Personal tools
Namespaces

Variants
Actions

Anti-Fraud And Email Verification For WHMCS

From ModulesGarden Wiki
(Difference between revisions)
Jump to: navigation, search
(Client Area)
 
(15 intermediate revisions by one user not shown)
Line 1: Line 1:
{{DISPLAYTITLE: Anti-Fraud & Email Verification For WHMCS}} 
 
 
 
<meta name="keywords" content="anti-fraud and email verification for whmcs, whmcs email verification configuration, whmcs email verification management, whmcs email verification installation, whmcs email verification common problems, about whmcs email verification, whmcs email verification documentation, whmcs email verification faq, whmcs email verification help, whmcs email verification guide, whmcs email verification wiki, whmcs email verification tutorial, whmcs email verification tips, whmcs fraud prevention"></meta>
 
<meta name="keywords" content="anti-fraud and email verification for whmcs, whmcs email verification configuration, whmcs email verification management, whmcs email verification installation, whmcs email verification common problems, about whmcs email verification, whmcs email verification documentation, whmcs email verification faq, whmcs email verification help, whmcs email verification guide, whmcs email verification wiki, whmcs email verification tutorial, whmcs email verification tips, whmcs fraud prevention"></meta>
 
<meta name="description" content="ModulesGarden Wiki Contains All The Information You Need About The Anti-Fraud &amp; Email Verification For WHMCS Module."></meta>
 
<meta name="description" content="ModulesGarden Wiki Contains All The Information You Need About The Anti-Fraud &amp; Email Verification For WHMCS Module."></meta>
  
= About The Module =
+
=About [https://www.modulesgarden.com/products/whmcs/anti-fraud-and-email-verification Anti-Fraud & Email Verification For WHMCS]=
'''Anti-Fraud & Email Verification For WHMCS''' allows you to require email address verification during checkout or before a client can access the Client Area.<br/>
+
{|
The module can deliver a clickable verification link or a code that the client enters manually, while the verification form may be displayed directly on the page or in a modal window.<br/>
+
|style="padding: 10px 0px 10px 0px;"|'''Anti-Fraud & Email Verification For WHMCS''' enables you to verify client email addresses during checkout or before granting access to the client area.<br/>
Configurable token validity, reminders and account lifecycle actions help you handle clients who do not complete verification. CAPTCHA protection, rate limiting, automatic bans and a blocklist for email addresses, domains and IP addresses add another layer of protection against automated and fraudulent activity.
+
The module can deliver a clickable verification link or a code for the client to enter manually.<br/>
 +
Configurable validity periods, reminders, account lifecycle actions, CAPTCHA protection, rate limiting and blocklist management give you greater control over client verification and help reduce fraudulent activity.
 +
|}
  
= Installation And Configuration =
+
*'''Core Features:'''
 +
{|
 +
|style="padding: 10px 0px 0px 30px;"|&#10004; Verify Client Email Addresses Before Allowing Access To Selected WHMCS Areas
 +
|}
 +
{|
 +
|style="padding: 0px 0px 0px 30px;"|&#10004; Require Email Verification During Checkout Or Across The Entire Client Area
 +
|}
 +
{|
 +
|style="padding: 0px 0px 0px 30px;"|&#10004; Deliver Email Verification Through Clickable Links Or Verification Codes
 +
|}
 +
{|
 +
|style="padding: 0px 0px 0px 30px;"|&#10004; Reduce Fraudulent Activity Through Rate Limiting, CAPTCHA Protection And Automatic Blocking
 +
|}
 +
{|
 +
|style="padding: 0px 0px 0px 30px;"|&#10004; Block Selected Email Addresses, Email Domains And IP Addresses
 +
|}
 +
{|
 +
|style="padding: 0px 0px 10px 30px;"|&#10004; Automate Lifecycle Actions For Client Accounts That Remain Unverified
 +
|}
  
== Installation ==
+
*'''Addon Module:'''
 +
{|
 +
|style="padding: 10px 0px 0px 30px;"|&#10004; View Dashboard With Anti-Fraud Activity Summary:
 +
|}
 +
{|
 +
|style="padding: 0px 0px 0px 45px;"|&#10004; Failed Verification Attempts
 +
|}
 +
{|
 +
|style="padding: 0px 0px 0px 45px;"|&#10004; Rate-Limited Requests
 +
|}
 +
{|
 +
|style="padding: 0px 0px 0px 45px;"|&#10004; Automatic Blocklist Entries
 +
|}
 +
{|
 +
|style="padding: 0px 0px 0px 45px;"|&#10004; Failed CAPTCHA Challenges
 +
|}
 +
{|
 +
|style="padding: 0px 0px 0px 45px;"|&#10004; Verification Emails Resent
 +
|}
 +
{|
 +
|style="padding: 0px 0px 0px 30px;"|&#10004; View Verified And Unverified Email Activity From The Last 30 Days
 +
|}
 +
{|
 +
|style="padding: 0px 0px 0px 30px;"|&#10004; View And Manage Email Verification Records:
 +
|}
 +
{|
 +
|style="padding: 0px 0px 0px 45px;"|&#10004; View Pending, Verified, Rejected And Expired Verifications
 +
|}
 +
{|
 +
|style="padding: 0px 0px 0px 45px;"|&#10004; View Verification Creation, Completion And Expiration Dates
 +
|}
 +
{|
 +
|style="padding: 0px 0px 0px 45px;"|&#10004; Filter Records By Verification Status
 +
|}
 +
{|
 +
|style="padding: 0px 0px 0px 45px;"|&#10004; Approve / Reject Pending Verifications Manually
 +
|}
 +
{|
 +
|style="padding: 0px 0px 0px 45px;"|&#10004; Return Verification Records To Pending Status
 +
|}
 +
{|
 +
|style="padding: 0px 0px 0px 45px;"|&#10004; Delete Verification Records
 +
|}
 +
{|
 +
|style="padding: 0px 0px 0px 30px;"|&#10004; Configure Email Verification Process:
 +
|}
 +
{|
 +
|style="padding: 0px 0px 0px 45px;"|&#10004; Require Verification During Checkout Or Across All Client Area Pages
 +
|}
 +
{|
 +
|style="padding: 0px 0px 0px 45px;"|&#10004; Deliver Verification Through Clickable Links Or Verification Codes
 +
|}
 +
{|
 +
|style="padding: 0px 0px 0px 45px;"|&#10004; Set Verification Token Validity Period
 +
|}
 +
{|
 +
|style="padding: 0px 0px 0px 45px;"|&#10004; Define Reminder Delivery Interval
 +
|}
 +
{|
 +
|style="padding: 0px 0px 0px 45px;"|&#10004; Set Cooldown Period Between Verification Email Resend Requests
 +
|}
 +
{|
 +
|style="padding: 0px 0px 0px 30px;"|&#10004; Configure Lifecycle Actions For Unverified Accounts:
 +
|}
 +
{|
 +
|style="padding: 0px 0px 0px 45px;"|&#10004; Automatically Inactivate Unverified Accounts After A Defined Number Of Days
 +
|}
 +
{|
 +
|style="padding: 0px 0px 0px 45px;"|&#10004; Automatically Terminate Unverified Accounts After A Defined Number Of Days
 +
|}
 +
{|
 +
|style="padding: 0px 0px 0px 45px;"|&#10004; Automatically Delete Unverified Accounts
 +
|}
 +
{|
 +
|style="padding: 0px 0px 0px 45px;"|&#10004; Define Delay Before Unverified Accounts Are Deleted
 +
|}
 +
{|
 +
|style="padding: 0px 0px 0px 30px;"|&#10004; Configure Rate Limiting And Anti-Fraud Protection:
 +
|}
 +
{|
 +
|style="padding: 0px 0px 0px 45px;"|&#10004; Set Maximum Number Of Verification Attempts
 +
|}
 +
{|
 +
|style="padding: 0px 0px 0px 45px;"|&#10004; Define Rate-Limit Time Window
 +
|}
 +
{|
 +
|style="padding: 0px 0px 0px 45px;"|&#10004; Set Number Of Failed Attempts Required For Automatic Blocking
 +
|}
 +
{|
 +
|style="padding: 0px 0px 0px 45px;"|&#10004; Define Automatic Blocking Time Window
 +
|}
 +
{|
 +
|style="padding: 0px 0px 0px 45px;"|&#10004; Protect Verification Forms Using CAPTCHA Configured In WHMCS
 +
|}
 +
{|
 +
|style="padding: 0px 0px 0px 30px;"|&#10004; View And Manage Blocklist Entries:
 +
|}
 +
{|
 +
|style="padding: 0px 0px 0px 45px;"|&#10004; Block Email Addresses, Email Domains And IP Addresses
 +
|}
 +
{|
 +
|style="padding: 0px 0px 0px 45px;"|&#10004; Add Optional Blocking Reasons
 +
|}
 +
{|
 +
|style="padding: 0px 0px 0px 45px;"|&#10004; Create Temporary Or Permanent Entries
 +
|}
 +
{|
 +
|style="padding: 0px 0px 0px 45px;"|&#10004; View Entry Source, Creation Date And Expiration Date
 +
|}
 +
{|
 +
|style="padding: 0px 0px 0px 45px;"|&#10004; View Full Blocklist Entry Details
 +
|}
 +
{|
 +
|style="padding: 0px 0px 0px 45px;"|&#10004; Delete Blocklist Entries
 +
|}
 +
{|
 +
|style="padding: 0px 0px 0px 30px;"|&#10004; Control Administrator Access To Module Sections And Actions
 +
|}
 +
{|
 +
|style="padding: 0px 0px 0px 30px;"|&#10004; Create Access Rules For Selected Administrators And Administrator Roles
 +
|}
 +
{|
 +
|style="padding: 0px 0px 0px 30px;"|&#10004; Enable Activity Logging For Individual Module Resources
 +
|}
 +
{|
 +
|style="padding: 0px 0px 0px 30px;"|&#10004; View, Filter And Delete Module Logs
 +
|}
 +
{|
 +
|style="padding: 0px 0px 0px 30px;"|&#10004; Export Logs To CSV Files
 +
|}
 
