Anti-Fraud And Email Verification For WHMCS
| Line 1: | Line 1: | ||
| − | |||
| − | |||
<meta name="keywords" content="anti-fraud and email verification for whmcs, whmcs email verification configuration, whmcs email verification management, whmcs email verification installation, whmcs email verification common problems, about whmcs email verification, whmcs email verification documentation, whmcs email verification faq, whmcs email verification help, whmcs email verification guide, whmcs email verification wiki, whmcs email verification tutorial, whmcs email verification tips, whmcs fraud prevention"></meta> | <meta name="keywords" content="anti-fraud and email verification for whmcs, whmcs email verification configuration, whmcs email verification management, whmcs email verification installation, whmcs email verification common problems, about whmcs email verification, whmcs email verification documentation, whmcs email verification faq, whmcs email verification help, whmcs email verification guide, whmcs email verification wiki, whmcs email verification tutorial, whmcs email verification tips, whmcs fraud prevention"></meta> | ||
<meta name="description" content="ModulesGarden Wiki Contains All The Information You Need About The Anti-Fraud & Email Verification For WHMCS Module."></meta> | <meta name="description" content="ModulesGarden Wiki Contains All The Information You Need About The Anti-Fraud & Email Verification For WHMCS Module."></meta> | ||
| − | = About | + | =About [https://www.modulesgarden.com/products/whmcs/anti-fraud-email-verification Anti-Fraud & Email Verification For WHMCS]= |
| − | '''Anti-Fraud & Email Verification For WHMCS''' | + | {| |
| − | The module can deliver a clickable verification link or a code | + | |style="padding: 10px 0px 10px 0px;"|'''Anti-Fraud & Email Verification For WHMCS''' enables you to verify client email addresses during checkout or before granting access to the client area.<br/> |
| − | Configurable | + | The module can deliver a clickable verification link or a code for the client to enter manually, while the verification form may be displayed directly on the page or in a modal window.<br/> |
| + | Configurable validity periods, reminders, account lifecycle actions, CAPTCHA protection, rate limiting and blocklist management give you greater control over client verification and help reduce fraudulent activity. | ||
| + | |} | ||
| − | = | + | *'''Core Features:''' |
| + | {| | ||
| + | |style="padding: 10px 0px 0px 30px;"|✔ Require Client Email Verification During Checkout Or Before Client Area Access | ||
| + | |} | ||
| + | {| | ||
| + | |style="padding: 0px 0px 0px 30px;"|✔ Deliver Verification Through Clickable Links Or Codes Entered Manually | ||
| + | |} | ||
| + | {| | ||
| + | |style="padding: 0px 0px 0px 30px;"|✔ Display Verification Forms Inline Or In Modal Windows | ||
| + | |} | ||
| + | {| | ||
| + | |style="padding: 0px 0px 0px 30px;"|✔ Automate Reminders And Management Of Accounts That Remain Unverified | ||
| + | |} | ||
| + | {| | ||
| + | |style="padding: 0px 0px 10px 30px;"|✔ Protect Verification Forms With CAPTCHA, Rate Limiting And Automatic Bans | ||
| + | |} | ||
| − | == | + | *'''Addon Module:''' |
| + | {| | ||
| + | |style="padding: 10px 0px 0px 30px;"|✔ View Verification Activity From The Last 30 Days | ||
| + | |} | ||
| + | {| | ||
| + | |style="padding: 0px 0px 0px 30px;"|✔ View And Filter Email Verification Records By Status: | ||
| + | |} | ||
| + | {| | ||
| + | |style="padding: 0px 0px 0px 45px;"|✔ Pending | ||
| + | |} | ||
| + | {| | ||
| + | |style="padding: 0px 0px 0px 45px;"|✔ Verified | ||
| + | |} | ||
| + | {| | ||
| + | |style="padding: 0px 0px 0px 45px;"|✔ Rejected | ||
| + | |} | ||
| + | {| | ||
| + | |style="padding: 0px 0px 0px 45px;"|✔ Expired | ||
| + | |} | ||
| + | {| | ||
| + | |style="padding: 0px 0px 0px 30px;"|✔ Review Verification Mode, Status And Important Dates | ||
| + | |} | ||
| + | {| | ||
| + | |style="padding: 0px 0px 0px 30px;"|✔ Mark Verification Records As Unverified | ||
| + | |} | ||
| + | {| | ||
| + | |style="padding: 0px 0px 0px 30px;"|✔ Delete Verification Records | ||
| + | |} | ||
| + | {| | ||
| + | |style="padding: 0px 0px 0px 30px;"|✔ Manage Blocklist Entries For Email Addresses, IP Addresses And Email Domains | ||
| + | |} | ||
| + | {| | ||
| + | |style="padding: 0px 0px 0px 30px;"|✔ Create Permanent Or Time-Limited Blocklist Entries | ||
| + | |} | ||
| + | {| | ||
| + | |style="padding: 0px 0px 0px 30px;"|✔ View Manually And Automatically Added Blocklist Entries | ||
| + | |} | ||
| + | {| | ||
| + | |style="padding: 0px 0px 0px 30px;"|✔ Select Checkout Or All Pages Verification Mode | ||
| + | |} | ||
