legitimate customer almost never needs three cards to check out.
- Email velocity. One email placing many orders quickly can be a reseller — or an account-takeover run. More telling: many different emails sharing a pattern (sequential names, same disposable domain) hitting checkout together.
- Shipping address velocity. A single "drop" address receiving orders funded by many different names and cards is a textbook reshipping fraud setup. Address velocity catches the mule even when every other detail looks clean.
- Device / cookie velocity. The same device fingerprint spinning up multiple "new" customers points to one person faking many identities.
The power move is cross-signal velocity: one card used across five emails, or one IP funding four different drop addresses. Any single number might look borderline; the combination rarely lies.
Setting thresholds that don't backfire
The hard part isn't detecting velocity — it's choosing limits that catch fraud without tripping on real life. Set the bar too low and you'll block a family sharing a café's Wi-Fi. Set it too high and testers slip through.
A practical approach:
- Baseline first. Before enforcing anything, look at your real order data. What does the *95th percentile* customer do? If almost no one legitimately places more than two orders per hour from one IP, that's your reference point — not a number you guessed.
- Leave headroom. Set the limit above your honest customers but below attack volume. If real shoppers top out around 2–3 orders/hour per IP and testers do 20+, a threshold of, say, 6 gives comfortable margin on both sides.
- Match the window to the behavior. Card testing happens in *minutes*, so a tight 5–15 minute window is ideal. Reshipping fraud plays out over *days*, so address velocity wants a longer 24–72 hour window.
- Prefer review over hard-block near the edge. For borderline velocity, flag for manual review or add friction instead of a flat rejection. Reserve outright blocking for egregious spikes.
Where Shopify merchants hit friction
A few real-world patterns cause false alarms if you're not careful:
- Shared networks. Corporate offices, universities, mobile carriers, and public Wi-Fi route many people through one IP. Pure IP velocity will over-flag them, so weight it alongside payment and email signals rather than acting on IP alone.
- Legitimate bulk buyers. Wholesale and B2B customers place many orders fast. Allowlist known good accounts so velocity rules skip them.
- Flash sales and drops. Traffic spikes compress everyone's activity. Consider relaxing windows during planned events, or exempting velocity on specific collections.
Because Shopify's native checkout doesn't expose fine-grained velocity controls, most stores lean on an app. Shieldy Fraud Filter runs velocity and IP/country/VPN/proxy checks at the checkout level via Shopify Functions, so a rapid-fire card-testing run gets stopped before the order is created — not caught after the chargeback lands. Its AI fraud-order scoring also blends velocity with device, email, and address signals so a single noisy metric doesn't decide the outcome on its own.
A quick starter configuration
If you're new to this, here's a sane opening posture to adapt to your data:
- Failed payments per IP: more than 4 in 10 minutes → block (strong card-testing signal)
- Orders per IP: more than 6 in 1 hour → review
- Distinct cards per email or per order: 3+ → review
- Orders to one shipping address from different names: 3+ in 48 hours → review
- Same device creating new customers: 3+ in 24 hours → review
Then watch your review queue for a week and tighten or loosen from there.
The takeaway
Velocity checks turn *speed* — the fraudster's biggest advantage — into their biggest tell. Start with the signals that map to your real attacks (IP and card for testing, address for reshipping), baseline against your own orders, and lean on review for the gray zone. Layer signals so no single metric can be gamed or misfire.
Want velocity, VPN/proxy, and AI order scoring working together at checkout without wiring rules by hand? See how Shieldy Fraud Filter is priced — there's a free plan to start.
Protect your Shopify store today
Install Shieldy free — block fraud, bots, and VPNs in under 5 minutes.
Install on Shopify — Free


