Anti-Fraud And Email Verification For WHMCS
(→Tips) |
(→Client Area) |
||
| (5 intermediate revisions by one user not shown) | |||
| Line 62: | Line 62: | ||
{| | {| | ||
|style="padding: 0px 0px 0px 45px;"|✔ Filter Records By Verification Status | |style="padding: 0px 0px 0px 45px;"|✔ Filter Records By Verification Status | ||
| + | |} | ||
| + | {| | ||
| + | |style="padding: 0px 0px 0px 45px;"|✔ Approve / Reject Pending Verifications Manually | ||
|} | |} | ||
{| | {| | ||
| Line 220: | Line 223: | ||
{| | {| | ||
|style="padding: 0px 0px 15px 15px;"|'''4. Log in to your WHMCS admin area and navigate to '' 'System Settings' '' → '' 'Addon Modules'.'''''<br/> | |style="padding: 0px 0px 15px 15px;"|'''4. Log in to your WHMCS admin area and navigate to '' 'System Settings' '' → '' 'Addon Modules'.'''''<br/> | ||
| − | Find '' ' | + | Find '' 'Anti-Fraud And Email Verification' '' on the list and press '' 'Activate'.''<br/> |
Press '' 'Configure' '', select the administrator role groups that should have access to the module, and save the changes.''' | Press '' 'Configure' '', select the administrator role groups that should have access to the module, and save the changes.''' | ||
| − | |||
| − | |||
| − | |||
|} | |} | ||
{| | {| | ||
| Line 272: | Line 272: | ||
*'''Expires At''' - when the verification link or code expires. | *'''Expires At''' - when the verification link or code expires. | ||
| − | Use the search field to find a record. | + | Use the search field to find a record. For records with '' 'Pending' '' status, the row actions allow you to manually approve or reject the verification. You can also return a record to '' 'Pending' '' status or delete it. |
| + | |} | ||
| + | |||
| + | ===Mark As Verified=== | ||
| + | {| | ||
| + | |style="padding: 10px 0px 15px 15px;"|Press the '' 'Approve' '' icon to manually approve a verification with '' 'Pending' '' status, then confirm the action.<br/> | ||
| + | The record status will change to '' 'Verified', '' allowing the client to continue without completing the standard email verification process. | ||
| + | |} | ||
| + | {| | ||
| + | |style="padding: 0px 0px 30px 25px;"|[[File:AFEV_7.png]] | ||
| + | |} | ||
| + | |||
| + | ===Mark As Rejected=== | ||
| + | {| | ||
| + | |style="padding: 10px 0px 15px 15px;"|Press the '' 'Reject' '' icon to manually reject a verification with '' 'Pending' '' status, then confirm the action.<br/> | ||
| + | The record status will change to '' 'Rejected', '' and the client will not be considered verified. | ||
| + | |} | ||
| + | {| | ||
| + | |style="padding: 0px 0px 30px 25px;"|[[File:AFEV_85.png]] | ||
|} | |} | ||
| Line 382: | Line 400: | ||
==Client Area== | ==Client Area== | ||
{| | {| | ||
| − | |style="padding: 10px 0px | + | |style="padding: 10px 0px 20px 15px;"|When verification is required, the client sees the '' 'Email Verification' '' pop-up. The exact verification flow depends on the selected delivery method. |
| − | The exact verification flow depends on the selected delivery method | + | |
|} | |} | ||
{| | {| | ||
| Line 395: | Line 412: | ||
If '' 'Enable Captcha Verification' '' is active, the CAPTCHA configured in WHMCS is also displayed. After successful verification, the client can continue to the restricted page or complete checkout. | If '' 'Enable Captcha Verification' '' is active, the CAPTCHA configured in WHMCS is also displayed. After successful verification, the client can continue to the restricted page or complete checkout. | ||
| − | |||
| − | |||
| − | |||
|} | |} | ||
{| | {| | ||
Latest revision as of 14:49, 9 September 2026
Contents |
[edit] About Anti-Fraud & Email Verification For WHMCS
| Anti-Fraud & Email Verification For WHMCS enables you to verify client email addresses during checkout or before granting access to the client area. The module can deliver a clickable verification link or a code for the client to enter manually. |
- Core Features:
| ✔ Verify Client Email Addresses Before Allowing Access To Selected WHMCS Areas |
| ✔ Require Email Verification During Checkout Or Across The Entire Client Area |
| ✔ Deliver Email Verification Through Clickable Links Or Verification Codes |
| ✔ Reduce Fraudulent Activity Through Rate Limiting, CAPTCHA Protection And Automatic Blocking |
| ✔ Block Selected Email Addresses, Email Domains And IP Addresses |
| ✔ Automate Lifecycle Actions For Client Accounts That Remain Unverified |
- Addon Module:
| ✔ View Dashboard With Anti-Fraud Activity Summary: |
| ✔ Failed Verification Attempts |
| ✔ Rate-Limited Requests |
| ✔ Automatic Blocklist Entries |
| ✔ Failed CAPTCHA Challenges |
| ✔ Verification Emails Resent |
| ✔ View Verified And Unverified Email Activity From The Last 30 Days |
| ✔ View And Manage Email Verification Records: |
| ✔ View Pending, Verified, Rejected And Expired Verifications |
| ✔ View Verification Creation, Completion And Expiration Dates |
| ✔ Filter Records By Verification Status |
| ✔ Approve / Reject Pending Verifications Manually |
| ✔ Return Verification Records To Pending Status |
| ✔ Delete Verification Records |
| ✔ Configure Email Verification Process: |
| ✔ Require Verification During Checkout Or Across All Client Area Pages |
| ✔ Deliver Verification Through Clickable Links Or Verification Codes |
| ✔ Set Verification Token Validity Period |
| ✔ Define Reminder Delivery Interval |
