Getting started — three steps
- Open Home and click "Import orders". It scores your last 60 days of orders through the same checks live orders get — up to 250, oldest first, so customer history builds in the right sequence. Tagging is off for the import by default.
- Open Settings and tune thresholds for your store — IP distance, duplicate window, units per order, how many names one phone may carry. Every threshold has a "How it works" popup with a worked example.
- Open Orders and check the Manual Review tab for anything that needs a human decision. Verified orders are the ones you shouldn't have to look at.
One approval Shopify needs first. Verifai reads names, phones, emails and addresses, which Shopify classes as protected customer data. The app shows a banner with the exact steps if the approval is missing; until it's granted, checks can't see the order and everything reports "skipped".
Verdicts — what the four words mean
- Verified — every check that ran passed. The app also tells you how many of the 12 actually ran, so "verified" is honest about its coverage.
- Manual Review — at least one check needs a human look. The reason is on the row.
- Rejected (High Risk) — a strong signal was found: a phone that's all one digit, a customer whose previous parcels came back, a prior order cancelled as fraud.
- Skipped — the order was never in scope. Almost always a prepaid order, which is already paid for. Counted in totals; no personal data is kept for it.
A check that says "skipped" is not a failure
Skipped means the check could not run — there was no data to check, or a vendor isn't configured — not that it failed. A skipped check is never held against the order. Two reasons are shown: not configured (you can fix it in Settings) and no data (the order didn't carry that field).
The 12 checks
All twelve run in parallel inside Shopify's webhook. One check throwing an error becomes a Review for that order — it never silently passes, and it never takes the other eleven down with it.
Phone
- Phone number is valid. Offline, every country. Fails on missing, unparseable, or invalid-for-country. Rejects line types a courier can't reach at the door — landline, VoIP, toll-free, premium, pager. A number that's a single repeated digit is the one thing here that's Rejected outright.
- Phone number is a live line. Carrier and line type from Twilio or Numverify with your key; a free North-America block lookup with none. Flags numbers carriers have blocked for SMS-pumping abuse — checked first, because a rented burner looks like a normal mobile on every other field.
- Phone is registered on WhatsApp. Informational only — it drives a badge on the row and is never used to hold an order. Needs your own WhatsApp checker (see Integrations).
- Phone is not shared across identities. Distinct names and addresses behind one number, counted from your own store only. Defaults: 3 names, 4 addresses.
Email
- Email is valid and not mistyped. Syntax → known typo domains (
gamil.com, with a "did you mean") → a 3,500-domain disposable-mail blocklist with a live fallback → a DNS MX lookup. A domain with no MX records is provably undeliverable. With a ZeroBounce or Kickbox key, the mailbox itself is checked; only a definite "no" fails.
Address
- Address is complete enough to deliver. Street, city, postal code and state present, and not "too thin" — under 10 characters or 3 words across both address lines.
- Postal code matches city and state. Strict format rules for 17 countries, then a lookup against a ~100-country postal table. Postal data records the local delivery office rather than the city people type, so the check matches every name a code goes by — branch, district and locality — and a code covering twenty offices still matches. Needs the postal dataset imported once.
- A landmark was provided. Only runs if your store collects one. Verifai ships a checkout extension that adds the field under the address form (Shopify Plus); on other plans, any order attribute named "landmark" works. "Near" and "opp." are too vague to count.
Behaviour
- Quantities look reasonable. Total units above your ceiling (default 10). Empty orders and impossible quantities fail.
- Not a duplicate. Same basket from the same identity inside the window (default 24 h), or three orders from one identity in that time.
- IP is near the delivery address. Distance between the IP's location and the postal code's coordinates, against your threshold (default 500 km). A different country is its own case, flagged for review and never Rejected — a gift from abroad is ordinary. Needs the free GeoLite2 database.
- No RTO or cancellation pattern. The one check that Rejects on its own: a prior order cancelled as fraud; two or more parcels sent and lost (RTO or cancelled after dispatch); or two cancellations and no delivery.
The risk score
Alongside the verdict, every order gets a 0–100 score. Each check that fails contributes a fixed number of points from a named rule — Invalid phone +40, Duplicate order +30, Postal-code mismatch +25, Email typo +10, and so on. Only the single highest factor in each category counts, so one bad field can't be charged twice. The total is capped at 100.
- 0–30 Verified · 31–70 Manual Review · 71–100 Rejected
Hover the score on any row to see the breakdown. Every calculation is written to an audit log with the old score, the new score, and why it changed.
Which decision wins? The verdict on the order comes from the checks themselves — any Rejected-level failure → Rejected; any failure → Review; else Verified. The score is the explanation and the ranking, shown alongside.