| + | {| | ||
| + | |style="padding: 0px 0px 0px 30px;"|✔ Deliver Verification Through Clickable Link Or Code To Type In | ||
| + | |} | ||
| + | {| | ||
| + | |style="padding: 0px 0px 0px 30px;"|✔ Display Verification As Inline Form Or Modal Popup | ||
| + | |} | ||
| + | {| | ||
| + | |style="padding: 0px 0px 0px 30px;"|✔ Define Verification Link And Code Validity Periods | ||
| + | |} | ||
| + | {| | ||
| + | |style="padding: 0px 0px 0px 30px;"|✔ Configure Verification Reminders And Resend Cooldown | ||
| + | |} | ||
| + | {| | ||
| + | |style="padding: 0px 0px 0px 30px;"|✔ Automatically Set Unverified Client Accounts To Inactive | ||
| + | |} | ||
| + | {| | ||
| + | |style="padding: 0px 0px 0px 30px;"|✔ Configure Automatic Termination And Deletion Of Unverified Accounts | ||
| + | |} | ||
| + | {| | ||
| + | |style="padding: 0px 0px 0px 30px;"|✔ Configure Verification Attempt Rate Limits And Automatic Bans | ||
| + | |} | ||
| + | {| | ||
| + | |style="padding: 0px 0px 0px 30px;"|✔ Protect Verification Forms With Built-In CAPTCHA, reCAPTCHA V3 Or Cloudflare Turnstile | ||
| + | |} | ||
{| | {| | ||
| − | |style="padding: 0px 0px | + | |style="padding: 0px 0px 10px 30px;"|✔ View And Manage Module Logs |
| − | + | ||
|} | |} | ||
| + | *'''Client Area:''' | ||
{| | {| | ||
| − | |style="padding: 0px 0px | + | |style="padding: 10px 0px 0px 30px;"|✔ Verify Email Address To Place Orders Or Access Client Area |
| − | + | |} | |
| + | {| | ||
| + | |style="padding: 0px 0px 0px 30px;"|✔ Verify Email Address Through Clickable Link Or Verification Code | ||
| + | |} | ||
| + | {| | ||
| + | |style="padding: 0px 0px 0px 30px;"|✔ Request Another Verification Email | ||
| + | |} | ||
| + | {| | ||
| + | |style="padding: 0px 0px 10px 30px;"|✔ Complete CAPTCHA Challenge When Enabled | ||
|} | |} | ||
| + | *'''General Info:''' | ||
{| | {| | ||
| − | |style="padding: 0px 0px | + | |style="padding: 10px 0px 0px 30px;"|✔ Multi-Language Support |
| − | + | |} | |
| + | {| | ||
| + | |style="padding: 0px 0px 0px 30px;"|✔ Supports PHP 8.3 Back To PHP 8.2 | ||
| + | |} | ||
| + | {| | ||
| + | |style="padding: 0px 0px 0px 30px;"|✔ Supports WHMCS Themes "Twenty-One" And "Nexus" | ||
| + | |} | ||
| + | {| | ||
| + | |style="padding: 0px 0px 0px 30px;"|✔ Supports WHMCS V9.X | ||
| + | |} | ||
| + | {| | ||
| + | |style="padding: 0px 0px 0px 30px;"|✔ Requires ionCube Loader V14 Or Later | ||
| + | |} | ||
| + | {| | ||
| + | |style="padding: 0px 0px 30px 30px;"|✔ Easy [https://www.docs.modulesgarden.com/How_To_Upgrade_WHMCS_Module Module Upgrade] To [https://www.modulesgarden.com/products/whmcs/anti-fraud-email-verification#open-source-version Open Source Version] | ||
|} | |} | ||
| − | + | =Installation= | |
| + | {| | ||
| + | |style="padding: 10px 0px 5px 0px;"|'''This tutorial will show you how to successfully install and configure [https://www.modulesgarden.com/products/whmcs/anti-fraud-email-verification Anti-Fraud & Email Verification For WHMCS.]''' <br /> | ||
| + | We will guide you step by step through the whole installation and configuration process. | ||
| + | |} | ||
| + | {| | ||
| + | |style="padding: 0px 0px 20px 15px;"|'''1. Log in to our client area and download the module.''' | ||
| + | |} | ||
| + | {| | ||
| + | |style="padding: 0px 0px 20px 25px;"|[[File:AFEV_download.png]] | ||
| + | |} | ||
| + | {| | ||
| + | |style="padding: 0px 0px 15px 15px;"|'''2. Extract the package and upload its content into the main WHMCS directory.'''<br /> | ||
| + | The content of the package to upload should look like this. | ||
| + | |} | ||
| + | {| | ||
| + | |style="padding: 0px 0px 20px 25px;"|[[File:AFEV_package.png]] | ||
| + | |} | ||
| + | {| | ||
| + | |style="padding: 0px 0px 15px 15px;"|'''3. When you install Anti-Fraud & Email Verification For WHMCS for the first time, rename the '' 'license_RENAME.php' '' file.'''<br /> | ||
| + | The file is located in '' 'modules/addons/EmailVerificationAntiFraud/license_RENAME.php'. '' Rename it from '' 'license_RENAME.php' '' to '' 'license.php'. '' | ||
| + | |} | ||
| + | {| | ||
| + | |style="padding: 0px 0px 20px 25px;"|[[File:AFEV_license.png]] | ||
| + | |} | ||
| + | {| | ||
| + | |style="padding: 0px 0px 15px 15px;"|'''4. To configure your license key, edit the previously renamed '' 'license.php' '' file.'''<br /> | ||
| + | Enter your license key between quotation marks, as shown on the following screen. You can find the license key in our client area under '' 'My Products'. '' | ||
| + | |} | ||
| + | {| | ||
| + | |style="padding: 0px 0px 20px 25px;"|[[File:AFEV_license2.png]] | ||
| + | |} | ||
| + | {| | ||
| + | |style="padding: 0px 0px 15px 15px;"|'''5. Activate the module in your WHMCS system.'''<br /> | ||
