Cash-on-delivery verification for Shopify

Every COD order checked,
before it ships.

Verifai runs 12 checks on each cash-on-delivery order the moment it lands — phone, email, address, duplicates, IP distance, order history — scores it 0–100, and tags it Verified or Manual Review right on the Shopify order. You only look at the ones that need a human.

.myshopify.com

Free plan, no card. Paid plans include a 14-day trial.

Runs inside Shopify's 5-second webhook window Vendor keys AES-256 encrypted Postal & phone rules for ~100 countries PII auto-purged after 180 days
#1042 Cash on delivery · $128.00 · Sacramento, US
Manual Review
60 out of 100
12 checks ran4 flagged0 skipped
ZIP 90210 is Beverly Hills, address says Sacramento+25
Same basket and address ordered 3 hours ago+15
Email domain gamil.com — did they mean gmail.com?+10
Address too vague to deliver — "Main Street"+10
+1 415 555 0142 — valid mobile, T-Mobile0
0–30 Verified31–70 Manual Review71–100 Rejected
The problem

COD parcels come back, and you pay both ways.

Cash-on-delivery is how a large part of the world buys. It's also how a store pays outbound shipping, pays return shipping, loses the sale, and ties up stock — on an order that was never going to be delivered. Most of those orders looked wrong from the first second.

The phone rings out

A landline, a VoIP number, a burner that carriers already blocked for SMS pumping, or just 9999999999. The courier can't reach anyone at the door, and the parcel turns around.

The address doesn't exist

A postal code for one city with a street in another. No apartment number. A "Flat 3" with no building. Deliverable to no one, and nobody finds out until the parcel has already travelled.

You've seen this customer before

The same basket twice in an hour. The same phone number behind four different names. A customer whose last two parcels came back. Shopify remembers none of it.

How it works

Four steps, inside the webhook.

No queue, no polling, no "check back in a minute". Verifai runs its checks in parallel the moment Shopify sends the order and writes its verdict back before the merchant has opened the notification.

Step 1

Order arrives

Name, phone, email, address, IP and payment method — straight from Shopify's orders/create webhook.

Step 2

Checks run

All 12 checks execute in parallel. One check failing can't take the others with it — each one reports for itself.

Step 3

Verdict decided

Verified, Manual Review or Rejected, with a 0–100 score and a plain-English reason on every check.

Step 4

Tag written back

Straight onto the Shopify order, so it shows up in the filters and workflows you already use.

Prepaid orders are counted, not checked. They're already paid for — holding one for review costs a sale and protects nothing. Verifai scopes itself to COD by default, and treats an ambiguous gateway as COD rather than silently skipping a real one.
The checks

Twelve questions, asked of every order.

Most run offline for free. A few can use a paid vendor for a sharper answer — with your own key, never a shared one. And if a key is missing or a vendor is down, the check skips. It never holds an order over Verifai's own plumbing.

Phone

Free

Is the number real?

Parsed against every country's numbering plan. Catches repeated digits, landlines, VoIP, toll-free and premium lines — none of which a courier can reach at the door.

Your key

Is the line live?

Carrier and line-type lookup via Twilio or Numverify. Flags numbers carriers have blocked for SMS-pumping abuse — the burner that looks fine on every other field.

Your key

On WhatsApp?

Whether the number is registered on WhatsApp — a strong sign a real person is behind it. Shown as a badge on the order; never used to hold one.

Free

Shared across identities?

One number behind three names or four addresses is a pattern worth a look. Counted from your own store's history, and only yours.

Email

Free

Valid, not mistyped, not disposable

Four tiers, cheapest first: syntax → known typos (gamil.com, with a "did you mean") → a 3,500-domain disposable-mail blocklist with a live fallback → a DNS MX lookup that proves whether the domain accepts mail at all.

Your key

Does the mailbox exist?

Live deliverability via ZeroBounce or Kickbox. Only a definite "no" fails the check — catch-all and unknown domains pass, so a strict vendor never costs you a real customer.

Address

Free

Complete enough to deliver?

Street, city, postal code, state — and a "too thin" test for the address that technically has all four but reads as "Main Rd".

Free dataset

Does the code match the city?

ZIP, PIN, postcode, CEP — strict format rules for 17 countries, then a lookup against a ~100-country postal table. It knows every name a code goes by, so a code covering twenty delivery offices still matches the city your customer actually typed.

Free · Plus

Is there a landmark?

Shopify has no landmark field. Verifai ships a checkout extension that adds one under the address form. "Near" and "opp." don't count. Requires Shopify Plus at checkout; a theme field works elsewhere.

Behaviour

Free

Does the quantity look right?