{|
 
{|
|style="padding: 0px 0px 15px 15px;"|'''1. Extract the module package into the main WHMCS directory.'''<br/>
+
|style="padding: 0px 0px 10px 30px;"|&#10004; Customize Module Interface In Admin And Client Areas Using Built-In Theme Management Tool
The files in the package will be uploaded to their corresponding WHMCS locations.
+
 
|}
 
|}
  
 +
*'''Client Area:'''
 
{|
 
{|
|style="padding: 0px 0px 15px 15px;"|'''2. Log in to your WHMCS admin area and go to ''System Settings → Addon Modules''.'''<br/>
+
|style="padding: 10px 0px 0px 30px;"|&#10004; Verify Email Address Through A Clickable Link Or Verification Code
Find '''Anti-Fraud & Email Verification''' on the list and press '''Activate'''.
+
|}
 +
{|
 +
|style="padding: 0px 0px 0px 30px;"|&#10004; Complete Email Verification During Checkout Or Before Accessing The Client Area
 +
|}
 +
{|
 +
|style="padding: 0px 0px 0px 30px;"|&#10004; Request Another Verification Email After The Configured Cooldown Period
 +
|}
 +
{|
 +
|style="padding: 0px 0px 0px 30px;"|&#10004; Complete CAPTCHA Challenge Before Submitting Verification
 +
|}
 +
{|
 +
|style="padding: 0px 0px 10px 30px;"|&#10004; Receive Confirmation After Successful Email Verification
 
|}
 
|}
  
 +
*'''General Info:'''
 
{|
 
{|
|style="padding: 0px 0px 15px 15px;"|'''3. Configure access permissions and provide the module license key if requested.'''<br/>
+
|style="padding: 10px 0px 0px 30px;"|&#10004; Multi-Language Support
Save the addon configuration and open the module through ''Addons → Anti-Fraud & Email Verification''.
+
|}
 +
{|
 +
|style="padding: 0px 0px 0px 30px;"|&#10004; Supports PHP 8.3 Back To PHP 8.2
 +
|}
 +
{|
 +
|style="padding: 0px 0px 0px 30px;"|&#10004; Supports WHMCS Themes "Twenty-One" And "Nexus"
 +
|}
 +
{|
 +
|style="padding: 0px 0px 0px 30px;"|&#10004; Supports WHMCS V9.X
 +
|}
 +
{|
 +
|style="padding: 0px 0px 0px 30px;"|&#10004; Requires ionCube Loader V14 Or Later
 +
|}
 +
{|
 +
|style="padding: 0px 0px 30px 30px;"|&#10004; Easy [https://www.docs.modulesgarden.com/How_To_Upgrade_WHMCS_Module Module Upgrade] To [https://www.modulesgarden.com/products/whmcs/anti-fraud-and-email-verification#open-source-version Open Source Version]
 
|}
 
|}
  
<!-- TODO FINAL: Add the exact cron command and recommended execution frequency once confirmed in the final build. -->
+
=Installation=
 +
{|
 +
|style="padding: 10px 0px 5px 0px;"|'''This tutorial will show you how to successfully install and configure [https://www.modulesgarden.com/products/whmcs/anti-fraud-and-email-verification Anti-Fraud & Email Verification For WHMCS.]''' <br />
 +
We will guide you step by step through the whole installation and configuration process.
 +
|}
  
== Initial Configuration ==
+
{|
Before enabling verification for production use, we recommend completing the following steps:<br/>
+
|style="padding: 0px 0px 10px 15px;"|'''1. Log in to our [https://www.modulesgarden.com/client-area/ client area] and download the module.'''
# Select the required '''Verification Mode'''.
+
|}
# Choose how verification data will be delivered and displayed.
+
{|
# Set the appropriate validity periods and reminder rules.
+
|style="padding: 0px 0px 5px 15px;"|'''2. Extract the downloaded package and upload its contents into the main WHMCS directory.'''<br/>
# Review all account lifecycle options carefully, especially those that may remove client data.
+
The package contents should be uploaded without changing the provided directory structure.
# Configure rate limiting and automatic bans.
+
|}
# Enable and configure CAPTCHA protection if required.
+
{|
# Save the settings and test the complete verification process using a test client account.
+
|style="padding: 0px 0px 15px 15px;"|'''3. Rename the module license file from '' 'license_RENAME.php' '' to '' 'license.php'.'''''<br/>
 +
Next, open the renamed file and enter your license key. The license key is available in our client area under '' 'My Products'.''
 +
|}
  
= Management =
+
{|
 +
|style="padding: 0px 0px 20px 25px;"|[[File:AFEV_license.png]]
 +
|}
 +
{|
 +
|style="padding: 0px 0px 15px 15px;"|'''4. Log in to your WHMCS admin area and navigate to '' 'System Settings' '' → '' 'Addon Modules'.'''''<br/>
 +
Find '' 'Anti-Fraud And Email Verification' '' on the list and press '' 'Activate'.''<br/>
 +
Press '' 'Configure' '', select the administrator role groups that should have access to the module, and save the changes.'''
 +
|}
 +
{|
 +
|style="padding: 0px 0px 30px 15px;"|'''5. You have successfully installed Secure Messages For WHMCS.'''<br/>
 +
The module is now available under '' 'Addons' '' → '' 'Secure Messages'.''
 +
|}
  
