
velocity checks card testing
Velocity checks are one of the fastest ways to catch card testing before it turns into a wave of chargebacks. This guide explains what a velocity check actually counts, how card-testing attacks appear in authorization data, and which thresholds give merchants a strong signal without blocking legitimate customers.
Key Features
- Counts activity across several identifiers at once: card fingerprint, BIN, IP address, device ID, email, and shipping address.
- Uses rolling time windows โ per minute, per hour, and per day โ so both short bursts and slow drips stay visible.
- Flags high-volume, low-value authorization attempts, the classic signature of card testing.
- Correlates many different card numbers hitting one device, IP, or email in a short period.
- Tracks decline-to-approval ratios, since testers usually fail repeatedly before a single success.
- Triggers alerts, auto-blocks, or a step-up authentication challenge when a threshold trips.
- Logs every event with a timestamp so risk teams can review patterns and support dispute evidence.
How a velocity rule is configured
A velocity rule is defined by three parts: a key, a window, and a limit. The key is what you count โ a card fingerprint, a BIN, a device ID, an IP, an email, or a combination such as BIN plus country. The window is the lookback period, commonly 60 seconds, one hour, or 24 hours. The limit is the number of attempts allowed inside that window before the rule fires. Strong setups run several rules in parallel at different windows and combine the results with address verification, CVV response codes, and 3-D Secure outcomes, so a decline is based on a pattern rather than a single signal. Thresholds should be baselined against your own normal traffic before they are enforced, and reviewed again after every major campaign or seasonal peak.
Delivery and support
This guide is delivered digitally to your account as soon as your order is confirmed, and revised editions are included whenever the material is updated. If a rule behaves differently than described in your environment, or you simply want a second opinion on your thresholds, support answers questions by email and will walk through the setup with you. If the guide does not match what you expected, contact support within the review period and the team will sort it out.
What is a velocity check?
A velocity check counts how many times a given identifier appears in transactions over a set time window. When that count crosses a defined limit, the rule flags or blocks the activity, which is exactly what a burst of card-testing attempts looks like.
What does card testing look like in velocity data?
Card testing typically appears as many small-value authorizations fired within seconds or minutes from the same IP or device, often across dozens of different card numbers. A very high decline rate followed by scattered approvals is the strongest tell.
Are velocity checks enough on their own?
No. Velocity checks are a pattern detector, so they work best alongside address verification, CVV checks, 3-D Secure, and device fingerprinting. Layering these controls catches both the fast automated attacks and the slower manual ones.