Shopify has no native button to block a customer, and the tools it does offer are built around card-payment signals that do not exist on a cash-on-delivery order. On COD the identity that matters is the phone number, not the email, and the loss is a returned parcel rather than a chargeback. Blocking has to happen against delivery history, before dispatch.
Most COD stores have a short list of phone numbers they recognise on sight. The same buyer orders, refuses the parcel, and orders again three weeks later. Everyone in the team knows the name. Nothing in Shopify stops the next order.
If you search for how to block a customer on Shopify, you will find plenty of guides. Almost all of them are written for a different problem — chargeback fraud, stolen cards, refund abuse. That advice does not transfer to cash on delivery, and following it leaves you unprotected.
This guide covers why, and what works instead.
Why Shopify’s Native Blocking Does Not Help COD Stores
Shopify genuinely does not have a block button on a customer profile. What it offers instead falls into three options, and each one breaks on COD for a different reason.
Disabling the customer account
This stops someone logging in. It does not stop them checking out as a guest, which is how the overwhelming majority of COD orders are placed. The buyer you disabled on Monday can order again on Tuesday without noticing anything changed.
Fraud Control and checkout rules
Shopify’s fraud analysis scores orders using signals like card verification results, billing and shipping address mismatches, IP location and repeated payment attempts. It is a genuinely useful system — for card payments.
On a COD order, none of those signals exist. There is no card, no billing address, no CVV, no payment attempt. The risk engine has almost nothing to work with, which is why COD orders so often come through as low risk right up until the parcel comes back. Shopify also retired its separate Fraud Filter app in January 2025, so older tutorials pointing you there are out of date.
Shopify Flow
Flow can auto-cancel or hold orders matching a tag you maintain. That is closer to useful, but it acts after checkout, and it only knows what you have manually tagged. It is a rule engine, not a memory — it cannot tell you that this phone number has refused three parcels, because nothing in Shopify tracks that.
Card Fraud and COD Abuse Are Different Problems
This is the distinction almost every guide misses.
| Card fraud | COD abuse | |
|---|---|---|
| Identity to block | Email, card, IP | Phone number |
| Signal available | AVS, CVV, IP, payment history | Delivery history only |
| How you lose money | Chargeback after delivery | Shipping paid both ways, never collected |
| When it is detectable | At checkout | Only after a delivery attempt |
| Where to intervene | Payment authorisation | Before dispatch |
| Usual intent | Deliberate fraud | Impulse, indecision or forgetting |
That last row matters more than it looks. Most COD losses are not fraud. They come from ordinary customers who ordered on impulse, forgot, or changed their mind and had no consequence-free way to say so. Treating them as criminals leads to over-blocking, which quietly costs you real revenue.
The Phone Number Is the Real Identity
On COD, email addresses are close to meaningless. Many buyers enter one only because checkout requires it, and a shopper who wants to slip past a blocklist changes their email in seconds.
The phone number is different. It has to be real, because the courier calls it to deliver the parcel. That single constraint makes it the only reliable identifier a COD store has, and it is the field your blocking should be built on.
It also means the history worth tracking is not order value or basket contents. It is what happened to the parcels — cancellations after confirmation, refusals at the door, unanswered confirmation requests, returns after delivery. None of that lives in Shopify natively, because Shopify has no concept of a delivery outcome tied to a customer record.
What Actually Counts as a Problem Customer
Before blocking anyone, be honest about what you are measuring. A customer who cancelled once is not a problem customer. A customer who cancels before dispatch is arguably doing you a favour, because a cancellation costs one message while a refusal costs a round trip.
Reasonable signals, roughly in order of severity:
- Refused a delivered parcel more than once. The strongest signal available. Each instance is a confirmed round-trip loss.
- Multiple failed attempts across separate orders. Distinguish this from one order failing three times, which is usually a courier or address problem rather than a customer problem.
- Confirmed on WhatsApp, then refused at the door. Worse than never replying, because you shipped on an explicit yes.
- Returns after delivery, repeatedly. Especially where the product comes back used.
- Never responds to confirmation but keeps ordering. Weak on its own; meaningful combined with failed deliveries.
What should not trigger a block: a single cancellation, an order that failed once for an address error, or a customer who asked a lot of questions. Over-blocking is a real cost that never appears in any report, because you never see the orders you refused to accept.
A Tiered Response Instead of a Blocklist
Blocking should be the last step, not the first. A graded response protects margin without throwing away customers who are merely inconsistent.
- Watch. One cancellation or one failed delivery. Do nothing except record it. Everyone has a bad week.