== Dashboard ==
+
=Management=
 
{|
 
{|
|style="padding: 0px 0px 15px 15px;"|The '''Dashboard''' provides an overview of verification activity recorded during the last 30 days.<br/>
+
|style="padding: 10px 0px 30px 15px;"|'''Anti-Fraud & Email Verification For WHMCS lets you control when clients must confirm their email addresses and provides tools to manage the complete verification lifecycle.'''<br/>
The '''Verifications Over Time''' chart compares successfully '''Verified''' records with '''Unverified''' attempts, helping you quickly review recent activity and trends.
+
In this guide, we will walk you through every section and option of the module in detail.
|style="padding: 0px 0px 20px 25px;"|[[File:Anti-Fraud_And_Email_Verification_For_WHMCS_1.png]]
+
 
|}
 
|}
  
== Verifications ==
+
==Dashboard==
 
{|
 
{|
|style="padding: 0px 0px 15px 15px;"|The '''Verifications''' section contains all email verification records created by the module.<br/>
+
|style="padding: 10px 0px 15px 15px;"|The dashboard provides an overview of recent verification and anti-fraud activity.<br/>
The summary tiles show the number of records with each status:
+
The '' 'Anti-Fraud Activity Summary' '' shows the numbers of failed verification attempts, rate-limited requests, automatic blocklist entries, failed CAPTCHA challenges and resent verification emails recorded today, during the last 7 days and during the last 30 days.<br/><br/>
* '''Pending''' the verification has been initiated but has not yet been completed.
+
The '' 'Verifications Over Time' '' chart compares verified and unverified records from the last 30 days, helping you identify recent activity and trends.
* '''Verified''' – the email address has been successfully verified.
+
|}
* '''Rejected''' – the verification attempt has been rejected.
+
{|
* '''Expired''' the verification link or code is no longer valid.
+
|style="padding: 0px 0px 30px 25px;"|[[File:Anti-Fraud_And_Email_Verification_5.png]]
* '''Total''' – the total number of verification records.
+
Press '''Show''' on a tile to filter the table by the selected status.
+
|style="padding: 0px 0px 20px 25px;"|[[File:Anti-Fraud_And_Email_Verification_For_WHMCS_2.png]]
+
 
|}
 
|}
  
The table includes the following information:
+
==Verifications==
* '''Email''' – the email address used for verification.
+
{|
* '''Mode''' – indicates whether the record was created in '''Checkout''' or '''All Pages''' mode.
+
|style="padding: 10px 0px 15px 15px;"|The '' 'Verifications' '' section contains all email verification records created by the module.<br/>
* '''Status''' – the current verification status.
+
Five counters provide a quick overview:
* '''Created At''' – the date and time when the verification was initiated.
+
* '''Verified At''' – the date and time when the verification was completed; '''Never''' is shown if it has not been completed.
+
* '''Expires At''' – the date and time when the link or code expires.
+
  
Use the search field to locate a record by its available data. The action icons allow you to mark a record as unverified or delete it.
+
*'''Pending''' - verification has been initiated but not yet completed.
 +
*'''Verified''' - the email address has been successfully verified.
 +
*'''Rejected''' - the verification attempt has been rejected.
 +
*'''Expired''' - the verification link or code is no longer valid.
 +
*'''Total''' - the total number of verification records.
  
=== Mark As Unverified ===
+
Press '' 'Show' '' on a counter to filter the table by the selected status.
 +
|}
 
{|
 
{|
|style="padding: 0px 0px 15px 15px;"|Press the '''Mark As Unverified''' icon next to a record to return it to the '''Pending''' status.<br/>
+
|style="padding: 0px 0px 20px 25px;"|[[File:Anti-Fraud_And_Email_Verification_6.png]]
Confirm the action in the modal window.<br/><br/>
+
'''''Important:''' This action changes the verification status only. It does not undo any order or account operation already completed while the email address was considered verified.''
+
|style="padding: 0px 0px 20px 25px;"|[[File:Anti-Fraud_And_Email_Verification_For_WHMCS_3.png]]
+
 
|}
 
|}
 +
{|
 +
|style="padding: 0px 0px 15px 15px;"|The table lists:
  
=== Delete Verification Record ===
+
*'''Email''' - the email address used for verification.
 +
*'''Status''' - '' 'Pending', '' '' 'Verified', '' '' 'Rejected' '' or '' 'Expired'. ''
 +
*'''Created At''' - when the verification was initiated.
 +
*'''Verified At''' - when the email address was verified; '' 'Never' '' is shown if verification has not been completed.
 +
*'''Expires At''' - when the verification link or code expires.
 +
 
 +
Use the search field to find a record. For records with '' 'Pending' '' status, the row actions allow you to manually approve or reject the verification. You can also return a record to '' 'Pending' '' status or delete it.
 +
|}
 +
 
 +
===Mark As Verified===
 
{|
 
{|
|style="padding: 0px 0px 15px 15px;"|Press the trash bin icon to permanently remove a verification record.<br/>
+
|style="padding: 10px 0px 15px 15px;"|Press the '' 'Approve' '' icon to manually approve a verification with '' 'Pending' '' status, then confirm the action.<br/>
Deleting the record does not affect the related WHMCS client account or order, if any. This action cannot be undone.
+
The record status will change to '' 'Verified', '' allowing the client to continue without completing the standard email verification process.
|style="padding: 0px 0px 20px 25px;"|[[File:Anti-Fraud_And_Email_Verification_For_WHMCS_4.png]]
+
|}
 +
{|
 +
|style="padding: 0px 0px 30px 25px;"|[[File:AFEV_7.png]]
 
|}
 
|}
  
== Blocklist ==
+
===Mark As Rejected===
 
{|
 
{|
|style="padding: 0px 0px 15px 15px;"|The '''Blocklist''' allows you to prevent selected email addresses, IP addresses and complete email domains from using the verification process.<br/>
+
|style="padding: 10px 0px 15px 15px;"|Press the '' 'Reject' '' icon to manually reject a verification with '' 'Pending' '' status, then confirm the action.<br/>
Entries may be added manually by an administrator or created automatically after the configured number of failed attempts is reached.
+
The record status will change to '' 'Rejected', '' and the client will not be considered verified.
|style="padding: 0px 0px 20px 25px;"|[[File:Anti-Fraud_And_Email_Verification_For_WHMCS_5.png]]
+
|}
 +
{|
 +
|style="padding: 0px 0px 30px 25px;"|[[File:AFEV_85.png]]
 
|}
 
|}
  
The table contains:
+
===Mark As Unverified===
* '''Type''' – email address, IP address or email domain.
+
{|
* '''Value''' the blocked value.
+
|style="padding: 10px 0px 15px 15px;"|Press the '' 'Mark As Unverified' '' icon to return a record to '' 'Pending', '' then confirm the action.<br/><br/>
* '''Source''' – '''Manual''' or '''Automatic'''.
+
'''''Important:''' This changes the verification status only. It does not undo any order or account action already taken while the address was considered verified.''
* '''Reason''' – an optional internal explanation for the entry.
+
|}
* '''Expires At''' – the expiration date; '''Never''' indicates a permanent entry.
+
{|
* '''Created At''' – the date and time when the entry was created.
+
|style="padding: 0px 0px 30px 25px;"|[[File:AFEV_5.png]]
 +
|}
  
If a reason is too long to fit in the table, use the eye icon to view its complete content. Press the trash bin icon to delete an entry from the blocklist.
+
===Delete Verification Record===
 +
{|
 +
|style="padding: 10px 0px 15px 15px;"|Press the trash bin icon to permanently remove the selected verification record.<br/>
 +
The related WHMCS client account and order, if any, remain unaffected. This action cannot be undone.
 +
|}
 +
{|
 +
|style="padding: 0px 0px 30px 25px;"|[[File:AFEV_6.png]]
 +
|}
  