| + | Go to '' 'System Settings' '' → '' 'Addon Modules'. '' Find '' 'Anti-Fraud & Email Verification' '' and press '' 'Activate'. '' | ||
| + | |} | ||
| + | {| | ||
| + | |style="padding: 0px 0px 20px 25px;"|[[File:AFEV_2.png]] | ||
| + | |} | ||
| + | {| | ||
| + | |style="padding: 0px 0px 15px 15px;"|'''6. Permit access to the module.'''<br /> | ||
| + | Press '' 'Configure', '' select the required administrator roles under '' 'Access Control', '' and press '' 'Save Changes'. '' | ||
| + | |} | ||
| + | {| | ||
| + | |style="padding: 0px 0px 20px 25px;"|[[File:AFEV_1.png]] | ||
| + | |} | ||
| + | {| | ||
| + | |style="padding: 0px 0px 30px 15px;"|'''7. You have successfully installed Anti-Fraud & Email Verification For WHMCS!'''<br /> | ||
| + | You can access the module under '' 'Addons' '' → '' 'Anti-Fraud & Email Verification'. '' | ||
| + | |} | ||
| − | + | <!-- TODO FINAL: Confirm the addon directory name and cron requirements. --> | |
| − | + | ||
| − | + | ||
| − | + | ||
| − | + | ||
| − | + | ||
| − | + | ||
| − | + | ||
| − | + | ||
| − | = Management = | + | =Management= |
| + | {| | ||
| + | |style="padding: 10px 0px 30px 15px;"|'''Anti-Fraud & Email Verification For WHMCS lets you control when clients must confirm their email addresses and provides tools to manage the complete verification lifecycle.'''<br/> | ||
| + | In this guide, we will walk you through every section and option of the module in detail. | ||
| + | |} | ||
| − | == Dashboard == | + | ==Dashboard== |
{| | {| | ||
| − | |style="padding: | + | |style="padding: 10px 0px 15px 15px;"|The dashboard presents a chart of verification activity recorded during the last 30 days.<br/> |
| − | + | It compares successfully '' 'Verified' '' records with '' 'Unverified' '' attempts, helping you quickly review recent activity and trends. | |
| − | |style="padding: 0px 0px | + | |} |
| + | {| | ||
| + | |style="padding: 0px 0px 30px 25px;"|[[File:AFEV_3.png]] | ||
|} | |} | ||
| − | == Verifications == | + | ==Verifications== |
{| | {| | ||
| − | |style="padding: | + | |style="padding: 10px 0px 15px 15px;"|The '' 'Verifications' '' section contains all email verification records created by the module.<br/> |
| − | + | Five counters provide a quick overview: | |
| − | * '''Pending''' | + | |
| − | * '''Verified''' | + | *'''Pending''' - verification has been initiated but not yet completed. |
| − | * '''Rejected''' | + | *'''Verified''' - the email address has been successfully verified. |
| − | * '''Expired''' | + | *'''Rejected''' - the verification attempt has been rejected. |
| − | * '''Total''' | + | *'''Expired''' - the verification link or code is no longer valid. |
| − | Press '''Show''' on a | + | *'''Total''' - the total number of verification records. |
| − | + | ||
| + | Press '' 'Show' '' on a counter to filter the table by the selected status. | ||
|} | |} | ||
| + | {| | ||
| + | |style="padding: 0px 0px 20px 25px;"|[[File:AFEV_4.png]] | ||
| + | |} | ||
| + | {| | ||
| + | |style="padding: 0px 0px 15px 15px;"|The table lists: | ||
| − | + | *'''Email''' - the email address used for verification. | |
| − | * '''Email''' | + | *'''Mode''' - '' 'Checkout' '' or '' 'All Pages'. '' |
| − | * '''Mode''' | + | *'''Status''' - '' 'Pending', '' '' 'Verified', '' '' 'Rejected' '' or '' 'Expired'. '' |
| − | * '''Status''' | + | *'''Created At''' - when the verification was initiated. |
| − | * '''Created At''' | + | *'''Verified At''' - when the email address was verified; '' 'Never' '' is shown if verification has not been completed. |
| − | * '''Verified At''' | + | *'''Expires At''' - when the verification link or code expires. |
| − | * '''Expires At''' | + | |
| − | Use the search field to | + | Use the search field to find a record. The row actions allow you to mark it as unverified or delete it. |
| + | |} | ||
| − | === Mark As Unverified === | + | ===Mark As Unverified=== |
{| | {| | ||
| − | |style="padding: | + | |style="padding: 10px 0px 15px 15px;"|Press the '' 'Mark As Unverified' '' icon to return a record to '' 'Pending', '' then confirm the action.<br/><br/> |
| − | + | '''''Important:''' This changes the verification status only. It does not undo any order or account action already taken while the address was considered verified.'' | |
| − | '''''Important:''' This | + | |} |
| − | |style="padding: 0px 0px | + | {| |
| + | |style="padding: 0px 0px 30px 25px;"|[[File:AFEV_5.png]] | ||
|} | |} | ||
| − | === Delete Verification Record === | + | ===Delete Verification Record=== |
{| | {| | ||
| − | |style="padding: | + | |style="padding: 10px 0px 15px 15px;"|Press the trash bin icon to permanently remove the selected verification record.<br/> |
