# Allow and block lists

MONEI gives you two lists to control who can pay you:

* The **blocklist** rejects payments that match an identifier you've blocked.
* The **allowlist** exempts trusted customers from being blocked, so a good customer isn't caught by a rule or by automatic fraud protection.

Both live in your [MONEI Dashboard](https://dashboard.monei.com/) under [Settings → Allow & block lists](https://dashboard.monei.com/settings/lists), on separate tabs.

## Blocklist[​](#blocklist "Direct link to Blocklist")

Any payment matching a blocklisted identifier is declined automatically, before it reaches your payment processor.

### What you can block[​](#blocklist-types "Direct link to What you can block")

| Type                | What it matches                                                                                                                   |
| ------------------- | --------------------------------------------------------------------------------------------------------------------------------- |
| Email               | The customer, billing, or shipping email address on the payment. Matched regardless of capitalization.                            |
| Phone               | The customer, billing, or shipping phone number.                                                                                  |
| IP                  | The IP address the payment was made from.                                                                                         |
| Card fingerprint    | The same card across payments. Keeps blocking that card even if the customer changes their email address or device.               |
| Session fingerprint | The same device and browser across payments. Keeps blocking that device even if the customer changes their email address or card. |

Card and session fingerprints are values MONEI derives at checkout — you don't type them by hand. Copy them from a payment's details page, or use the one-click option below.

### Add a blocking rule[​](#add-block "Direct link to Add a blocking rule")

1. Go to [Settings → Allow & block lists](https://dashboard.monei.com/settings/lists) and open the **Blocklist** tab.
2. Select **Add blocking rule**.
3. Choose the **type** and enter the **value** to block. MONEI shows how many of your payments in the last 3 months the rule would have blocked, so you can check the rule before saving it.
4. Optionally set an **expiration date** — the rule is removed automatically once it passes. Leave it empty for a permanent rule.
5. Optionally add a **note** to record why you added the rule.
6. Select **Add**.

You can also block straight from a payment. Open the payment, then select the shield icon next to the customer's email address or phone number, or next to the IP address or session fingerprint under session details. Rules added this way are permanent and can be removed at any time.

tip

Blocking a **card fingerprint** or **session fingerprint** is the most effective way to stop a repeat offender, because it survives a change of email address or phone number.

### Rules MONEI adds for you[​](#automatic "Direct link to Rules MONEI adds for you")

Two kinds of rules can appear in your blocklist without you adding them:

* **Repeated-attempt blocks.** When MONEI detects several distinct payment attempts from the same email address or device in a short window — typically card testing — it adds a temporary rule with the note *Multiple attempts detected*. These expire automatically after 24 hours.
* **MONEI's own list.** MONEI maintains a block list that applies across all merchants to stop known fraud. It isn't shown in your dashboard, so a payment can be declined even when your own blocklist is empty.

## Allowlist[​](#allowlist "Direct link to Allowlist")

The allowlist is the counterpart to the blocklist: it marks an identifier as trusted so those payments are never blocked. Use it for a customer who was blocked by mistake, or for a legitimate high-volume buyer who keeps triggering automatic protection.

You can allowlist an **email address** or a **session fingerprint**. Allowlist entries don't expire — they stay until you remove them.

### Add an exemption[​](#add-exemption "Direct link to Add an exemption")

1. Go to [Settings → Allow & block lists](https://dashboard.monei.com/settings/lists) and open the **Allowlist** tab.
2. Select **Add exemption**.
3. Choose **Email** or **Session fingerprint** and enter the value. MONEI shows how many of your payments in the last 3 months the exemption would have covered.
4. Optionally add a **note**. For a session fingerprint, MONEI fills in a description of the device automatically.
5. Select **Add**.

As with blocking, you can allowlist straight from a payment using the shield icon next to the customer's email address or the session fingerprint.

### What an exemption skips[​](#exemption-scope "Direct link to What an exemption skips")

An allowlisted payment skips:

* every blocklist rule — yours **and** MONEI's own list
* automatic repeated-attempt blocking

An exemption does **not** turn off the rest of your fraud protection. [Fraud Detector](https://docs.monei.com/fraud-prevention/fraud-detector-how-it-works-configuration-and-best-practices/.md) risk scoring, [3D Secure](https://docs.monei.com/fraud-prevention/3d-secure/.md) authentication, and your payment processor's own checks all still apply, and any of them can still decline the payment.

warning

Because an allowlist entry overrides MONEI's network-wide protection, add one only for a customer you recognize and trust. Anyone who can use that email address or device gets the same exemption.

## Which list wins[​](#precedence "Direct link to Which list wins")

The allowlist always takes precedence. If a payment matches both lists, it goes through.

<!-- -->

## How matching works[​](#matching "Direct link to How matching works")

A payment is matched only when the identifier is an exact match — email addresses ignore capitalization, and phone numbers are compared in international format. If the same person pays with a different email address, phone number, card, or device, that payment is **not** matched.

That makes both lists precise tools for known cases rather than broad protection. For risk-based coverage of customers you haven't seen before, combine them with the [Fraud Detector](https://docs.monei.com/fraud-prevention/fraud-detector-how-it-works-configuration-and-best-practices/.md).

## Remove a rule[​](#remove "Direct link to Remove a rule")

Open [Settings → Allow & block lists](https://dashboard.monei.com/settings/lists), find the entry on the **Blocklist** or **Allowlist** tab, and delete it. You can also remove an entry from a payment's details page by selecting the highlighted shield icon next to the value.

In the list, select any value to see the payments that match it.