=== Add Blocked Entry ===
+
==Blocklist==
 
{|
 
{|
|style="padding: 0px 0px 15px 15px;"|Press '''Add Blocked Entry''' and configure the following options:
+
|style="padding: 10px 0px 15px 15px;"|The '' 'Blocklist' '' prevents selected email addresses, IP addresses and complete email domains from using the verification process.<br/>
* '''Type''' – choose what should be blocked:
+
Entries may be added manually or created automatically after the configured number of failed attempts is reached.
** '''Email''' – a specific email address.
+
** '''IP Address''' – a specific IP address.
+
** '''Email Domain''' – every email address belonging to the specified domain.
+
* '''Value''' – enter a value matching the selected type.
+
* '''Reason (Optional)''' – add an internal note explaining why the entry was created.
+
* '''Expires At (Optional)''' – select when the entry should expire; leave the field empty to create a permanent block.
+
Press '''Confirm''' to add the entry.
+
|style="padding: 0px 0px 20px 25px;"|[[File:Anti-Fraud_And_Email_Verification_For_WHMCS_6.png]]
+
 
|}
 
|}
 +
{|
 +
|style="padding: 0px 0px 20px 25px;"|[[File:Anti-Fraud_And_Email_Verification_7.png]]
 +
|}
 +
{|
 +
|style="padding: 0px 0px 15px 15px;"|The table includes:
  
<!-- TODO FINAL: Confirm whether the primary button will remain "Confirm" or change to "Add". -->
+
*'''Type''' - email address, IP address or email domain.
 +
*'''Value''' - the blocked value.
 +
*'''Source''' - '' 'Manual' '' or '' 'Automatic'. ''
 +
*'''Reason''' - an optional internal explanation.
 +
*'''Expires At''' - the expiration date; '' 'Never' '' indicates a permanent block.
 +
*'''Created At''' - when the entry was created.
  
== Settings ==
+
Press the eye icon to view the complete reason when it is shortened in the table. Use the trash bin icon to delete an entry.
{|
+
|style="padding: 0px 0px 15px 15px;"|The '''Settings''' section controls the verification workflow, reminders, lifecycle automation and anti-fraud protection.<br/>
+
Configure the options described below and press '''Submit''' to save the changes.
+
|style="padding: 0px 0px 20px 25px;"|[[File:Anti-Fraud_And_Email_Verification_For_WHMCS_7.png]]
+
 
|}
 
|}
  
=== Verification Mode ===
+
===Add Blocked Entry===
* '''Verification Mode''' – choose where email verification is required:
+
{|
** '''All Pages''' – prevents an unverified client from accessing the Client Area until verification is completed.
+
|style="padding: 10px 0px 15px 15px;"|Press '' 'Add Blocked Entry' '' and configure:
** '''Checkout''' – prevents an unverified client from placing an order.
+
* '''Verification Delivery''' – choose what the client receives by email:
+
** '''Clickable Link''' – the client completes verification by opening the link included in the email.
+
** '''Code to Type In''' – the client enters the code received by email into the verification form.
+
* '''Verification Display''' – choose how the verification form is presented:
+
** '''Inline Form''' – displays the form directly on the page.
+
** '''Modal Popup''' – displays a button that opens the form in a modal window.
+
* '''Checkout Token Validity (Days)''' – define how many days a verification link or code generated in '''Checkout''' mode remains valid.
+
* '''All Pages Token Validity (Days)''' – define how many days a verification link or code generated in '''All Pages''' mode remains valid.
+
  
=== Reminders ===
+
*'''Type''' - select '' 'Email', '' '' 'IP Address' '' or '' 'Email Domain'. ''
* '''Checkout Reminder After (Days)''' – send a reminder this many days after an unverified checkout attempt; enter ''0'' to disable reminders.
+
*'''Value''' - enter a value matching the selected type.
* '''All Pages Reminder After (Days)''' – send a reminder this many days after registration if the client remains unverified; enter ''0'' to disable reminders.
+
*'''Reason (Optional)''' - enter an internal note explaining the entry.
* '''Resend Cooldown (Minutes)''' – define the minimum time a client must wait before requesting another verification email.
+
*'''Expires At (Optional)''' - select an expiration date or leave the field empty to create a permanent block.
  
=== Account Lifecycle ===
+
Press '' 'Confirm' '' to add the entry.
The account lifecycle settings automate actions against client accounts that remain unverified.<br/>
+
|}
Values for '''Checkout''' and '''All Pages''' modes can be configured separately.
+
{|
 +
|style="padding: 0px 0px 30px 25px;"|[[File:Anti-Fraud_And_Email_Verification_8.png]]
 +
|}
  
* '''Checkout Auto-Inactivate After (Days)''' – set the client account to '''Inactive''' after this many unverified days following a checkout attempt; enter ''0'' to disable the action.
+
==Settings==
* '''All Pages Auto-Inactivate After (Days)''' – set the client account to '''Inactive''' after this many unverified days following registration; enter ''0'' to disable the action.
+
{|
* '''Checkout Auto-Terminate After (Days)''' – define when the client account and all of its WHMCS data should be permanently removed after an unverified checkout attempt; enter ''0'' to disable the action.
+
|style="padding: 10px 0px 15px 15px;"|The '' 'Settings' '' section controls the verification workflow, reminders, account lifecycle and anti-fraud protection.<br/>
* '''All Pages Auto-Terminate After (Days)''' – define when the client account and all of its WHMCS data should be permanently removed after registration without verification; enter ''0'' to disable the action.
+
The options are divided into four panels. Press '' 'Submit' '' to save the configuration.
* '''Auto-Delete Unverified Accounts''' – enable additional automatic cleanup for unverified accounts without active orders.
+
|}
* '''Auto-Delete After (Days)''' – define how many days after the Auto-Terminate stage an eligible unverified account should be closed. This option is applied only when '''Auto-Delete Unverified Accounts''' is enabled.
+
{|
 +
|style="padding: 0px 0px 20px 25px;"|[[File:Anti-Fraud_And_Email_Verification_9.png]]
 +
|}
  
'''''Important:''' Auto-Terminate actions are permanent and irreversible and may remove the client account together with all related WHMCS data. Carefully verify these settings before enabling them in a production environment.''
+
===Verification Mode===
 +
{|
 +
|style="padding: 10px 0px 15px 15px;"|
 +
*'''Verification Mode''' - choose where verification is required:
 +
** '''All Pages''' - locks the entire client area until verification is completed.
 +
** '''Checkout''' - prevents an unverified client from placing an order.
 +
*'''Verification Delivery''' - choose '' 'Clickable Link' '' or '' 'Code To Type In'. ''
 +
*'''Token Validity (Days)''' - define how long the generated verification link or code remains valid.
 +
|}
  
<!-- TODO FINAL: The current language strings describe Auto-Terminate as deleting the client and Auto-Delete as acting after Auto-Terminate. Confirm the exact distinction and sequence before publication. -->
+
===Reminders===
 +
{|
 +
|style="padding: 10px 0px 15px 15px;"|
 +
*'''Reminder After (Days)''' - send a reminder email after the client has remained unverified for the specified number of days. Enter '''0''' to disable reminders.
 +
*'''Resend Cooldown (Minutes)''' - the minimum wait before another verification email can be requested.
 +
|}
  