| − | + | The related WHMCS client account and order, if any, remain unaffected. This action cannot be undone. | |
| − | |style="padding: 0px 0px | + | |} |
| + | {| | ||
| + | |style="padding: 0px 0px 30px 25px;"|[[File:AFEV_6.png]] | ||
|} | |} | ||
| − | == Blocklist == | + | ==Blocklist== |
{| | {| | ||
| − | |style="padding: | + | |style="padding: 10px 0px 15px 15px;"|The '' 'Blocklist' '' prevents selected email addresses, IP addresses and complete email domains from using the verification process.<br/> |
| − | Entries may be added manually | + | Entries may be added manually or created automatically after the configured number of failed attempts is reached. |
| − | + | ||
|} | |} | ||
| + | {| | ||
| + | |style="padding: 0px 0px 20px 25px;"|[[File:AFEV_7.png]] | ||
| + | |} | ||
| + | {| | ||
| + | |style="padding: 0px 0px 15px 15px;"|The table includes: | ||
| − | + | *'''Type''' - email address, IP address or email domain. | |
| − | * '''Type''' | + | *'''Value''' - the blocked value. |
| − | * '''Value''' | + | *'''Source''' - '' 'Manual' '' or '' 'Automatic'. '' |
| − | * '''Source''' | + | *'''Reason''' - an optional internal explanation. |
| − | * '''Reason''' | + | *'''Expires At''' - the expiration date; '' 'Never' '' indicates a permanent block. |
| − | * '''Expires At''' | + | *'''Created At''' - when the entry was created. |
| − | * '''Created At''' | + | |
| − | + | Press the eye icon to view the complete reason when it is shortened in the table. Use the trash bin icon to delete an entry. | |
| + | |} | ||
| − | === Add Blocked Entry === | + | ===Add Blocked Entry=== |
{| | {| | ||
| − | |style="padding: | + | |style="padding: 10px 0px 15px 15px;"|Press '' 'Add Blocked Entry' '' and configure: |
| − | * '''Type''' | + | |
| − | + | *'''Type''' - select '' 'Email', '' '' 'IP Address' '' or '' 'Email Domain'. '' | |
| − | + | *'''Value''' - enter a value matching the selected type. | |
| − | + | *'''Reason (Optional)''' - enter an internal note explaining the entry. | |
| − | * '''Value''' | + | *'''Expires At (Optional)''' - select an expiration date or leave the field empty to create a permanent block. |
| − | * '''Reason (Optional)''' | + | |
| − | * '''Expires At (Optional)''' | + | Press '' 'Confirm' '' to add the entry. |
| − | Press '''Confirm''' to add the entry. | + | |} |
| − | |style="padding: 0px 0px | + | {| |
| + | |style="padding: 0px 0px 30px 25px;"|[[File:AFEV_8.png]] | ||
|} | |} | ||
| − | + | ==Settings== | |
| + | {| | ||
| + | |style="padding: 10px 0px 15px 15px;"|The '' 'Settings' '' section controls the verification workflow, reminders, account lifecycle and anti-fraud protection.<br/> | ||
| + | The options are divided into five panels. Press '' 'Submit' '' to save the configuration. | ||
| + | |} | ||
| + | {| | ||
| + | |style="padding: 0px 0px 20px 25px;"|[[File:AFEV_9.png]] | ||
| + | |} | ||
| − | == | + | ===Verification Mode=== |
{| | {| | ||
| − | |style="padding: | + | |style="padding: 10px 0px 15px 15px;"| |
| − | + | *'''Verification Mode''' - choose where verification is required: | |
| − | + | ** '''All Pages''' - locks the entire client area until verification is completed. | |
| + | ** '''Checkout''' - prevents an unverified client from placing an order. | ||
| + | *'''Verification Delivery''' - choose '' 'Clickable Link' '' or '' 'Code To Type In'. '' | ||
| + | *'''Verification Display''' - show the form as an '' 'Inline Form' '' or through a '' 'Modal Popup'. '' | ||
| + | *'''Checkout Token Validity (Days)''' - how long a link or code created in '' 'Checkout' '' mode remains valid. | ||
| + | *'''All Pages Token Validity (Days)''' - how long a link or code created in '' 'All Pages' '' mode remains valid. | ||
|} | |} | ||
| − | === | + | ===Reminders=== |
| − | + | {| | |
| − | + | |style="padding: 10px 0px 15px 15px;"| | |
| − | + | *'''Checkout Reminder After (Days)''' - send a reminder this many days after an unverified checkout attempt. Enter '''0''' to disable it. | |
| − | + | *'''All Pages Reminder After (Days)''' - send a reminder this many days after registration if still unverified. Enter '''0''' to disable it. | |
| − | + | *'''Resend Cooldown (Minutes)''' - the minimum wait before another verification email can be requested. | |
| − | + | |} | |
| − | * ''' | + | |
| − | + | ||
| − | + | ||
| − | + | ||
| − | * ''' | + | |
| − | === | + | ===Account Lifecycle=== |
| − | + | {| | |
| − | + | |style="padding: 10px 0px 15px 15px;"|These options automate actions against client accounts that remain unverified: | |
| − | + | ||
| − | + | *'''Checkout Auto-Inactivate After (Days)''' - set the account to '' 'Inactive' '' after this many unverified days following checkout. Enter '''0''' to disable it. | |
