Risk & payment — Rules2Tag presets
Fraud signals, cancellations and unpaid orders.
These are the tags for suspicious activity — orders and signups that look like fraud, card testing, bots or spam, plus the cancellations and unpaid orders that usually follow. Tagging them is the first step: a tag can be filtered, reported on, and handed to a checkout rule that blocks the next one.
Each of these is a ready-made rule you can adopt in one click inside Rules2Tag, then change however you like. Nothing runs until you say so, and every rule can be previewed against your own store first.
12 presets in this category
Customers using disposable email
I want to flag customers signing up with throwaway addresses
Tags a customer whose email is on a throwaway domain as fraud-suspected.
Why: A throwaway address is the cheapest signal that a buyer does not mean to be reachable, and it often comes before card testing and chargebacks. Shopify surfaces nothing about it. This app writes the tag and stops there — blocking is a separate job, and Ruleproof's "Block checkout for flagged customers" is the rule that refuses the next attempt.
Customers with automated email patterns
I want to flag signups that look generated rather than typed
Tags a customer whose email looks machine-generated as bot-suspected.
Why: Card testing and bulk signups reuse one mailbox through aliases — name+1@, name+2@ — or bolt digits onto a real-looking name. Both are visible in the address itself, and Shopify cannot filter on either. Tagged as a bot rather than as fraud on purpose: these are usually worth reviewing rather than refusing. This app only writes the tag — pair it with Ruleproof's "Block checkout for flagged customers" if you do want them refused.
Tiny first orders
I want to spot card testing in my orders, not just my signups
Tags a customer’s first order when it comes in under an amount you set.
Why: Card testing is a run of tiny charges looking for a card that works, and the first order from an address is where it lands. The email presets catch the signup; this catches the shape of the order itself, which is often the only thing a merchant notices. Tiny and first is a much narrower signal than either half alone — plenty of real customers try one cheap item, and plenty of tiny orders come from regulars.
Unusually large first orders
I want a second look at a big order from a brand-new customer
Tags a customer’s first order when it goes over an amount you set.
Why: Chargeback exposure concentrates in the orders you know least about, and a first order is the one with no history to judge it against. This is the opposite end of the same idea as tiny first orders: there the amount is suspicious because it is small, here because it is large for someone who has never bought from you. A genuine big first order is a good day, so this is a review signal rather than a refusal.
Customers whose last order was refunded
I want to know who to handle carefully next time they order
Tags a customer whose most recent order ended in the payment states you choose.
Why: A refunded last order is the single most useful piece of context a support agent can have before replying, and it is buried two clicks into a customer record nobody opens mid-queue. It is also the segment to exclude from win-back campaigns, which otherwise cheerfully invite someone back who just asked for their money back.
Customers whose last order was paid
I want to reach only people whose most recent order actually went through
Tags a customer whose most recent order reached a paid status.
Why: The positive counterpart to the refunded rule, and the safer base for anything that rewards a purchase: a loyalty point, a thank-you, an upsell. Awarding those off an order that was later refunded or never captured is the mistake this prevents.
Orders by payment method
I want to tag orders paid a particular way
Tags an order paid through any of the gateways you list.
Why: Payment method changes how an order is handled — manual methods need checking, some gateways carry more chargeback risk — and it is not something the order list lets you filter on.
Risky orders
I want to review orders Shopify thinks are risky before shipping them
Tags an order Shopify recommends you cancel or investigate.
Why: Shopify already computes a fraud recommendation, but it lives on the order page rather than anywhere you can filter or automate against. As a tag it can hold fulfillment.
Canceled orders
I want canceled orders kept out of my reporting
Tags an order that has been canceled.
Why: Canceled orders skew every filter and export they are left in, and tagging them is the simplest way to keep them out without deleting anything.
Orders canceled for a particular reason
I want to see WHY orders are being canceled, not just that they were
Tags a canceled order whose reason is one of those you list.
Why: Cancellations get counted together and mean completely different things: a customer changing their mind is a merchandising signal, a declined payment is a checkout problem, and fraud is neither. Separating them is the difference between a number and a diagnosis.
Orders still awaiting payment
I want to hold anything that has not actually been paid for
Tags an order whose payment is pending or only partially paid.
Why: Pending and partially-paid orders look like normal orders on a picking list, and shipping one is a straight loss. This is the flag a packer or a 3PL can be told to stop on, which "check the financial status column" is not.
Refunded orders
I want refunds visible without opening every order
Tags an order that has been fully or partially refunded.
Why: Refunds are the number your reporting is most often wrong about, because a refunded order still counts as an order everywhere it is not explicitly excluded. A tag makes them filterable in every tool that reads tags, including the ones that cannot read financial status at all.