=== Rate Limiting & Anti-Fraud ===
+
===Account Lifecycle===
* '''Rate Limit: Max Attempts''' – define the maximum number of verification attempts allowed within the configured time window.
+
{|
* '''Rate Limit: Window (Minutes)''' – define the rolling period used to count verification attempts.
+
|style="padding: 10px 0px 15px 15px;"|These options automate actions against client accounts that remain unverified:
* '''Auto-Ban After Failed Attempts''' – automatically block the email address and IP address after this number of failed attempts; enter ''0'' to disable automatic bans.
+
* '''Auto-Ban Window (Minutes)''' – define the rolling period used to count failed attempts for automatic bans.
+
  
Once the rate limit is reached, additional verification attempts are temporarily rejected. When the automatic ban threshold is reached, the related email address and IP address are added to the blocklist.
+
*'''Auto-Inactivate After (Days)''' - set the client account to '' 'Inactive' '' after it has remained unverified for the specified number of days. Enter '''0''' to disable this action.
 +
*'''Auto-Terminate After (Days)''' - permanently and irreversibly delete the client account and all of its WHMCS data after the specified number of unverified days. Enter '''0''' to disable this action.
 +
*'''Auto-Delete Unverified Accounts''' - enable automatic cleanup of unverified accounts without active orders.
 +
*'''Auto-Delete After (Days)''' - define the delay after Auto-Terminate before an eligible account is closed.<br/><br/>
  
<!-- TODO FINAL: Confirm whether auto-ban creates one or two entries and how long automatically generated entries remain blocked. -->
+
'''''Important:''' Auto-Terminate actions are permanent and irreversible and may remove the client account together with all related WHMCS data. Review these settings carefully before enabling them in production.''
 +
|}
  
=== CAPTCHA ===
+
===Rate Limiting & Anti-Fraud===
* '''CAPTCHA Enabled''' – require an additional CAPTCHA challenge on the verification and resend forms.
+
{|
* '''CAPTCHA Provider''' – select one of the supported protection methods:
+
|style="padding: 10px 0px 15px 15px;"|
** '''Built-in (arithmetic challenge)''' – uses a simple arithmetic question and requires no external account.
+
*'''Rate Limit: Max Attempts''' - the maximum attempts allowed within the configured window.
** '''reCAPTCHA v3''' – uses Google reCAPTCHA v3 and requires a site key and secret key.
+
*'''Rate Limit: Window (Minutes)''' - the rolling period used to count verification attempts.
** '''Cloudflare Turnstile''' uses Cloudflare Turnstile and requires a site key and secret key.
+
*'''Auto-Ban After Failed Attempts''' - automatically block the related email address and IP address after this many failures. Enter '''0''' to disable it.
 +
*'''Auto-Ban Window (Minutes)''' - the rolling period used to count failed attempts for automatic bans.
 +
*'''Enable Captcha Verification''' - require a CAPTCHA challenge during email verification. The module uses the CAPTCHA type and credentials configured in WHMCS.<br/><br/>
  
Additional fields appear after selecting an external provider:
+
Before enabling this option, go to '' 'System Settings' '' &rarr; '' 'General Settings' '' &rarr; '' 'Security' '' in WHMCS and configure CAPTCHA.<br/>
* '''reCAPTCHA Site Key''' – the public key generated in the Google reCAPTCHA administration panel.
+
'''''Important:''' If CAPTCHA verification is enabled in the module but CAPTCHA has not been configured correctly in WHMCS, clients will encounter an error when attempting to complete verification.''
* '''reCAPTCHA Secret Key''' – the corresponding private key; it is not shared with the browser.
+
|}
* '''reCAPTCHA Minimum Score''' – set a value between ''0'' and ''1''; lower scores indicate traffic that is more likely to be automated.
+
* '''Turnstile Site Key''' – the public key generated in the Cloudflare Turnstile dashboard.
+
* '''Turnstile Secret Key''' – the corresponding private key; it is not shared with the browser.
+
  
== Logs ==
+
==Client Area==
The '''Logs''' section records important operations performed by the module, including verification activity, email delivery, token generation, warnings and lifecycle cron execution.<br/>
+
{|
Use the available search and status filters to locate an entry. Depending on the available action icons, you can view entry details or delete selected records.
+
|style="padding: 10px 0px 20px 15px;"|When verification is required, the client sees the '' 'Email Verification' '' pop-up. The exact verification flow depends on the selected delivery method.
 +
|}
 +
{|
 +
|style="padding: 0px 0px 20px 25px;"|[[File:Anti-Fraud_And_Email_Verification_1.png]]
 +
|}
 +
{|
 +
|style="padding: 0px 0px 15px 15px;"|The available flows are:
  
<!-- TODO FINAL: Add the final Logs screenshot and document bulk actions/filters after confirming the final interface. -->
+
*'''Clickable Link''' - open the link received in the verification email and complete any required CAPTCHA challenge.
 +
*'''Code To Type In''' - enter the code received in the verification email in the form and press '' 'Verify'. ''
  
= Client Area =
+
If '' 'Enable Captcha Verification' '' is active, the CAPTCHA configured in WHMCS is also displayed. After successful verification, the client can continue to the restricted page or complete checkout.
 +
|}
 
{|
 
{|
|style="padding: 0px 0px 15px 15px;"|When verification is required, the client sees the '''Email Verification''' page with the address associated with the account.<br/>
+
|style="padding: 0px 0px 15px 15px;"|The verification email contains either a clickable verification link or a one-time code, depending on the selected delivery method.
The exact form depends on the selected delivery and display settings. In the presented example, the module informs the client that a verification link has been sent and provides a '''Resend''' button if the message was not received or the previous link expired.
+
|}
|style="padding: 0px 0px 20px 25px;"|[[File:Anti-Fraud_And_Email_Verification_For_WHMCS_8.png]]
+
{|
 +
|style="padding: 0px 0px 20px 25px;"|[[File:Anti-Fraud_And_Email_Verification_4.png]]
 +
|}
 +
{|
 +
|style="padding: 0px 0px 15px 15px;"|If an unverified client attempts to place an order while '' 'Checkout' '' mode is enabled, WHMCS prevents the order from being completed and asks the client to verify the email address first.
 +
|}
 +
{|
 +
|style="padding: 0px 0px 30px 25px;"|[[File:Anti-Fraud_And_Email_Verification_3.png]]
 
|}
 
|}
  
The available verification flows are:
+
==[https://www.docs.modulesgarden.com/Access_Control_Tool Access Control]==
* '''Clickable Link''' – the client opens the link received by email to confirm the address.
+
{|
* '''Code to Type In''' the client enters the email address and verification code in the provided form.
+
|style="padding: 10px 0px 15px 15px;"|The '' 'Access Control' '' tool allows you to restrict administrator access to individual module sections and actions.<br/>
* '''Inline Form''' – the required form is displayed directly on the verification page.
+
Create rules and assign them to selected administrators or administrator roles. For each rule, define the resources that should be available or restricted.
* '''Modal Popup''' – the client opens the required form in a modal window.
+
|}
 +
{|
 +
|style="padding: 0px 0px 20px 25px;"|[[File:Anti-Fraud_And_Email_Verification_10.png]]
 +
|}
 +
{|
 +
|style="padding: 0px 0px 15px 15px;"|The '' 'Resources' '' tab lists the module resources available for access rules. Use the switches in the '' 'Log' '' column to decide which resource actions should be recorded in the access control logs.<br/>
 +
For detailed instructions, see the dedicated [https://www.docs.modulesgarden.com/Access_Control_Tool Access Control documentation].
 +
|}
 +
{|
 +
|style="padding: 0px 0px 30px 25px;"|[[File:Anti-Fraud_And_Email_Verification_11.png]]
 +
|}
  
