How can I prevent fake abandoned checkouts from multiple email addresses?

Topic summary

Store owners are experiencing a surge of fake abandoned checkouts from bot-generated ProtonMail addresses following a pattern like mail01@protonmail.com, mail02@protonmail.com, etc. Each uses different names but similar email formats, making them harder to block than single-address spam.

Recommended Solutions:

  • Enable Shopify’s built-in spam protection under Online Store > Preferences > Spam Protection for customer accounts and newsletter signups
  • Install third-party apps like Negate Bot Protection, Shop Protector, or Fraud Filter (which can block specific email domains)
  • Use fraud prevention apps that block disposable email addresses and filter by domain (e.g., protonmail.com)
  • Enable Google reCAPTCHA in Settings > Checkout and customer accounts
  • Filter suspicious addresses in email marketing platforms to prevent them from receiving abandoned cart emails

Community Concerns:
Multiple users express frustration that this requires paid third-party apps despite already paying Shopify subscription and transaction fees. Some report the issue distorts their analytics and reporting. One user notes Shopify previously allowed IP address capture during abandoned checkout but removed this feature. The discussion remains open with no definitive free solution, and some users are considering alternative platforms.

Summarized with AI on October 23. AI used: claude-sonnet-4-5-20250929.

Have the same issue in 2024. Most likely a Bot Protection App causing this to create a need for apps just like it

2 Likes