Block a customer by email address

Updated · 4 min read

Create a rule for the exact address and any checkout using it is refused before payment. It takes a minute. The part worth reading is what happens next, because email is the easiest field in a checkout to replace.

Block the address

  1. Open the problem order in Shopify admin and copy the address from the contact details. Do not retype it from memory — a silent typo looks exactly like a working rule.
  2. Open Chargeback Blacklist, add a blocking rule, choose Email, paste, save. It is live immediately.
  3. Add the alias variants below while you are there.
  4. Test it in a private window. You should see a generic checkout error and no new order in admin.

Screenshot placeholder: the new blocking rule form with Email selected and an address filled in.

The aliasing problem

An email address is not one string. Several providers deliver a whole family of addresses to the same inbox, so a fraudster does not even need a new account to look new:

VariantWhat happens
[email protected]Gmail ignores dots, so the same inbox can be written many ways
[email protected]Everything after the plus is ignored on Gmail, Outlook, iCloud and others
[email protected]Gmail's alternate domain, same mailbox
[email protected]Disposable inbox — a signal in itself

You cannot win this by writing more email rules. Add the obvious variants, then add the fields they cannot regenerate for free: the phone number and the shipping address.

Block the email in a minute, then let the app close the gaps: every blocked checkout also bans the device and IP behind it.

Install Chargeback Blacklist

A new email does not get them back in

This is the question every merchant asks next, so here is the mechanism. When a checkout is blocked, the device fingerprint and IP address are banned automatically. The same person reloading the page with a brand new address is still blocked, because the browser and network are already known. They would need a different device and a different network as well. What still gets through covers the limits honestly.

Emails you have never seen

An email rule only knows the addresses that already burned you. The community blacklist checks the address against reports from other stores, so an email that is new to you but heavily reported elsewhere can be stopped on its first visit. You choose how many reports are required.

When email alone is genuinely enough

Plenty of blocking is not about fraud. An abusive customer, a serial returner who wants refunds on the same account, an ex-supplier placing orders to inspect your packaging — none of them are engineering aliases to get back in. One rule ends it quietly.

Deleting the customer in Shopify admin does nothing here. It removes your order history, not their access. Why account deletion fails.

FAQ

Can I block an email address from ordering on Shopify?
Not from Shopify admin. Deleting the customer account does not stop a guest checkout with the same address. With a checkout validation app you create a rule for the email and the checkout is refused before payment.
Is email matching case sensitive?
No. The rule matches regardless of capitalisation, so you do not need separate rules for [email protected] and [email protected].
What if they just make a new email address?
The first blocked attempt bans the device fingerprint and IP behind it, so the retry fails even with a new address. Adding the phone and shipping address from the same order closes the gap further.
Can I block a whole email domain?
Blocking a consumer domain like gmail.com would stop most of your real customers. Blocking a specific disposable-mail domain is occasionally justified — check your order history first.