| ✔ Set Cooldown Period Between Verification Email Resend Requests |
| ✔ Configure Lifecycle Actions For Unverified Accounts: |
| ✔ Automatically Inactivate Unverified Accounts After A Defined Number Of Days |
| ✔ Automatically Terminate Unverified Accounts After A Defined Number Of Days |
| ✔ Automatically Delete Unverified Accounts |
| ✔ Define Delay Before Unverified Accounts Are Deleted |
| ✔ Configure Rate Limiting And Anti-Fraud Protection: |
| ✔ Set Maximum Number Of Verification Attempts |
| ✔ Define Rate-Limit Time Window |
| ✔ Set Number Of Failed Attempts Required For Automatic Blocking |
| ✔ Define Automatic Blocking Time Window |
| ✔ Protect Verification Forms Using CAPTCHA Configured In WHMCS |
| ✔ View And Manage Blocklist Entries: |
| ✔ Block Email Addresses, Email Domains And IP Addresses |
| ✔ Add Optional Blocking Reasons |
| ✔ Create Temporary Or Permanent Entries |
| ✔ View Entry Source, Creation Date And Expiration Date |
| ✔ View Full Blocklist Entry Details |
| ✔ Delete Blocklist Entries |
| ✔ Control Administrator Access To Module Sections And Actions |
| ✔ Create Access Rules For Selected Administrators And Administrator Roles |
| ✔ Enable Activity Logging For Individual Module Resources |
| ✔ View, Filter And Delete Module Logs |
| ✔ Export Logs To CSV Files |
| ✔ Customize Module Interface In Admin And Client Areas Using Built-In Theme Management Tool |
- Client Area:
| ✔ Verify Email Address Through A Clickable Link Or Verification Code |
| ✔ Complete Email Verification During Checkout Or Before Accessing The Client Area |
| ✔ Request Another Verification Email After The Configured Cooldown Period |
| ✔ Complete CAPTCHA Challenge Before Submitting Verification |
| ✔ Receive Confirmation After Successful Email Verification |
- General Info:
| ✔ Multi-Language Support |
| ✔ Supports PHP 8.3 Back To PHP 8.2 |
| ✔ Supports WHMCS Themes "Twenty-One" And "Nexus" |
| ✔ Supports WHMCS V9.X |
| ✔ Requires ionCube Loader V14 Or Later |
| ✔ Easy Module Upgrade To Open Source Version |
[edit] Installation
| This tutorial will show you how to successfully install and configure Anti-Fraud & Email Verification For WHMCS. We will guide you step by step through the whole installation and configuration process. |
| 1. Log in to our client area and download the module. |
| 2. Extract the downloaded package and upload its contents into the main WHMCS directory. The package contents should be uploaded without changing the provided directory structure. |
| 3. Rename the module license file from 'license_RENAME.php' to 'license.php'. Next, open the renamed file and enter your license key. The license key is available in our client area under 'My Products'. |
|
| 4. Log in to your WHMCS admin area and navigate to 'System Settings' → 'Addon Modules'. Find 'Anti-Fraud And Email Verification' on the list and press 'Activate'. |
| 5. You have successfully installed Secure Messages For WHMCS. The module is now available under 'Addons' → 'Secure Messages'. |
[edit] Management
| Anti-Fraud & Email Verification For WHMCS lets you control when clients must confirm their email addresses and provides tools to manage the complete verification lifecycle. In this guide, we will walk you through every section and option of the module in detail. |
[edit] Dashboard
| The dashboard provides an overview of recent verification and anti-fraud activity. The 'Anti-Fraud Activity Summary' shows the numbers of failed verification attempts, rate-limited requests, automatic blocklist entries, failed CAPTCHA challenges and resent verification emails recorded today, during the last 7 days and during the last 30 days. |
|
[edit] Verifications
| The 'Verifications' section contains all email verification records created by the module. Five counters provide a quick overview:
Press 'Show' on a counter to filter the table by the selected status. |
|
The table lists:
Use the search field to find a record. For records with 'Pending' status, the row actions allow you to manually approve or reject the verification. You can also return a record to 'Pending' status or delete it. |
[edit] Mark As Verified
| Press the 'Approve' icon to manually approve a verification with 'Pending' status, then confirm the action. The record status will change to 'Verified', allowing the client to continue without completing the standard email verification process. |
|
[edit] Mark As Rejected
| Press the 'Reject' icon to manually reject a verification with 'Pending' status, then confirm the action. The record status will change to 'Rejected', and the client will not be considered verified. |
|
[edit] Mark As Unverified
| Press the 'Mark As Unverified' icon to return a record to 'Pending', then confirm the action. Important: This changes the verification status only. It does not undo any order or account action already taken while the address was considered verified. |
|
[edit] Delete Verification Record
| Press the trash bin icon to permanently remove the selected verification record. The related WHMCS client account and order, if any, remain unaffected. This action cannot be undone. |
|
[edit] Blocklist
| The 'Blocklist' prevents selected email addresses, IP addresses and complete email domains from using the verification process. Entries may be added manually or created automatically after the configured number of failed attempts is reached. |
|
The table includes:
Press the eye icon to view the complete reason when it is shortened in the table. Use the trash bin icon to delete an entry. |
[edit] Add Blocked Entry
Press 'Add Blocked Entry' and configure:
Press 'Confirm' to add the entry. |
|
[edit] Settings
| The 'Settings' section controls the verification workflow, reminders, account lifecycle and anti-fraud protection. The options are divided into four panels. Press 'Submit' to save the configuration. |
|
[edit] Verification Mode
|
[edit] Reminders
|
[edit] Account Lifecycle
These options automate actions against client accounts that remain unverified:
Important: Auto-Terminate actions are permanent and irreversible and may remove the client account together with all related WHMCS data. Review these settings carefully before enabling them in production. |
[edit] Rate Limiting & Anti-Fraud
Before enabling this option, go to 'System Settings' → 'General Settings' → 'Security' in WHMCS and configure CAPTCHA. |
[edit] Client Area
| When verification is required, the client sees the 'Email Verification' pop-up. The exact verification flow depends on the selected delivery method. |
|
The available flows are:
If 'Enable Captcha Verification' is active, the CAPTCHA configured in WHMCS is also displayed. After successful verification, the client can continue to the restricted page or complete checkout. |
| The verification email contains either a clickable verification link or a one-time code, depending on the selected delivery method. |
|
| If an unverified client attempts to place an order while 'Checkout' mode is enabled, WHMCS prevents the order from being completed and asks the client to verify the email address first. |
|
[edit] Access Control
| The 'Access Control' tool allows you to restrict administrator access to individual module sections and actions. Create rules and assign them to selected administrators or administrator roles. For each rule, define the resources that should be available or restricted. |
|
| The 'Resources' tab lists the module resources available for access rules. Use the switches in the 'Log' column to decide which resource actions should be recorded in the access control logs. For detailed instructions, see the dedicated Access Control documentation. |
|
[edit] Logs
| The "Logs" tool makes monitoring and managing module activity records simple and efficient. It provides options to categorize, filter and view detailed entries, giving you control over the logs. For detailed guidance, check its dedicated article, available here. |
|
[edit] Themes
| The 'Themes' tool allows you to customize the appearance of the module interface in the admin and client areas. Create a new theme or activate an existing one separately for each area. The module includes the officially supported 'Default' and 'Dark' themes. |
|
| The following screen presents the module dashboard with the officially supported 'Dark' theme enabled. |
|
[edit] Tips
| 1. Test every verification flow before applying restrictions to all clients. Use a test account to check the selected delivery method, email content, CAPTCHA challenge and redirect behavior. |
| 2. Use reminders and account inactivation before enabling permanent account removal. This gives legitimate clients additional time to complete verification and reduces the risk of unintended data loss. |
| 3. Set a resend cooldown and reasonable rate limits. These measures reduce repeated email requests while allowing legitimate clients to try again after a short wait. |
| 4. Review the blocklist and logs regularly. Check automatically created entries and repeated failures before removing a block or changing the anti-fraud thresholds. |
| 5. Customize the verification email template. Go to 'System Settings' → 'Email Templates' in WHMCS and edit the 'Email Verification Link' template to adjust its subject and message content. |
[edit] Update Instructions
| An essential guide to updating the module is available here. Follow every step carefully to prevent data loss or other unexpected issues. |
[edit] Upgrade Guide
| Looking for greater flexibility, custom modifications and unrestricted access to the source code? Choose the Open Source version of Anti-Fraud & Email Verification For WHMCS to receive these benefits together with prioritized support services. |
[edit] Common Problems
| 1. The client does not receive the verification email. Check the module and WHMCS mail logs, verify the mail configuration and ask the client to check the spam folder. Wait until the 'Resend Cooldown' ends before trying again. |
| 2. The verification link or code is rejected. The verification details may have expired, already been used or may not match the pending record. Request a new message and use the newest link or code within its validity period. |
| 3. The client cannot request another verification email. The resend cooldown or rate limit may have been reached. Wait until the relevant window ends or review the limits under 'Settings'. |
| 4. A legitimate client cannot complete verification. The client's email address, domain or IP address may be on the blocklist. Review 'Blocklist' and 'Logs', then remove the entry only after confirming the request is legitimate. |
| 5. CAPTCHA verification fails. Go to 'System Settings' → 'General Settings' → 'Security' and confirm that CAPTCHA has been configured correctly in WHMCS before enabling it in the module. |

















