# How to Block a Customer on Shopify {#post-title}

[X Shield](/blog/#blog-x-shield)

By [B2B Gold](/about/#how-we-write) Published 24 September 2026 Updated 26 September 2026

## Can you block a customer on Shopify? {#can-you-block-a-customer-on-shopify}

Not with a single button. The closest thing is Shopify’s free Fraud Control app, which blocks checkouts by email, address or IP if you use Shopify Payments. Pair it with a Shopify Flow rule that cancels or holds their orders, and an IP or network block if they keep browsing, because each one alone is easy to get around.

> **Note:** The Shopify settings, labels and plan rules on this page were checked against Shopify’s help documentation on 26 September 2026. Customer accounts changed in 2026, so older advice about disabling an account may not match your admin.

“Blocking a customer” can mean four different things, and each acts at a different moment:

| What you want | Shopify tool | When it acts | Needs |
| --- | --- | --- | --- |
| Stop them checking out | Fraud Control checkout rules | Before an order exists | Shopify Payments |
| Catch orders that get through | Shopify Flow | After the order is placed | Basic plan or higher |
| Stop them signing in | Customer account settings | At sign-in | Very limited on current accounts |
| Stop them browsing | An IP-blocker app | On your storefront | An app |

## How do I stop a customer from placing orders? {#how-do-i-stop-a-customer-from-placing-orders}

Create a Fraud Control checkout rule with their email address, their address details or their IP address. When a checkout matches, Shopify shows the buyer an error saying the checkout couldn’t be completed and asking them to contact you. No order is created, and the attempt appears in your abandoned checkouts.

Fraud Control is free and made by Shopify. In **Apps** → **Fraud Control**, click **Rules** → **Create rule**, add what you know under **Checkout conditions**, and save; the rule is active immediately. The same steps, with the rule’s limits, are walked through in [how to block an IP from checking out](/blog/block-ip-address-shopify/#how-do-i-block-an-ip-from-checking-out).

A rule can hold several conditions: Shopify’s own example combines an IP address and a ZIP code to block orders with both. So if you want their email or their address to trigger a block on its own, give each its own rule ([Fraud Control app](https://help.shopify.com/en/manual/payments/fraud-prevention/fraud-control-app#fraud-control-checkout-rules)).

Two things older guides get wrong:

- **The Fraud Filter app is gone.** [Its App Store page](https://apps.shopify.com/fraud-filter) says it “is not currently available”, and Shopify’s [fraud-prevention guidance](https://help.shopify.com/en/manual/payments/fraud-prevention/preventing-fraud) now points to Fraud Control. Advice that starts “open Fraud Filter” is out of date.
- **Checkout rules need Shopify Payments.** If you use another payment provider, the alternative is an app that adds a checkout rule under **Settings** → **Checkout** → **Checkout rules**. Shopify lets apps from the App Store do this on any plan ([Shopify Functions](https://shopify.dev/docs/apps/build/functions)), and its [validation API](https://shopify.dev/docs/api/functions/latest/cart-and-checkout-validation) gives those apps the buyer’s email, customer tags and delivery address, but not their IP address.

## How do I cancel or hold their orders automatically? {#how-do-i-cancel-or-hold-their-orders-automatically}

Use [Shopify Flow](https://help.shopify.com/en/manual/shopify-flow), which is free on the Basic plan and above. A workflow checks each new order against the customer’s email, a tag you put on their profile, or their IP address, then cancels the order, holds its fulfilment or tags it. It acts after the order exists, so it stops you shipping, not them buying.

1. Tag the customer: go to **Customers**, open their profile and add a tag such as `blocked`.
2. Go to **Apps** → **Flow** and click **Create workflow**. Start with the **Order created** trigger.
3. Add a condition on the order: the customer’s tags include `blocked`, the email equals theirs, or the IP address starts with a range you’ve seen.
4. Add actions: **Cancel order**, or **Hold fulfillment order** if you’d rather review first, plus **Add order tags** so you can find these orders later.
5. Click **Turn on workflow**.