- Confirm harder. Two incidents. Do not dispatch this customer’s orders without an explicit confirmation reply. No reply means no parcel.
- Require prepayment. Three incidents. Accept the order, but ask for payment up front. This is the most underused tier — it keeps the customer while removing your exposure entirely.
- Block. A sustained pattern with no explanation. Stop accepting orders and get alerted if they try again.
Tier three is where most of the value sits. A customer who has refused two parcels is not necessarily malicious, and offering prepayment converts your riskiest orders into guaranteed revenue rather than lost revenue.
What You Can Do Natively Today
If you are not using any app, this is the best available manual process:
- Tag customers consistently. Agree a small fixed set — something like watch, confirm-first, prepaid-only, blocked. Inconsistent tags are worse than none, because nobody trusts them.
- Always write a note explaining why. A tag with no reason is unusable in three months and impossible for a colleague to act on. Record the order number and what happened.
- Check tags before packing, not after. A tag caught at dispatch saves the shipping cost. A tag caught afterwards saves nothing.
- Search by phone number, not name. Names get spelled differently across orders; numbers do not.
This works at low volume and collapses somewhere around 30 to 50 orders a day, because it depends on a human remembering to look.
How ConfirmQ Handles Customer Blocking
Fake order detection scores each customer against their own history — cancellations, returns, failed deliveries and unanswered confirmation requests — rather than against card signals that do not exist on a COD order. The score sits on the order before you pack it.
You set the threshold. Cross it and the customer can be blocked outright, and if a blocked number orders again you get a WhatsApp alert instead of a silent loss. Internal staff notes attach to the customer record, so the reason travels with them and your team is not relying on memory.
Because the history is built from confirmation responses and shipment outcomes, the record reflects what actually happened to each parcel — who confirmed, who cancelled, who never replied, and which deliveries failed. That is the data Shopify does not keep.
Reports and analytics then shows the aggregate: how many customers are flagged, how many orders were blocked, and what those blocks saved you. Blocking without measurement is guesswork, and it is how stores end up over-blocking without noticing.
Mistakes That Cost Money
Blocking on one incident. The single most common error. One refusal is noise, not a pattern.
Blocking without a note. In two months nobody will remember why, and someone will either unblock a genuine repeat offender or keep a good customer locked out.
Never reviewing the list. Circumstances change and phone numbers get reassigned. Review quarterly.
Treating blocking as the whole solution. Blocking only helps with customers who have already cost you money. It does nothing for a first-time buyer about to refuse their first parcel. That is what confirmation before dispatch is for. Blocking handles the tail; confirmation handles the volume.
Announcing the block. There is nothing to gain from telling someone they are blocked. Stop accepting the orders and move on.
Where to Start
Pull your last three months of failed and returned orders and group them by phone number. Most stores find a small group of numbers accounting for a disproportionate share of the damage — and it is almost always fewer people than expected, which is good news, because the fix is narrow.
Apply the prepayment tier to that group first. Only block the ones who keep failing after that. Then measure the difference over the following month, using the same failure-cost figures you started with.
Frequently Asked Questions
There is no native block button on a customer profile. You can disable a customer account, which prevents login but not guest checkout, and you can use tags with Shopify Flow to cancel or hold matching orders after checkout. For cash on delivery, neither approach stops the order being placed.
Shopify’s risk scoring relies on payment signals such as card verification results, billing address matching and IP data. A cash-on-delivery order has no card and no payment attempt, so most of those signals are absent and COD orders frequently appear low risk regardless of the customer’s history.
Phone number. Many COD buyers enter an email only because checkout requires one, and it is trivial to change. The phone number has to be genuine because the courier calls it to arrange delivery, which makes it the most reliable identifier available.
There is no universal number, and a single incident is rarely enough. A practical approach is to escalate gradually: record the first incident, require confirmation before dispatch after the second, require prepayment after the third, and block only on a sustained pattern.
Prepayment first in most cases. It removes your exposure completely while keeping a customer who may simply be indecisive rather than malicious. Blocking discards the revenue entirely, so it makes sense only once prepayment has been offered and the pattern continues.
It helps with the concentrated tail — the small group of repeat offenders responsible for a disproportionate share of failed deliveries. It does nothing for first-time buyers, who make up most COD volume, so blocking works alongside confirmation before dispatch rather than replacing it.
Want blocking that works on COD? ConfirmQ scores every customer against their own delivery history, blocks repeat offenders by phone number, and alerts you if a blocked customer orders again. Install ConfirmQ from the Shopify App Store or view pricing plans.
Related: How to Identify Fake Orders on Shopify: 9 Warning Signs