| − | + | *'''All Pages Auto-Inactivate After (Days)''' - set the account to '' 'Inactive' '' after this many unverified days following registration. Enter '''0''' to disable it. | |
| − | + | *'''Checkout Auto-Terminate After (Days)''' - permanently remove the client and all WHMCS data after this many unverified days following checkout. Enter '''0''' to disable it. | |
| + | *'''All Pages Auto-Terminate After (Days)''' - permanently remove the client and all WHMCS data after this many unverified days following registration. Enter '''0''' to disable it. | ||
| + | *'''Auto-Delete Unverified Accounts''' - enable automatic cleanup of unverified accounts without active orders. | ||
| + | *'''Auto-Delete After (Days)''' - define the delay after Auto-Terminate before an eligible account is closed.<br/><br/> | ||
| − | + | '''''Important:''' Auto-Terminate actions are permanent and irreversible and may remove the client account together with all related WHMCS data. Review these settings carefully before enabling them in production.'' | |
| − | + | |} | |
| − | + | ||
| − | + | ||
| − | + | ||
| − | + | ||
| − | + | <!-- TODO FINAL: Confirm the exact relationship between Auto-Terminate and Auto-Delete. --> | |
| − | + | ===Rate Limiting & Anti-Fraud=== | |
| + | {| | ||
| + | |style="padding: 10px 0px 15px 15px;"| | ||
| + | *'''Rate Limit: Max Attempts''' - the maximum attempts allowed within the configured window. | ||
| + | *'''Rate Limit: Window (Minutes)''' - the rolling period used to count verification attempts. | ||
| + | *'''Auto-Ban After Failed Attempts''' - automatically block the related email address and IP address after this many failures. Enter '''0''' to disable it. | ||
| + | *'''Auto-Ban Window (Minutes)''' - the rolling period used to count failed attempts for automatic bans. | ||
| + | |} | ||
| − | + | <!-- TODO FINAL: Confirm the number, type and duration of automatically created blocklist entries. --> | |
| − | + | ||
| − | + | ||
| − | + | ||
| − | + | ||
| − | + | ===CAPTCHA=== | |
| + | {| | ||
| + | |style="padding: 10px 0px 15px 15px;"| | ||
| + | *'''CAPTCHA Enabled''' - require a CAPTCHA challenge on verification and resend forms. | ||
| + | *'''CAPTCHA Provider''' - choose: | ||
| + | ** '''Built-In (Arithmetic Challenge)''' - requires no external account. | ||
| + | ** '''reCAPTCHA V3''' - requires a Google site key and secret key. | ||
| + | ** '''Cloudflare Turnstile''' - requires a Cloudflare site key and secret key. | ||
| − | + | When an external provider is selected, configure the corresponding '' 'Site Key' '' and '' 'Secret Key'. '' For reCAPTCHA V3, also set the '' 'Minimum Score' '' between '''0''' and '''1'''; lower scores indicate traffic more likely to be automated. | |
| + | |} | ||
| − | === | + | ==Client Area== |
| − | + | {| | |
| − | + | |style="padding: 10px 0px 15px 15px;"|When verification is required, the client sees the '' 'Email Verification' '' page with the account email address.<br/> | |
| − | + | The exact form depends on the selected delivery and display options. In the example below, a verification link has already been sent and the client can press '' 'Resend' '' if it did not arrive or expired. | |
| − | + | |} | |
| − | + | {| | |
| + | |style="padding: 0px 0px 20px 25px;"|[[File:AFEV_10.png]] | ||
| + | |} | ||
| + | {| | ||
| + | |style="padding: 0px 0px 15px 15px;"|The available flows are: | ||
| − | + | *'''Clickable Link''' - open the link received by email. | |
| − | * ''' | + | *'''Code To Type In''' - enter the email address and code in the verification form. |
| − | * ''' | + | *'''Inline Form''' - display the form directly on the page. |
| − | * ''' | + | *'''Modal Popup''' - open the form in a modal window. |
| − | + | ||
| − | * ''' | + | |
| − | + | If CAPTCHA is enabled, the selected challenge is also shown. After successful verification, the client can continue to the restricted page or complete checkout. | |
| − | + | |} | |
| − | + | ||
| − | <!-- TODO FINAL: | + | <!-- TODO FINAL: Confirm the exact redirect and add final screenshots for all applicable flows. --> |
| − | = | + | ==[https://www.docs.modulesgarden.com/Logs Logs]== |
{| | {| | ||
| − | |style="padding: 0px | + | |style="padding: 10px 0px 5px 15px;"|The '' "Logs" '' tool makes monitoring and managing module activity records simple and efficient. It provides options to categorize, filter and view detailed entries, giving you control over the logs.<br/> |
| − | + | For detailed guidance, check its dedicated article, available [https://www.docs.modulesgarden.com/Logs here]. | |
| − | |style="padding: 0px 0px | + | |} |
| + | {| | ||
| + | |style="padding: 0px 0px 30px 25px;"|[[File:AFEV_11.png]] | ||