For the email version, Shopify offers a ready-made template: **Browse templates** → **Risk** → **Cancel and tag orders from known bad email addresses**. Shopify’s own description admits it’s easy for fraudsters to work around, but it can interrupt automated fraud ([Flow for high-risk orders](https://help.shopify.com/en/manual/fulfillment/managing-orders/protecting-orders/shopify-flow)).

Watch the money. With automatic payment capture, the customer has already been charged when Flow cancels, so the money goes back only as a refund (the action’s **Refund** option), and card transaction fees aren’t returned on refunds ([cancelling orders](https://help.shopify.com/en/manual/fulfillment/managing-orders/canceling-orders)). If you capture payments manually, the **Cancel order** action voids the authorisation instead ([Cancel order action](https://help.shopify.com/en/manual/shopify-flow/reference/actions/cancel-order)).

A customer tag on its own blocks nothing. It’s a label; it only does something when a workflow or an app reads it.

## Can I disable or delete their account? {#can-i-disable-or-delete-their-account}

Barely, and it rarely stops them. On Shopify’s current customer accounts you can’t deactivate an individual account. You can delete a customer’s profile only if they have no orders, and if they sign in again with the same email, Shopify creates a new profile. Disabling accounts belonged to legacy customer accounts, which Shopify deprecated in February 2026.

If you’ve looked for a disable option on a customer’s page and not found it, that’s why ([managing customer accounts](https://help.shopify.com/en/manual/customers/customer-accounts/manage)). What each account action actually does:

- **Delete the profile:** **Customers** → open the profile → **More actions** → **Delete customer**. It can’t be undone, and Shopify refuses if the customer has any order, a subscription history, an undelivered scheduled gift card or a pending data-erasure request ([managing customers](https://help.shopify.com/en/manual/customers/manage-customers)).
- **Erase their personal data:** this answers a privacy request, not a ban. Shopify redacts details such as their name and address, and the profile and order history stay.
- **Disable the account (legacy accounts only):** Shopify [deprecated legacy customer accounts](https://changelog.shopify.com/posts/legacy-customer-accounts-are-now-deprecated) on 26 February 2026 and will announce a final shutdown date. On stores still using them, a disabled customer can’t create an account or sign in during checkout ([Flow trigger reference](https://help.shopify.com/en/manual/shopify-flow/reference/triggers/customer-account-disabled)). That’s all Shopify says it does; it doesn’t claim to stop a guest checkout, and a new email address gets round it anyway.
- **Require sign-in at checkout:** **Settings** → **Checkout** → **Require customers to sign in to their account before checkout**. On current accounts, anyone who signs in with a new email simply gets a new profile, so this adds a step for every shopper without keeping one person out. It also hides accelerated checkout buttons such as Apple Pay from the cart ([checkout settings](https://help.shopify.com/en/manual/checkout-settings/checkout-form-options)).

## How do I stop them visiting the store? {#how-do-i-stop-them-visiting-the-store}

Block their IP address or network with a storefront blocker app; Shopify has no setting for it. It’s the weakest identifier of the lot, because mobile data or a VPN gives them a new IP, so use it for someone who keeps browsing from the same connection and keep the checkout rule as the real lock.

X Shield, which we build, covers the storefront side. It turns away visitors by IP address, IP range, country and, on higher plans, whole networks (ASN), and it can refuse VPN and data-centre traffic. It does not block by email, name or postal address. It runs as JavaScript in the visitor’s browser, so it only turns away visitors whose browsers run your pages’ scripts, and it can’t control Shopify’s hosted checkout, so it doesn’t replace the Fraud Control rule above.

To block their connection in X Shield, open **IP & Network**, turn on the switch at the top of the page, choose **Block listed** under **Access mode**, paste their IP address, or the range around it, into the field under **IP addresses to block**, click **Add**, then save. The full steps are in [block IPs and networks in X Shield](/docs/x-shield/block-ip-addresses/); finding the right address and range size is covered in [how to block an IP address on Shopify](/blog/block-ip-address-shopify/).

On paid plans, X Shield’s [order protection](/docs/x-shield/order-protection/) also watches for them at the order stage. It flags a new order when its IP was blocked by your rules in the past week, or when the customer appeared in blocked visits, and adds that evidence to the order’s fraud analysis in Shopify. Higher plans can tag the order or hold its fulfilment. It never cancels an order.

