Allow and block lists
MONEI gives you two lists to control who can pay you:
- The blocklist rejects payments that match an identifier you've blocked.
- The allowlist exempts trusted customers from being blocked, so a good customer isn't caught by a rule or by automatic fraud protection.
Both live in your MONEI Dashboard under Settings → Allow & block lists, on separate tabs.
Blocklist
Any payment matching a blocklisted identifier is declined automatically, before it reaches your payment processor.
What you can block
| Type | What it matches |
|---|---|
| The customer, billing, or shipping email address on the payment. Matched regardless of capitalization. | |
| Phone | The customer, billing, or shipping phone number. |
| IP | The IP address the payment was made from. |
| Card fingerprint | The same card across payments. Keeps blocking that card even if the customer changes their email address or device. |
| Session fingerprint | The same device and browser across payments. Keeps blocking that device even if the customer changes their email address or card. |
Card and session fingerprints are values MONEI derives at checkout — you don't type them by hand. Copy them from a payment's details page, or use the one-click option below.
Add a blocking rule
- Go to Settings → Allow & block lists and open the Blocklist tab.
- Select Add blocking rule.
- Choose the type and enter the value to block. MONEI shows how many of your payments in the last 3 months the rule would have blocked, so you can check the rule before saving it.
- Optionally set an expiration date — the rule is removed automatically once it passes. Leave it empty for a permanent rule.
- Optionally add a note to record why you added the rule.
- Select Add.
You can also block straight from a payment. Open the payment, then select the shield icon next to the customer's email address or phone number, or next to the IP address or session fingerprint under session details. Rules added this way are permanent and can be removed at any time.
Blocking a card fingerprint or session fingerprint is the most effective way to stop a repeat offender, because it survives a change of email address or phone number.
Rules MONEI adds for you
Two kinds of rules can appear in your blocklist without you adding them:
- Repeated-attempt blocks. When MONEI detects several distinct payment attempts from the same email address or device in a short window — typically card testing — it adds a temporary rule with the note Multiple attempts detected. These expire automatically after 24 hours.
- MONEI's own list. MONEI maintains a block list that applies across all merchants to stop known fraud. It isn't shown in your dashboard, so a payment can be declined even when your own blocklist is empty.
Allowlist
The allowlist is the counterpart to the blocklist: it marks an identifier as trusted so those payments are never blocked. Use it for a customer who was blocked by mistake, or for a legitimate high-volume buyer who keeps triggering automatic protection.
You can allowlist an email address or a session fingerprint. Allowlist entries don't expire — they stay until you remove them.
Add an exemption
- Go to Settings → Allow & block lists and open the Allowlist tab.
- Select Add exemption.
- Choose Email or Session fingerprint and enter the value. MONEI shows how many of your payments in the last 3 months the exemption would have covered.
- Optionally add a note. For a session fingerprint, MONEI fills in a description of the device automatically.
- Select Add.
As with blocking, you can allowlist straight from a payment using the shield icon next to the customer's email address or the session fingerprint.
What an exemption skips
An allowlisted payment skips:
- every blocklist rule — yours and MONEI's own list
- automatic repeated-attempt blocking
An exemption does not turn off the rest of your fraud protection. Fraud Detector risk scoring, 3D Secure authentication, and your payment processor's own checks all still apply, and any of them can still decline the payment.
Because an allowlist entry overrides MONEI's network-wide protection, add one only for a customer you recognize and trust. Anyone who can use that email address or device gets the same exemption.
Which list wins
The allowlist always takes precedence. If a payment matches both lists, it goes through.
How matching works
A payment is matched only when the identifier is an exact match — email addresses ignore capitalization, and phone numbers are compared in international format. If the same person pays with a different email address, phone number, card, or device, that payment is not matched.
That makes both lists precise tools for known cases rather than broad protection. For risk-based coverage of customers you haven't seen before, combine them with the Fraud Detector.
Remove a rule
Open Settings → Allow & block lists, find the entry on the Blocklist or Allowlist tab, and delete it. You can also remove an entry from a payment's details page by selecting the highlighted shield icon next to the value.
In the list, select any value to see the payments that match it.