Forty units of one SKU on a first order is a question, not an order. You set the ceiling.

Free

Is it a duplicate?

The same basket from the same identity inside your window — 24 hours by default — or three orders from one person in that time.

Free dataset

Is the IP near the address?

Self-hosted GeoLite2, so the customer's IP never leaves your infrastructure. A different country is treated as its own case — a gift from abroad isn't "far", it's international.

Free

What happened last time?

Two parcels sent and lost. Two cancellations and no delivery. A prior order cancelled as fraud. The one signal that predicts RTO better than anything else.

The risk score

A number you can argue with.

Every order gets a score from 0 to 100. Every point on it comes from a named rule with a fixed weight — Invalid phone, +40. Duplicate order, +30. Postal-code mismatch, +25. Only the worst factor in each category counts, so one bad field can't be double-charged.

That's the whole point. When a merchant asks in three weeks why order #1042 was held, the answer is in the row — not in a model nobody can explain. Every score change is written to an audit log with what changed and why.

0–30
Verified
31–70
Manual Review
71–100
Rejected
Orders · Manual Review
#1046
R. Sharma · Mumbai, IN
82 · Invalid phone (0000000000) · 2 previous parcels returned
Rejected
#1042
E. Kowalski · Sacramento, US
60 · ZIP 90210 is Beverly Hills, address says Sacramento · +3 more
Manual Review
#1041
A. Rahman · Dubai, AE
40 · Phone shared across 3 names · order IP 4,100 km from address
Manual Review
#1040
S. Moreno · Madrid, ES
0 · Repeat customer — verified 4 months ago, no lookups spent
Verified
#1039
J. Thornton · Manchester, GB
0 · All 12 checks passed · postcode M1 4BT matches city
Verified
Order #1042 · Customer details
Phone+1 415 555 0142
CitySacramento
ZIP90210 → 95814
Editing ZIP — checked locally before it's written to Shopify
Save & re-verifyCancel
Fix it where you see it

Correct the order without leaving the queue.

A wrong postal code is usually a typo, not fraud. Click the red field, type the right value, and Verifai checks the correction before it touches the order — it won't let you save a code that still doesn't match the city. Then it writes the fix to the real Shopify order and re-scores it in the same click. No separate "re-verify" step, no round trip to the admin.

Overrides are final. If a person approves or rejects an order, a later re-run records fresh evidence alongside that decision, but never overturns it. Someone looked at it — that outranks any rule.

The outcome loop

Shopify doesn't know a parcel came back. Verifai does.

Shopify has no concept of return-to-origin. An RTO'd order just sits there, fulfilled. Yet "this customer's last two parcels came back" is the single strongest predictor of the next one doing the same — so Verifai builds that history itself, three ways, and reads it on every future order from the same person.

Mark it yourself

One click on the order — "Delivered" or "Came back". The return is recorded as a strike against that customer's history.

Shopify tells us

Cancellation and fulfillment webhooks record the outcome automatically. A cancel after dispatch counts like an RTO. A cancel because you were out of stock doesn't count at all — that was you, not them.

The courier tells us

Connect Shipway and every shipment is pushed to it on fulfillment. Delivery and RTO status flows back into Verifai — 500+ couriers, no per-courier integration.

Integrations

Your keys. Your vendors. Optional, every one.

Verifai never routes your customers' data through a shared vendor account. Bring your own key for any of these and the matching check gets sharper. Leave it out and the check simply reports itself skipped.

Twilio · Numverify

Carrier, line type, and Twilio's SMS-pumping risk signal. A free North-America block lookup runs even with no key.

ZeroBounce · Kickbox

Live mailbox verification. Results cached 90 days under a hash of the address, never the address itself.

WhatsApp

Whapi.Cloud, 2Chat, or a self-hosted checker on your own number — because a shared linked number would be a ban target.

Shipway

Courier-agnostic tracking. Shipments pushed on fulfillment; delivered / RTO outcomes read back.

MaxMind GeoLite2

IP geolocation, self-hosted from a free MaxMind account. No per-call cost, no third party in the webhook path.

GeoNames postal data

~100 countries of postal codes with coordinates, imported once. The only source of a delivery coordinate — Shopify doesn't geocode.

Every connection has a "Test" button and a live status. Keys are encrypted at rest with AES-256-GCM and never shown back after saving — Settings only tells you whether one exists.
Built right

Built the way a store's data should be handled.

Inline, under 5 seconds

All 12 checks run in parallel inside Shopify's webhook budget. No background queue means no "verified 20 minutes later".

Repeat customers skip the line

Same phone, email and address as an order you verified in the last 6 months? Verified instantly, and not a single paid lookup spent.