|} | |} | ||
| − | + | =Tips= | |
| − | + | {| | |
| − | + | |style="padding: 10px 0px 15px 15px;"|1. '''Test every verification flow before applying restrictions to all clients.'''<br/> | |
| − | + | Use a test account to check the selected delivery method, display mode, email and redirect behavior. | |
| − | + | |} | |
| + | {| | ||
| + | |style="padding: 0px 0px 15px 15px;"|2. '''Use reminders and account inactivation before enabling permanent account removal.'''<br/> | ||
| + | This gives legitimate clients additional time to complete verification and reduces the risk of unintended data loss. | ||
| + | |} | ||
| + | {| | ||
| + | |style="padding: 0px 0px 15px 15px;"|3. '''Set a resend cooldown and reasonable rate limits.'''<br/> | ||
| + | These measures reduce repeated email requests while allowing legitimate clients to try again after a short wait. | ||
| + | |} | ||
| + | {| | ||
| + | |style="padding: 0px 0px 30px 15px;"|4. '''Review the blocklist and logs regularly.'''<br/> | ||
| + | Check automatically created entries and repeated failures before removing a block or changing the anti-fraud thresholds. | ||
| + | |} | ||
| − | + | =Update Instructions= | |
| + | {| | ||
| + | |style="padding: 10px 0px 30px 15px;"|An essential guide to updating the module is available '''[https://www.docs.modulesgarden.com/How_To_Update_WHMCS_Module here]'''.<br/> | ||
| + | Follow every step carefully to prevent data loss or other unexpected issues. | ||
| + | |} | ||
| − | + | =Upgrade Guide= | |
| + | {| | ||
| + | |style="padding: 10px 0px 30px 15px;"|Looking for greater flexibility, custom modifications and unrestricted access to the source code?<br/> | ||
| + | Choose the [https://www.modulesgarden.com/products/whmcs/anti-fraud-email-verification#open-source-version Open Source version] of Anti-Fraud & Email Verification For WHMCS to receive these benefits together with prioritized support services.<br/><br/> | ||
| + | Press '' 'Get Source Code' '' or '' 'Upgrade To Lifetime' '' on the product page in our client area to complete the upgrade, with a '''dedicated discount''' already applied.<br/> | ||
| + | Follow the [https://www.docs.modulesgarden.com/How_To_Upgrade_WHMCS_Module comprehensive guide] for the complete transition process. | ||
| + | |} | ||
| − | = | + | =Common Problems= |
{| | {| | ||
| − | |style="padding: | + | |style="padding: 10px 0px 15px 15px;"|'''1. The client does not receive the verification email.'''<br/> |
| + | Check the module and WHMCS mail logs, verify the mail configuration and ask the client to check the spam folder. Wait until the '' 'Resend Cooldown' '' ends before trying again. | ||
|} | |} | ||
{| | {| | ||
| − | |style="padding: | + | |style="padding: 10px 0px 15px 15px;"|'''2. The verification link or code is rejected.'''<br/> |
| + | The verification details may have expired, already been used or may not match the pending record. Request a new message and use the newest link or code within its validity period. | ||
|} | |} | ||
{| | {| | ||
| − | |style="padding: | + | |style="padding: 10px 0px 15px 15px;"|'''3. The client cannot request another verification email.'''<br/> |
| + | The resend cooldown or rate limit may have been reached. Wait until the relevant window ends or review the limits under '' 'Settings'. '' | ||
|} | |} | ||
{| | {| | ||
| − | |style="padding: | + | |style="padding: 10px 0px 15px 15px;"|'''4. A legitimate client cannot complete verification.'''<br/> |
| + | The client's email address, domain or IP address may be on the blocklist. Review '' 'Blocklist' '' and '' 'Logs', '' then remove the entry only after confirming the request is legitimate. | ||
|} | |} | ||
| − | + | {| | |
| − | + | |style="padding: 10px 0px 30px 15px;"|'''5. External CAPTCHA verification fails.'''<br/> | |
| − | + | Confirm that the site and secret keys are correct and assigned to the WHMCS domain. For reCAPTCHA V3, also review the minimum score. | |
| − | + | ||
| − | + | ||
| − | + | ||
| − | | | + | |
| − | + | ||
| − | + | ||
| − | + | ||
| − | + | ||
| − | + | ||
| − | + | ||
| − | + | ||
| − | + | ||
| − | + | ||
| − | + | ||
| − | + | ||
| − | + | ||
| − | + | ||
| − | + | ||
| − | + | ||
| − | + | ||
| − | + | ||
| − | + | ||
| − | + | ||
|} | |} | ||
| − | <!-- END OF FIRST DRAFT --> | + | <!-- END OF FIRST DRAFT - FINAL BEHAVIOR, PRODUCT LINKS AND SCREEN NAMES TO BE VERIFIED BEFORE PUBLICATION --> |
Revision as of 13:04, 2 September 2026
Contents |
About Anti-Fraud & Email Verification For WHMCS
| Anti-Fraud & Email Verification For WHMCS enables you to verify client email addresses during checkout or before granting access to the client area. The module can deliver a clickable verification link or a code for the client to enter manually, while the verification form may be displayed directly on the page or in a modal window. |
