Minimize risk and secure your online payments by learning how Checkfront’s security measures help block repeated failed payment attempts and deter fraud.
Learn several ways that Checkfront prevents fraudulent payments.
Accessing the features mentioned in this article
Where can I find this feature using the top menu?
-
{your account}.checkfront.com/reserve> Payment page
Which Checkfront version supports this feature - classic items, classic products, or both?
- This feature is available in both our classic version using classic items (Inventory > Items) and our classic version using classic products (Inventory > Products). → Learn more about products
Overview
To prevent fraudulent use of the payment pages, Checkfront has several security measures in place, including protection against carding bot attacks, in which attackers make multiple parallel attempts to authorize stolen credit card credentials using your payment forms.
- The system automatically blocks payments for a Booking ID after 10 failed attempts. After 24 hours, the system unblocks the payment for the Booking ID.
- The system blocks payments for all bookings from an IP address after 20 failed attempts. The system then unblocks payments for that IP address after 24 hours.
Frequently Asked Questions
What error message is shown to the User when a Booking ID or IP is blocked?
The following error message displays. The error message includes your company phone number if it is configured in your account (Manage > Setup > Company > Phone number).
You have reached the limit of failed payment attempts, please contact {$Company_Name} at {$Phone} to complete the booking.”
Can an Admin or Staff Member remove the block?
No, you cannot remove the block, but you can attempt to process the payment Staff-side on behalf of legitimate Customers if they reach out.
If the payment processor continues to decline the payment, you can let the Customer know why their card has been declined (e.g., expired card) and how to resolve the issue (e.g., reach out to their card-issuing bank). You can also offer to complete payment using a different payment method.
|
Activating reCAPTCHA For added security on your payment pages, we recommend activating reCAPTCHA v3 for a more secure payment flow. reCAPTCHA v3 is only available on certain payment providers: Braintree, Moneris, Stripe, and Square). Learn more here: |