The queue
Home is the queue. Ten clickable stat cards filter it — Total, Verified, Rejected, Manual Review, Location mismatch, Invalid phone, Invalid email, Invalid address, Duplicates, Cancelled/RTO. An order can carry more than one issue, so the cards don't sum to the total.
- Tabs: Risk · Review · Verified · Awaiting outcome · Skipped · All. Search by order number, customer, city or product.
- Row actions: Quick Approve, Quick Reject, Mark RTO. Rejected orders get a Restore action that re-derives the verdict from the score.
- Bulk: select rows → Approve / Review / Reject / Export Selected.
- Export CSV: 18 columns including risk score and the hold reason, for the filtered set or your selection. Opens cleanly in Excel.
- Fix in place: open an order, click a red field, correct it. The correction is checked locally first — it won't let you save a postal code that still doesn't match the city — then written to the real Shopify order and re-scored in the same click.
- Overrides are final. Once a person approves or rejects an order, a later re-run records fresh evidence next to that decision but never overturns it.
Products
The Products screen answers a warehouse question: how many of each item can be packed today? Live catalogue with Confirmed / Review / Rejected / Not checked counts and a confirmation rate per product. "Not checked" is prepaid, shown in grey and never folded into Rejected.
Settings
Changes apply to all new orders instantly. Defaults, with what each one does:
- IP distance threshold — 500 km. Generous on purpose: mobile carriers route through regional gateways and VPNs are common. Expect to widen it, not narrow it.
- Flag orders placed from another country — on. Review-only.
- Duplicate order window — 24 hours.
- RTO strikes for high risk — 2 lost parcels.
- Maximum units per order — 10. Set 0 to disable.
- Names / addresses / orders per phone number — 3 / 4 / off.
- Hold orders whose phone is from another country — off.
- Also verify prepaid orders — off. Turn on only if prepaid fraud is a real problem for you.
- Write tags to Shopify orders — on. Turning it off cleans up the tags Verifai already wrote.
- Auto-tag verified orders — off. Failing orders are still tagged; only the "everything's fine" tag is withheld until you trust it.
Settings also shows what the app can actually see: whether the GeoLite2 database and postal dataset are present, whether a landmark has ever arrived on an order, which payment gateways it has classified as COD or prepaid, and which couriers you actually ship with.
Integrations
Four cards, each with a provider selector, key fields, a Test Connection button and a live status. Keys are encrypted at rest with AES-256-GCM and never shown back — the page only tells you whether one is saved. Leaving a field blank keeps the existing key.
- Live email mailbox verification — ZeroBounce or Kickbox.
- Phone carrier & line intel — Twilio Lookup or Numverify.
- WhatsApp number verification — a self-hosted checker on your own number (a shared linked number would be a ban target).
- Courier RTO tracking — Shipway. Shipments are pushed on fulfillment; delivery and RTO status reads back.
Two datasets are self-hosted, not vendors: MaxMind GeoLite2 (free account, one download) for IP location, and the GeoNames postal file (free, imported once) for postal-code matching and delivery coordinates. Neither is bundled; both are free.
Every adapter follows three rules: never throw, never block (hard timeouts), and only a definite negative fails a check.
Outcomes & RTO
Shopify has no concept of a parcel coming back. Verifai records the outcome of every shipped order three ways, and the customer-history check reads it on the next order from that person:
- Manually — "Mark Delivered" / "Mark RTO" on the order.
- From Shopify — cancellation and fulfillment webhooks. A cancel after dispatch counts like an RTO. A cancel for inventory or declined doesn't count at all — that was the store, not the customer. A cancel marked fraud outranks everything.
- From the courier — Shipway.
RTO is the final word: a "delivered" scan followed by a return is recorded as a return.
Plans & billing
Four plans — Free, Starter ($9), Growth ($29), Plus ($79) — billed through Shopify, cancellable any time from the Plans page with unused time prorated. Paid plans start with 14 days free. The offline checks are free on every plan; paid plans add the live vendor lookups and CSV export.
Troubleshooting
Every order says "skipped"
Almost always the protected-customer-data approval. Home shows a banner with the exact Partner-dashboard steps when this is the cause.
The landmark check skips on every order
Your checkout isn't collecting one. Home shows a nudge with a link to Checkout settings when this has been true for the last 30 orders.
Import failed
The banner shows Shopify's actual reason rather than a bare error code. Most often it's the approval above; occasionally it's the 60-day read window — the Free and Starter scopes can't see orders older than that.
A verdict looks wrong
Hover the score for the per-rule breakdown. If a field is wrong, fix it in place and it re-scores. If the rule is too strict for your store, the threshold is in Settings with a worked example.
I turned off tags but old ones are still there
Turning tagging off strips the tags Verifai wrote on the next update to each order. It only ever removes its own eight; anything else on the order is yours.
Still stuck? Contact us with the store handle and order number.