- Core Features:
| ✔ Require Client Email Verification During Checkout Or Before Client Area Access |
| ✔ Deliver Verification Through Clickable Links Or Codes Entered Manually |
| ✔ Display Verification Forms Inline Or In Modal Windows |
| ✔ Automate Reminders And Management Of Accounts That Remain Unverified |
| ✔ Protect Verification Forms With CAPTCHA, Rate Limiting And Automatic Bans |
- Addon Module:
| ✔ View Verification Activity From The Last 30 Days |
| ✔ View And Filter Email Verification Records By Status: |
| ✔ Pending |
| ✔ Verified |
| ✔ Rejected |
| ✔ Expired |
| ✔ Review Verification Mode, Status And Important Dates |
| ✔ Mark Verification Records As Unverified |
| ✔ Delete Verification Records |
| ✔ Manage Blocklist Entries For Email Addresses, IP Addresses And Email Domains |
| ✔ Create Permanent Or Time-Limited Blocklist Entries |
| ✔ View Manually And Automatically Added Blocklist Entries |
| ✔ Select Checkout Or All Pages Verification Mode |
| ✔ Deliver Verification Through Clickable Link Or Code To Type In |
| ✔ Display Verification As Inline Form Or Modal Popup |
| ✔ Define Verification Link And Code Validity Periods |
| ✔ Configure Verification Reminders And Resend Cooldown |
| ✔ Automatically Set Unverified Client Accounts To Inactive |
| ✔ Configure Automatic Termination And Deletion Of Unverified Accounts |
| ✔ Configure Verification Attempt Rate Limits And Automatic Bans |
| ✔ Protect Verification Forms With Built-In CAPTCHA, reCAPTCHA V3 Or Cloudflare Turnstile |
| ✔ View And Manage Module Logs |
- Client Area:
| ✔ Verify Email Address To Place Orders Or Access Client Area |
| ✔ Verify Email Address Through Clickable Link Or Verification Code |
| ✔ Request Another Verification Email |
| ✔ Complete CAPTCHA Challenge When Enabled |
- General Info:
| ✔ Multi-Language Support |
| ✔ Supports PHP 8.3 Back To PHP 8.2 |
| ✔ Supports WHMCS Themes "Twenty-One" And "Nexus" |
| ✔ Supports WHMCS V9.X |
| ✔ Requires ionCube Loader V14 Or Later |
| ✔ Easy Module Upgrade To Open Source Version |
Installation
| This tutorial will show you how to successfully install and configure Anti-Fraud & Email Verification For WHMCS. We will guide you step by step through the whole installation and configuration process. |
| 1. Log in to our client area and download the module. |
| File:AFEV download.png |
| 2. Extract the package and upload its content into the main WHMCS directory. The content of the package to upload should look like this. |
| File:AFEV package.png |
| 3. When you install Anti-Fraud & Email Verification For WHMCS for the first time, rename the 'license_RENAME.php' file. The file is located in 'modules/addons/EmailVerificationAntiFraud/license_RENAME.php'. Rename it from 'license_RENAME.php' to 'license.php'. |
|
| 4. To configure your license key, edit the previously renamed 'license.php' file. Enter your license key between quotation marks, as shown on the following screen. You can find the license key in our client area under 'My Products'. |
| File:AFEV license2.png |
| 5. Activate the module in your WHMCS system. Go to 'System Settings' → 'Addon Modules'. Find 'Anti-Fraud & Email Verification' and press 'Activate'. |
| File:AFEV 2.png |
| 6. Permit access to the module. Press 'Configure', select the required administrator roles under 'Access Control', and press 'Save Changes'. |
| File:AFEV 1.png |
| 7. You have successfully installed Anti-Fraud & Email Verification For WHMCS! You can access the module under 'Addons' → 'Anti-Fraud & Email Verification'. |
Management
| Anti-Fraud & Email Verification For WHMCS lets you control when clients must confirm their email addresses and provides tools to manage the complete verification lifecycle. In this guide, we will walk you through every section and option of the module in detail. |
Dashboard
| The dashboard presents a chart of verification activity recorded during the last 30 days. It compares successfully 'Verified' records with 'Unverified' attempts, helping you quickly review recent activity and trends. |
| File:AFEV 3.png |
Verifications
| The 'Verifications' section contains all email verification records created by the module. Five counters provide a quick overview:
Press 'Show' on a counter to filter the table by the selected status. |
| File:AFEV 4.png |
The table lists:
Use the search field to find a record. The row actions allow you to mark it as unverified or delete it. |
Mark As Unverified