> **Tip:** [X Shield, a free country and bot blocker for Shopify](/shopify/x-shield/), includes IP rules on its Free plan, and its rule tester shows whether a given IP would be blocked by the rules you’ve saved, so you can check a new rule in dry run before it blocks anyone.

## Which of these will they get around? {#which-of-these-will-they-get-around}

All of them, with enough effort. Each method keys on one detail the person controls, so layering them is what works: every extra layer costs them another new email, address or connection. Here’s what defeats each one:

| Method | Where it acts | Needs | Beaten by |
| --- | --- | --- | --- |
| Fraud Control rule on email | Checkout | Shopify Payments | A new email address |
| Fraud Control rule on address | Checkout | Shopify Payments | A different delivery address |
| Fraud Control rule on IP | Checkout | Shopify Payments | Mobile data, a VPN, another Wi-Fi network |
| Flow cancel or hold | After the order | Basic plan or higher | Anything the condition doesn’t check; the order still reaches you |
| Checkout-rule app | Checkout | An app, any plan | A new email or address; it can’t see IPs |
| Deleting the profile | Account | No orders on record | Signing in again, which recreates it |
| Disabling the account | Sign-in | Legacy accounts only | Checking out with a new email |
| Storefront IP or network block | Storefront | A blocker app | Mobile data, a VPN, a direct checkout link |

For a repeat offender, the combination that holds up best is a Fraud Control rule on their email and on their delivery address, a Flow hold on anything that still slips through, and a manual look at new orders to the same address. If an order from them does arrive, treat it like any flagged order: [what to do with a high-risk order](/blog/shopify-high-risk-orders/) covers verifying, holding and cancelling.

## Is it legal to refuse a customer? {#is-it-legal-to-refuse-a-customer}

It depends on where you and the customer are. Anti-discrimination and consumer-protection laws limit whom a business may refuse and why, and they differ between countries and within them. This isn’t legal advice, but three habits help:

- Record the conduct behind each block, such as fraud, abuse or repeated chargebacks, with dates and order numbers.
- Treat your blocklist as personal data. Emails, postal addresses and IP addresses tied to a person are covered by privacy laws such as the GDPR.
- If you cancel an order, refund it through Shopify’s cancel flow so the money goes back to the original payment method.

For anything beyond a clear case of fraud or abuse, ask a lawyer where you trade before you refuse someone.

[X Shield: IP Country Blocker](/shopify/x-shield/)

X Shield is a Shopify app that blocks visitors by country, IP address or network, and turns away the bots, VPNs and spy extensions it detects, showing them a blocked page instead of your store. Googlebot and Bingbot, checked against their published IP ranges, still get in, and dry run lets you test every rule before it blocks anyone.

[Install free on the Shopify App Store](https://apps.shopify.com/x-shield-store-guard?utm_source=b2bgold.app&utm_medium=referral&utm_campaign=blog&utm_content=blog/block-customer-shopify&utm_term=post-cta) [Plans and pricing](/shopify/x-shield/#pricing) [X Shield docs](/docs/x-shield/) [How X Shield compares with Blockify](/compare/x-shield-vs-blockify/)

Need help with X Shield? Email [support@b2bgold.app](mailto:support@b2bgold.app).

## More on X Shield {#related-heading}

- 24 September 2026 **[How to Block an IP Address on Shopify](/blog/block-ip-address-shopify/)** Block an IP from checking out or from browsing your Shopify store. Where to find a visitor's IP, Fraud Control rules vs blocker apps, and why IP blocks fail.
- 24 September 2026 **[Shopify High Risk of Fraud Detected: What to Do](/blog/shopify-high-risk-orders/)** What Shopify's high-risk flag means, how to verify an order before it ships, when to hold or cancel it, and how storefront signals like VPN visits help decide.
- 24 September 2026 **[How to Block Countries on Shopify: 4 Ways Compared](/blog/block-countries-on-shopify/)** Shopify has no country-block setting. Compare Markets, Fraud Control, blocker apps and Cloudflare, then block a country without blocking Googlebot or customers.
