Why blocking a country in Shopify doesn't stop fraud orders

"Shopify block country still getting orders" is one of the more frustrating things to type into a search box, because it means you already did the obvious thing and it did not work. A merchant left a one-star review of Geo:Pro on January 1, 2026 saying they were "getting fraudulent orders from countries I have blocked" (one- and two-star reviews). Whatever went wrong in that particular case, the expectation behind it is worth unpicking, because no storefront geolocation app, including ours, can make that promise. This article explains what a "block country" feature technically does, why it cannot stop fraudulent orders by country, and which Shopify settings actually decide who can check out.

What a storefront blocking app really does

Every geolocation app that works on the Online Store channel, whether it redirects, shows a popup or "blocks", is a piece of JavaScript running in the visitor's browser. The sequence is always the same: Shopify's servers receive the request and return the full HTML of the page; the browser parses it; the app's script starts; it determines the visitor's country, either by asking Shopify or by calling the vendor's IP lookup service; then it does something to the page it is sitting on, such as covering it with an overlay or navigating away.

Three consequences follow. First, the page has already been delivered, so nothing has been "blocked" in the network sense; the content is in the browser and visible in the source. Second, the script only runs where it is installed, which is the theme. Checkout is a separate part of Shopify that theme app embeds do not render on, so a visitor who reaches a checkout URL directly is never examined. Third, anything that disables or bypasses JavaScript defeats it: a bot placing orders through automation, a browser with scripts off, or simply a VPN endpoint in a permitted country. Shopify's own localization documentation notes that IP-based geolocation "isn't always accurate" and that VPNs, corporate networks and some mobile carriers are detected in the wrong location; a fraudster choosing their exit country is the adversarial version of the same limitation.

The deeper mismatch is that "country" means two different things. Blocking apps look at where the visitor's connection appears to be. Fraud is about where the payment card, the billing address and the shipping address are, none of which a storefront script can see. A shopper connecting from Country A with a stolen card registered in Country B and a drop address in Country C is blocked by nothing that inspects Country A.

Where order eligibility is really decided

Markets

Shopify decides whether a customer can order based on markets, not on scripts. Per Shopify's shipping zones documentation, customers can only place orders for countries that are in an active market. A visitor from a country outside every active market receives the backup region experience, which Shopify describes as able to browse and view products but "can't complete a purchase". If you genuinely do not want orders from a country, the reliable lever is to leave it out of your markets. That is enforced by Shopify at checkout, server-side, for every visitor regardless of browser, VPN or bot.

Shipping zones

Within your active markets, shipping zones and rates define where you deliver and what the customer pays. A physical product with no applicable rate cannot be shipped there, and a country you leave out of every zone is not a country you can fulfil to. Shipping zones are the right place to express "we sell to the EU market but do not deliver to these two islands", which is a different problem from fraud but often the one merchants actually have.

Fraud analysis

Shopify's fraud analysis evaluates each order and shows risk indicators with a low, medium or high recommendation. Shopify is careful to say what it is not: it does not guarantee that fraudulent orders are caught, and acting on the recommendation (reviewing, cancelling, refunding) is your job. What it can see that a storefront script cannot is the mismatch between IP country, billing country and shipping country, the card's issuing country, and the order's history across the Shopify network. If your real goal is "stop fraudulent orders from country X", the fraud analysis page of each order is where that country actually shows up.

A manual fix that works today

  1. Decide the real rule. Is it "no sales to these countries at all", "no shipping to these countries", or "extra scrutiny for orders whose billing or shipping address is in these countries"? They map to markets, shipping zones and order review respectively.
  2. Remove the country from every active market if it is the first. Test by visiting your store with a VPN endpoint there, or by picking the country in your theme's selector if it is still offered, and confirm checkout is unavailable.
  3. Tidy shipping zones so that no rate applies to places you will not ship to.
  4. Review high-risk orders before fulfilment, especially where the fraud analysis shows the IP, billing and shipping countries disagreeing. Cancel and refund rather than ship.
  5. Keep the storefront tool for what it is good at: telling a visitor, politely and early, that you do not ship to them, or sending them to the store that does. That saves support tickets; it does not save you from fraud.

Where GeoBeacon fits, honestly

GeoBeacon has no block feature, and we are not going to add a checkbox that implies one. What it does is detect the shopper's country by asking your own store's Shopify endpoint, then either show a popup or perform a switch to the market or regional store you chose. The switch to a market uses Shopify's localization form, so the shopper ends up seeing the currency, prices and product availability of that market, and if the market does not include their country they get Shopify's backup region behaviour. Redirects to separate stores can keep the page path. Checkout, cart and account pages are always excluded.

Used that way, GeoBeacon complements the settings above rather than pretending to replace them: Markets decide who can buy, shipping zones decide where you deliver, fraud analysis decides which orders you look at twice, and GeoBeacon makes sure the shopper started in the right place. If you are choosing between one store with Markets and separate regional stores, this comparison covers how each affects what a visitor can and cannot do. The GeoBeacon landing page lists exactly what the app does, and nothing about blocking is on it on purpose.

Frequently asked questions

I blocked a country with an app. Why am I still getting orders from it?

Because a storefront blocking app runs as JavaScript in the visitor's browser after Shopify has already served the page. Anyone using a VPN, a browser with scripts disabled, a bot, or a direct link to a checkout URL never triggers it. Order eligibility is decided by your Markets and shipping settings, not by a script on the page.

What actually prevents a customer in a country from checking out on Shopify?

Shopify only allows orders for countries that belong to an active market. Visitors from countries outside all your active markets receive the backup region experience, where they can browse but cannot complete a purchase. Shipping zones then decide which of those countries you ship to and at what rate.

Does Shopify's fraud analysis block fraudulent orders?

No. Shopify's fraud analysis shows risk indicators and a recommendation for each order; it does not guarantee that a fraudulent order will be flagged, and it is up to you to review, cancel or refund high-risk orders. Treat it as a review tool, not a wall.

Can GeoBeacon block countries?

No, and it does not claim to. GeoBeacon detects a shopper's country and either suggests or performs a switch to the right market or regional store. It has no block mode and never touches checkout. Use Markets and shipping zones to control who can order.