Skip to main content
Checkout blocklist stops orders from emails, domains, phone numbers, IP addresses and customer accounts you list. Blocked shoppers see one neutral message that never says why. Shows in: Checkout

Turn it on

  1. Go to WooCommerce → Powerups and click Configure on Checkout blocklist.
  2. Fill in the lists, click Save changes, and switch the power-up on.

Settings

How matching works

  • Phone numbers: formatting, a leading 0 or 00, and a country code in front don’t matter. A different area code never matches. Numbers under 7 digits are ignored.
  • IP addresses: lines that aren’t an address or a sensible range (wider than /8, or /16 for IPv6) are ignored and listed under the field. IPv4 addresses also match their ::ffff: form.
IP addresses change and can be shared, so blocking one can stop innocent shoppers.

Which IP address is checked

The blocklist checks the address connecting to your site. Behind a proxy or CDN (such as Cloudflare or a load balancer), that’s the proxy’s address. The IP WooCommerce shows on orders comes from forwarded headers, so the two can differ.
  • Don’t block the proxy’s IP: that blocks everyone.
  • Forwarded headers aren’t trusted by default, because anyone can fake them.
  • A developer can pass the real shopper IP with the apwc_blocklist_ip filter.

Where it checks

  • The classic checkout and the block checkout.
  • The classic “Pay for order” page.
It doesn’t check account sign-up, and it isn’t fraud scoring.

Blocked attempts

The Blocked attempts tab (also linked from the Powerups list) lists checkouts the blocklist stopped: the date, Blocked by (email, phone, IP address or account, with the entry that matched), the email and the IP address. It keeps up to 200 entries for 30 days.
  • Only placing the order is logged, not typing in the form.
  • The same attempt repeated within a minute is logged once.
  • One IP address adds at most 10 rows every 10 minutes. Further tries from it are counted on its latest row (“+3 more attempts”), so one address can’t push other attempts off the list.
  • Emails are kept up to 254 characters, other values up to 200.
The Blocked attempts tab with a few stopped checkouts

The Blocked attempts tab with a few stopped checkouts

Data

Last modified on September 28, 2026