If CAPTCHA is enabled, the selected challenge is also displayed on the verification or resend form. After successful verification, the client may continue to the previously restricted Client Area page or complete the checkout process.
+
==[https://www.docs.modulesgarden.com/Logs Logs]==
 +
{|
 +
|style="padding: 10px 0px 5px 15px;"|The '' "Logs" '' tool makes monitoring and managing module activity records simple and efficient. It provides options to categorize, filter and view detailed entries, giving you control over the logs.<br/>
 +
For detailed guidance, check its dedicated article, available [https://www.docs.modulesgarden.com/Logs here].
 +
|}
 +
{|
 +
|style="padding: 0px 0px 30px 25px;"|[[File:Anti-Fraud_And_Email_Verification_12.png]]
 +
|}
  
<!-- TODO FINAL: Confirm the exact redirect destination after successful verification and add screenshots for Link/Code plus Inline/Modal combinations. -->
+
==[https://www.docs.modulesgarden.com/Theme_Management_Tool Themes]==
 +
{|
 +
|style="padding: 10px 0px 15px 15px;"|The '' 'Themes' '' tool allows you to customize the appearance of the module interface in the admin and client areas.<br/>
 +
Create a new theme or activate an existing one separately for each area. The module includes the officially supported '' 'Default' '' and '' 'Dark' '' themes.
 +
|}
 +
{|
 +
|style="padding: 0px 0px 20px 25px;"|[[File:Anti-Fraud_And_Email_Verification_13.png]]
 +
|}
 +
{|
 +
|style="padding: 0px 0px 15px 15px;"|The following screen presents the module dashboard with the officially supported '' 'Dark' '' theme enabled.
 +
|}
 +
{|
 +
|style="padding: 0px 0px 30px 25px;"|[[File:Anti-Fraud_And_Email_Verification_15.png]]
 +
|}
  
= Tips =
+
=Tips=
 
{|
 
{|
|style="padding: 0px 0px 15px 15px;"|'''1.''' Test every enabled verification flow with a test client before applying restrictions to all clients.
+
|style="padding: 10px 0px 15px 15px;"|1. '''Test every verification flow before applying restrictions to all clients.'''<br/>
 +
Use a test account to check the selected delivery method, email content, CAPTCHA challenge and redirect behavior.
 
|}
 
|}
 
{|
 
{|
|style="padding: 0px 0px 15px 15px;"|'''2.''' Set a resend cooldown and reasonable rate limits to prevent repeated email requests without blocking legitimate clients too aggressively.
+
|style="padding: 0px 0px 15px 15px;"|2. '''Use reminders and account inactivation before enabling permanent account removal.'''<br/>
 +
This gives legitimate clients additional time to complete verification and reduces the risk of unintended data loss.
 
|}
 
|}
 
{|
 
{|
|style="padding: 0px 0px 15px 15px;"|'''3.''' Review the '''Blocklist''' and '''Logs''' regularly to identify repeated failed attempts and remove entries that are no longer required.
+
|style="padding: 0px 0px 15px 15px;"|3. '''Set a resend cooldown and reasonable rate limits.'''<br/>
 +
These measures reduce repeated email requests while allowing legitimate clients to try again after a short wait.
 
|}
 
|}
 
{|
 
{|
|style="padding: 0px 0px 15px 15px;"|'''4.''' Use account lifecycle automation cautiously. Begin with reminders and account inactivation before enabling permanent deletion.
+
|style="padding: 0px 0px 15px 15px;"|4. '''Review the blocklist and logs regularly.'''<br/>
 +
Check automatically created entries and repeated failures before removing a block or changing the anti-fraud thresholds.
 +
|}
 +
{|
 +
|style="padding: 0px 0px 30px 15px;"|5. '''Customize the verification email template.'''<br/>
 +
Go to '' 'System Settings' '' &rarr; '' 'Email Templates' '' in WHMCS and edit the '' 'Email Verification Link' '' template to adjust its subject and message content.<br/>
 +
The template supports separate content for initial messages and reminders, as well as for code and clickable-link delivery.<br/> When customizing it, retain the required Smarty conditions and variables, including <code>{$is_reminder}</code>, <code>{$is_code_delivery}</code>, <code>{$code}</code> and <code>{$verify_url}</code>.
 
|}
 
|}
  
= Common Problems =
+
=Update Instructions=
{| class="wikitable"
+
{|
! Problem
+
|style="padding: 10px 0px 30px 15px;"|An essential guide to updating the module is available '''[https://www.docs.modulesgarden.com/How_To_Update_WHMCS_Module here]'''.<br/>
! Possible Cause
+
Follow every step carefully to prevent data loss or other unexpected issues.
! Solution
+
|-
+
|The client does not receive the verification email.
+
|The WHMCS mail configuration is incorrect, the message was filtered as spam, or the resend cooldown is still active.
+
|Check the module logs and WHMCS mail logs, confirm the mail configuration, ask the client to check the spam folder, and wait until the resend cooldown ends before trying again.
+
|-
+
|The verification link or code is rejected.
+
|The verification data has expired, has already been used, or does not match the pending record.
+
|Request a new verification email and make sure that the newest link or code is used before its configured validity period ends.
+
|-
+
|The client cannot request another verification email.
+
|The configured resend cooldown or rate limit has been reached.
+
|Wait for the configured time window to end or review the relevant limits in the module settings.
+
|-
+
|A legitimate client cannot complete verification.
+
|The client's email address, email domain or IP address may be present on the blocklist, or an automatic ban may have been created.
+
|Review the '''Blocklist''' and '''Logs'''. Remove the relevant entry only after confirming that the request is legitimate.
+
|-
+
|External CAPTCHA verification fails.
+
|The site key, secret key or provider configuration is invalid.
+
|Verify the credentials configured for the selected CAPTCHA provider and confirm that they are assigned to the correct WHMCS domain.
+
 
|}
 
|}
  
<!-- END OF FIRST DRAFT -->
+
=Upgrade Guide=
 +
{|
 +
|style="padding: 10px 0px 30px 15px;"|Looking for greater flexibility, custom modifications and unrestricted access to the source code?<br/>
 +
Choose the [https://www.modulesgarden.com/products/whmcs/anti-fraud-and-email-verification#open-source-version Open Source version] of Anti-Fraud & Email Verification For WHMCS to receive these benefits together with prioritized support services.<br/><br/>
 +
Press '' 'Get Source Code' '' or '' 'Upgrade To Lifetime' '' on the product page in our client area to complete the upgrade, with a '''dedicated discount''' already applied.<br/>
 +
Follow the [https://www.docs.modulesgarden.com/How_To_Upgrade_WHMCS_Module comprehensive guide] for the complete transition process.
 +
|}
 +
 
 +
=Common Problems=
 +
{|
 +
|style="padding: 10px 0px 15px 15px;"|'''1. The client does not receive the verification email.'''<br/>
 +
Check the module and WHMCS mail logs, verify the mail configuration and ask the client to check the spam folder. Wait until the '' 'Resend Cooldown' '' ends before trying again.
 +
|}
 +
{|
 +
|style="padding: 10px 0px 15px 15px;"|'''2. The verification link or code is rejected.'''<br/>
 +
The verification details may have expired, already been used or may not match the pending record. Request a new message and use the newest link or code within its validity period.
 +
|}
 +
{|
 +
|style="padding: 10px 0px 15px 15px;"|'''3. The client cannot request another verification email.'''<br/>
 +
The resend cooldown or rate limit may have been reached. Wait until the relevant window ends or review the limits under '' 'Settings'. ''
 +
|}
 +
{|
 +
|style="padding: 10px 0px 15px 15px;"|'''4. A legitimate client cannot complete verification.'''<br/>
 +
The client's email address, domain or IP address may be on the blocklist. Review '' 'Blocklist' '' and '' 'Logs', '' then remove the entry only after confirming the request is legitimate.
 +
|}
 +
{|
 +
|style="padding: 10px 0px 30px 15px;"|'''5. CAPTCHA verification fails.'''<br/>
 +
Go to '' 'System Settings' '' &rarr; '' 'General Settings' '' &rarr; '' 'Security' '' and confirm that CAPTCHA has been configured correctly in WHMCS before enabling it in the module.
 +
|}

Latest revision as of 14:49, 9 September 2026

Contents

[edit] About Anti-Fraud & Email Verification For WHMCS

Anti-Fraud & Email Verification For WHMCS enables you to verify client email addresses during checkout or before granting access to the client area.