Touches only its own tags

Eight tags, added and removed additively. A tag Verifai didn't write is yours, and not its to touch. Turn tagging off and it cleans up after itself.

Forgets on a schedule

Personal data is purged after 180 days, automatically, every 12 hours. The verdict stays; the person doesn't.

Hashes, not contact details

Vendor caches are keyed by SHA-256, so they can never become a second, unpurged copy of a customer's phone or email.

GDPR webhooks, all three

Data request, customer redact, shop redact — implemented, and they deliberately don't swallow errors.

Compared

Verifai vs. a typical "AI fraud" app

Most order-risk apps hand you a number and a confidence percentage. Ask why and you get a shrug. Verifai is deterministic on purpose.

VerifaiTypical AI-scoring app
Why this order got its scoreNamed rule + fixed points per factor"Model confidence 94%"
Same order, same score, every timeYes — deterministicVaries with the model
Fix a typo and re-check from the queueYes, pre-validated, one clickEdit in admin, wait for re-sync
RTO history from your courierYes — Shipway, 500+ couriersRarely
Vendor keysYours, encrypted, never shown backShared account, opaque
Customer IP locationSelf-hosted — never leaves your serverSent to a third-party API
A missing key or vendor outageCheck skips; order never heldOften blocks or errors
Prepaid ordersCounted, never heldChecked like COD, held like COD
Audit trail per score changeYesUsually not
Pricing

Start free. Pay when the vendors do.

The offline checks — phone format, email typos, address, postal code, duplicates, history — are free forever. Paid plans add the live vendor lookups and export. Every paid plan starts with 14 days free.

Free
$0forever

For testing, and for a new store starting out.

Install free
  • Phone syntax & range validation
  • Email syntax, typo & DNS MX check
  • Address & postal-code verification
  • Duplicate order detection
  • Manual review queue & Shopify tagging
Starter
$9/ month

For a store just getting started with COD verification.

Start trial
  • Everything in Free
  • Phone-shared-across-names detection
  • Automated Shopify tagging
  • Export verification logs to CSV
  • 14-day free trial
Plus
$79/ month

For a high-volume store that wants every signal.

Start trial
  • Everything in Growth
  • Live carrier & network lookups
  • VoIP & virtual-number detection
  • Priority verification support
  • 14-day free trial

Billed through Shopify. Cancel any time from the Plans page; unused time is prorated.

FAQ

Answers before you install.

Does Verifai block or cancel orders?
No. It tags them. An order Verifai isn't sure about gets a Manual Review tag and a reason; a strongly bad one gets High-Risk Customer. Fulfilment is still your decision, made from a queue that's sorted so the risky ones are at the top.
Why is a prepaid order marked "Skipped" instead of checked?
Prepaid orders are already paid for, so holding one for review costs a sale and protects nothing. Turn on "Verify prepaid orders" in Settings if prepaid fraud becomes a real problem for you.
A check says "skipped" — is that a failure?
No. Skipped means the check could not run — there was no data to check, or a vendor isn't configured — not that it failed. A skipped check is never held against the order, and the queue shows you how many of the 12 checks actually ran.
Is this AI?
No, and that's deliberate. Verifai is a rule engine with fixed, visible weights. The same order gets the same score every time, and every point is traceable to a named rule you can read in the app. We think a merchant should be able to argue with the number.
What happens on an existing store with years of orders?
Click "Import orders" once and Verifai scores your last 60 days through the identical pipeline live orders get — up to 250 orders, oldest first, so customer history builds in the right sequence. Tagging is off for the import by default; writing tags to hundreds of historical orders isn't something you can take back.
Can I stop Verifai writing tags to my orders?
Yes — turn off "Write tags to Shopify" in Settings. Every check still runs and every verdict is still recorded, but nothing is written back to the order. Turning it off also strips the tags Verifai previously wrote.
Does the landmark field work on every store?
The checkout extension renders under the shipping address, which requires Shopify Plus. On other plans, a landmark field on the cart page or in your theme works the same way — Verifai reads any order attribute whose name contains "landmark". If you don't collect one, the check simply skips.
What does Verifai need from Shopify?
Read and write orders, read customers and fulfilments, read products. It also needs Shopify's protected customer data approval to read names, phones and addresses at all — a one-time request in the Partner dashboard that the app walks you through.
How long is customer data kept?
180 days by default, then the personal fields are blanked automatically — every 12 hours, without anyone having to remember. The verdict and the reason survive; they're your store's operating history and no longer contain a person. The window is configurable. Note it's also the app's memory for customer history.

Stop paying for parcels that come back.

Install on your store, import your last 60 days, and see what Verifai would have caught.