The module can deliver a clickable verification link or a code for the client to enter manually.
Configurable validity periods, reminders, account lifecycle actions, CAPTCHA protection, rate limiting and blocklist management give you greater control over client verification and help reduce fraudulent activity.

  • Core Features:
✔ Verify Client Email Addresses Before Allowing Access To Selected WHMCS Areas
✔ Require Email Verification During Checkout Or Across The Entire Client Area
✔ Deliver Email Verification Through Clickable Links Or Verification Codes
✔ Reduce Fraudulent Activity Through Rate Limiting, CAPTCHA Protection And Automatic Blocking
✔ Block Selected Email Addresses, Email Domains And IP Addresses
✔ Automate Lifecycle Actions For Client Accounts That Remain Unverified
  • Addon Module:
✔ View Dashboard With Anti-Fraud Activity Summary:
✔ Failed Verification Attempts
✔ Rate-Limited Requests
✔ Automatic Blocklist Entries
✔ Failed CAPTCHA Challenges
✔ Verification Emails Resent
✔ View Verified And Unverified Email Activity From The Last 30 Days
✔ View And Manage Email Verification Records:
✔ View Pending, Verified, Rejected And Expired Verifications
✔ View Verification Creation, Completion And Expiration Dates
✔ Filter Records By Verification Status
✔ Approve / Reject Pending Verifications Manually
✔ Return Verification Records To Pending Status
✔ Delete Verification Records
✔ Configure Email Verification Process:
✔ Require Verification During Checkout Or Across All Client Area Pages
✔ Deliver Verification Through Clickable Links Or Verification Codes
✔ Set Verification Token Validity Period
✔ Define Reminder Delivery Interval
✔ Set Cooldown Period Between Verification Email Resend Requests
✔ Configure Lifecycle Actions For Unverified Accounts:
✔ Automatically Inactivate Unverified Accounts After A Defined Number Of Days
✔ Automatically Terminate Unverified Accounts After A Defined Number Of Days
✔ Automatically Delete Unverified Accounts
✔ Define Delay Before Unverified Accounts Are Deleted
✔ Configure Rate Limiting And Anti-Fraud Protection:
✔ Set Maximum Number Of Verification Attempts
✔ Define Rate-Limit Time Window
✔ Set Number Of Failed Attempts Required For Automatic Blocking
✔ Define Automatic Blocking Time Window
✔ Protect Verification Forms Using CAPTCHA Configured In WHMCS
✔ View And Manage Blocklist Entries:
✔ Block Email Addresses, Email Domains And IP Addresses
✔ Add Optional Blocking Reasons
✔ Create Temporary Or Permanent Entries
✔ View Entry Source, Creation Date And Expiration Date
✔ View Full Blocklist Entry Details
✔ Delete Blocklist Entries
✔ Control Administrator Access To Module Sections And Actions
✔ Create Access Rules For Selected Administrators And Administrator Roles
✔ Enable Activity Logging For Individual Module Resources
✔ View, Filter And Delete Module Logs
✔ Export Logs To CSV Files
✔ Customize Module Interface In Admin And Client Areas Using Built-In Theme Management Tool
  • Client Area:
✔ Verify Email Address Through A Clickable Link Or Verification Code
✔ Complete Email Verification During Checkout Or Before Accessing The Client Area
✔ Request Another Verification Email After The Configured Cooldown Period
✔ Complete CAPTCHA Challenge Before Submitting Verification
✔ Receive Confirmation After Successful Email Verification
  • General Info:
✔ Multi-Language Support
✔ Supports PHP 8.3 Back To PHP 8.2
✔ Supports WHMCS Themes "Twenty-One" And "Nexus"
✔ Supports WHMCS V9.X
✔ Requires ionCube Loader V14 Or Later
✔ Easy Module Upgrade To Open Source Version

[edit] Installation

This tutorial will show you how to successfully install and configure Anti-Fraud & Email Verification For WHMCS.

We will guide you step by step through the whole installation and configuration process.

1. Log in to our client area and download the module.
2. Extract the downloaded package and upload its contents into the main WHMCS directory.

The package contents should be uploaded without changing the provided directory structure.

3. Rename the module license file from 'license_RENAME.php' to 'license.php'.

Next, open the renamed file and enter your license key. The license key is available in our client area under 'My Products'.

AFEV license.png
4. Log in to your WHMCS admin area and navigate to 'System Settings' 'Addon Modules'.

Find 'Anti-Fraud And Email Verification' on the list and press 'Activate'.
Press 'Configure' , select the administrator role groups that should have access to the module, and save the changes.

5. You have successfully installed Secure Messages For WHMCS.

The module is now available under 'Addons' 'Secure Messages'.

[edit] Management

Anti-Fraud & Email Verification For WHMCS lets you control when clients must confirm their email addresses and provides tools to manage the complete verification lifecycle.

In this guide, we will walk you through every section and option of the module in detail.

[edit] Dashboard

The dashboard provides an overview of recent verification and anti-fraud activity.

The 'Anti-Fraud Activity Summary' shows the numbers of failed verification attempts, rate-limited requests, automatic blocklist entries, failed CAPTCHA challenges and resent verification emails recorded today, during the last 7 days and during the last 30 days.

The 'Verifications Over Time' chart compares verified and unverified records from the last 30 days, helping you identify recent activity and trends.

Anti-Fraud And Email Verification 5.png

[edit] Verifications

The 'Verifications' section contains all email verification records created by the module.

Five counters provide a quick overview:

  • Pending - verification has been initiated but not yet completed.
  • Verified - the email address has been successfully verified.
  • Rejected - the verification attempt has been rejected.
  • Expired - the verification link or code is no longer valid.
  • Total - the total number of verification records.

Press 'Show' on a counter to filter the table by the selected status.

Anti-Fraud And Email Verification 6.png
The table lists:
  • Email - the email address used for verification.
  • Status - 'Pending', 'Verified', 'Rejected' or 'Expired'.
  • Created At - when the verification was initiated.
  • Verified At - when the email address was verified; 'Never' is shown if verification has not been completed.
  • Expires At - when the verification link or code expires.

Use the search field to find a record. For records with 'Pending' status, the row actions allow you to manually approve or reject the verification. You can also return a record to 'Pending' status or delete it.

[edit] Mark As Verified

Press the 'Approve' icon to manually approve a verification with 'Pending' status, then confirm the action.

The record status will change to 'Verified', allowing the client to continue without completing the standard email verification process.

AFEV 7.png

[edit] Mark As Rejected

Press the 'Reject' icon to manually reject a verification with 'Pending' status, then confirm the action.

The record status will change to 'Rejected', and the client will not be considered verified.

AFEV 85.png

[edit] Mark As Unverified

Press the 'Mark As Unverified' icon to return a record to 'Pending', then confirm the action.

Important: This changes the verification status only. It does not undo any order or account action already taken while the address was considered verified.

AFEV 5.png

[edit] Delete Verification Record

Press the trash bin icon to permanently remove the selected verification record.

The related WHMCS client account and order, if any, remain unaffected. This action cannot be undone.

AFEV 6.png

[edit] Blocklist

The 'Blocklist' prevents selected email addresses, IP addresses and complete email domains from using the verification process.

Entries may be added manually or created automatically after the configured number of failed attempts is reached.

Anti-Fraud And Email Verification 7.png
The table includes:
  • Type - email address, IP address or email domain.
  • Value - the blocked value.
  • Source - 'Manual' or 'Automatic'.
  • Reason - an optional internal explanation.
  • Expires At - the expiration date; 'Never' indicates a permanent block.
  • Created At - when the entry was created.

Press the eye icon to view the complete reason when it is shortened in the table. Use the trash bin icon to delete an entry.

[edit] Add Blocked Entry

Press 'Add Blocked Entry' and configure:
  • Type - select 'Email', 'IP Address' or 'Email Domain'.
  • Value - enter a value matching the selected type.
  • Reason (Optional) - enter an internal note explaining the entry.
  • Expires At (Optional) - select an expiration date or leave the field empty to create a permanent block.

Press 'Confirm' to add the entry.

Anti-Fraud And Email Verification 8.png

[edit] Settings

The 'Settings' section controls the verification workflow, reminders, account lifecycle and anti-fraud protection.

The options are divided into four panels. Press 'Submit' to save the configuration.

Anti-Fraud And Email Verification 9.png

[edit] Verification Mode

  • Verification Mode - choose where verification is required:
    • All Pages - locks the entire client area until verification is completed.
    • Checkout - prevents an unverified client from placing an order.
  • Verification Delivery - choose 'Clickable Link' or 'Code To Type In'.
  • Token Validity (Days) - define how long the generated verification link or code remains valid.

[edit] Reminders

  • Reminder After (Days) - send a reminder email after the client has remained unverified for the specified number of days. Enter 0 to disable reminders.
  • Resend Cooldown (Minutes) - the minimum wait before another verification email can be requested.

[edit] Account Lifecycle

These options automate actions against client accounts that remain unverified:
  • Auto-Inactivate After (Days) - set the client account to 'Inactive' after it has remained unverified for the specified number of days. Enter 0 to disable this action.
  • Auto-Terminate After (Days) - permanently and irreversibly delete the client account and all of its WHMCS data after the specified number of unverified days. Enter 0 to disable this action.
  • Auto-Delete Unverified Accounts - enable automatic cleanup of unverified accounts without active orders.
  • Auto-Delete After (Days) - define the delay after Auto-Terminate before an eligible account is closed.

Important: Auto-Terminate actions are permanent and irreversible and may remove the client account together with all related WHMCS data. Review these settings carefully before enabling them in production.

[edit] Rate Limiting & Anti-Fraud

  • Rate Limit: Max Attempts - the maximum attempts allowed within the configured window.
  • Rate Limit: Window (Minutes) - the rolling period used to count verification attempts.
  • Auto-Ban After Failed Attempts - automatically block the related email address and IP address after this many failures. Enter 0 to disable it.
  • Auto-Ban Window (Minutes) - the rolling period used to count failed attempts for automatic bans.
  • Enable Captcha Verification - require a CAPTCHA challenge during email verification. The module uses the CAPTCHA type and credentials configured in WHMCS.

Before enabling this option, go to 'System Settings' 'General Settings' 'Security' in WHMCS and configure CAPTCHA.
Important: If CAPTCHA verification is enabled in the module but CAPTCHA has not been configured correctly in WHMCS, clients will encounter an error when attempting to complete verification.

[edit] Client Area

When verification is required, the client sees the 'Email Verification' pop-up. The exact verification flow depends on the selected delivery method.
Anti-Fraud And Email Verification 1.png
The available flows are:
  • Clickable Link - open the link received in the verification email and complete any required CAPTCHA challenge.
  • Code To Type In - enter the code received in the verification email in the form and press 'Verify'.

If 'Enable Captcha Verification' is active, the CAPTCHA configured in WHMCS is also displayed. After successful verification, the client can continue to the restricted page or complete checkout.

The verification email contains either a clickable verification link or a one-time code, depending on the selected delivery method.
Anti-Fraud And Email Verification 4.png
If an unverified client attempts to place an order while 'Checkout' mode is enabled, WHMCS prevents the order from being completed and asks the client to verify the email address first.
Anti-Fraud And Email Verification 3.png

[edit] Access Control

The 'Access Control' tool allows you to restrict administrator access to individual module sections and actions.

Create rules and assign them to selected administrators or administrator roles. For each rule, define the resources that should be available or restricted.

Anti-Fraud And Email Verification 10.png
The 'Resources' tab lists the module resources available for access rules. Use the switches in the 'Log' column to decide which resource actions should be recorded in the access control logs.

For detailed instructions, see the dedicated Access Control documentation.

Anti-Fraud And Email Verification 11.png

[edit] Logs

The "Logs" tool makes monitoring and managing module activity records simple and efficient. It provides options to categorize, filter and view detailed entries, giving you control over the logs.

For detailed guidance, check its dedicated article, available here.

Anti-Fraud And Email Verification 12.png

[edit] Themes

The 'Themes' tool allows you to customize the appearance of the module interface in the admin and client areas.

Create a new theme or activate an existing one separately for each area. The module includes the officially supported 'Default' and 'Dark' themes.

Anti-Fraud And Email Verification 13.png
The following screen presents the module dashboard with the officially supported 'Dark' theme enabled.
Anti-Fraud And Email Verification 15.png

[edit] Tips

1. Test every verification flow before applying restrictions to all clients.

Use a test account to check the selected delivery method, email content, CAPTCHA challenge and redirect behavior.

2. Use reminders and account inactivation before enabling permanent account removal.

This gives legitimate clients additional time to complete verification and reduces the risk of unintended data loss.

3. Set a resend cooldown and reasonable rate limits.

These measures reduce repeated email requests while allowing legitimate clients to try again after a short wait.

4. Review the blocklist and logs regularly.

Check automatically created entries and repeated failures before removing a block or changing the anti-fraud thresholds.

5. Customize the verification email template.

Go to 'System Settings' 'Email Templates' in WHMCS and edit the 'Email Verification Link' template to adjust its subject and message content.
The template supports separate content for initial messages and reminders, as well as for code and clickable-link delivery.
When customizing it, retain the required Smarty conditions and variables, including {$is_reminder}, {$is_code_delivery}, {$code} and {$verify_url}.

[edit] Update Instructions

An essential guide to updating the module is available here.

Follow every step carefully to prevent data loss or other unexpected issues.

[edit] Upgrade Guide

Looking for greater flexibility, custom modifications and unrestricted access to the source code?

Choose the Open Source version of Anti-Fraud & Email Verification For WHMCS to receive these benefits together with prioritized support services.

Press 'Get Source Code' or 'Upgrade To Lifetime' on the product page in our client area to complete the upgrade, with a dedicated discount already applied.
Follow the comprehensive guide for the complete transition process.

[edit] Common Problems

1. The client does not receive the verification email.

Check the module and WHMCS mail logs, verify the mail configuration and ask the client to check the spam folder. Wait until the 'Resend Cooldown' ends before trying again.

2. The verification link or code is rejected.

The verification details may have expired, already been used or may not match the pending record. Request a new message and use the newest link or code within its validity period.

3. The client cannot request another verification email.

The resend cooldown or rate limit may have been reached. Wait until the relevant window ends or review the limits under 'Settings'.

4. A legitimate client cannot complete verification.

The client's email address, domain or IP address may be on the blocklist. Review 'Blocklist' and 'Logs', then remove the entry only after confirming the request is legitimate.

5. CAPTCHA verification fails.

Go to 'System Settings' 'General Settings' 'Security' and confirm that CAPTCHA has been configured correctly in WHMCS before enabling it in the module.

Navigation
WHMCS Modules
WHMCS Module Bundles
WHMCS Widgets
Tools And Applications
Translations
General
FAQ
Community