| Press the 'Mark As Unverified' icon to return a record to 'Pending', then confirm the action. Important: This changes the verification status only. It does not undo any order or account action already taken while the address was considered verified. |
|
Delete Verification Record
| Press the trash bin icon to permanently remove the selected verification record. The related WHMCS client account and order, if any, remain unaffected. This action cannot be undone. |
|
Blocklist
| The 'Blocklist' prevents selected email addresses, IP addresses and complete email domains from using the verification process. Entries may be added manually or created automatically after the configured number of failed attempts is reached. |
|
The table includes:
Press the eye icon to view the complete reason when it is shortened in the table. Use the trash bin icon to delete an entry. |
Add Blocked Entry
Press 'Add Blocked Entry' and configure:
Press 'Confirm' to add the entry. |
| File:AFEV 8.png |
Settings
| The 'Settings' section controls the verification workflow, reminders, account lifecycle and anti-fraud protection. The options are divided into five panels. Press 'Submit' to save the configuration. |
| File:AFEV 9.png |
Verification Mode
|
Reminders
|
Account Lifecycle
These options automate actions against client accounts that remain unverified:
Important: Auto-Terminate actions are permanent and irreversible and may remove the client account together with all related WHMCS data. Review these settings carefully before enabling them in production. |
Rate Limiting & Anti-Fraud
|
CAPTCHA
When an external provider is selected, configure the corresponding 'Site Key' and 'Secret Key'. For reCAPTCHA V3, also set the 'Minimum Score' between 0 and 1; lower scores indicate traffic more likely to be automated. |
Client Area
| When verification is required, the client sees the 'Email Verification' page with the account email address. The exact form depends on the selected delivery and display options. In the example below, a verification link has already been sent and the client can press 'Resend' if it did not arrive or expired. |
| File:AFEV 10.png |
The available flows are:
If CAPTCHA is enabled, the selected challenge is also shown. After successful verification, the client can continue to the restricted page or complete checkout. |
Logs
| The "Logs" tool makes monitoring and managing module activity records simple and efficient. It provides options to categorize, filter and view detailed entries, giving you control over the logs. For detailed guidance, check its dedicated article, available here. |
| File:AFEV 11.png |
Tips
| 1. Test every verification flow before applying restrictions to all clients. Use a test account to check the selected delivery method, display mode, email and redirect behavior. |
| 2. Use reminders and account inactivation before enabling permanent account removal. This gives legitimate clients additional time to complete verification and reduces the risk of unintended data loss. |
| 3. Set a resend cooldown and reasonable rate limits. These measures reduce repeated email requests while allowing legitimate clients to try again after a short wait. |
| 4. Review the blocklist and logs regularly. Check automatically created entries and repeated failures before removing a block or changing the anti-fraud thresholds. |
Update Instructions
| An essential guide to updating the module is available here. Follow every step carefully to prevent data loss or other unexpected issues. |
Upgrade Guide
| Looking for greater flexibility, custom modifications and unrestricted access to the source code? Choose the Open Source version of Anti-Fraud & Email Verification For WHMCS to receive these benefits together with prioritized support services. |
Common Problems
| 1. The client does not receive the verification email. Check the module and WHMCS mail logs, verify the mail configuration and ask the client to check the spam folder. Wait until the 'Resend Cooldown' ends before trying again. |
| 2. The verification link or code is rejected. The verification details may have expired, already been used or may not match the pending record. Request a new message and use the newest link or code within its validity period. |
| 3. The client cannot request another verification email. The resend cooldown or rate limit may have been reached. Wait until the relevant window ends or review the limits under 'Settings'. |
| 4. A legitimate client cannot complete verification. The client's email address, domain or IP address may be on the blocklist. Review 'Blocklist' and 'Logs', then remove the entry only after confirming the request is legitimate. |
| 5. External CAPTCHA verification fails. Confirm that the site and secret keys are correct and assigned to the WHMCS domain. For reCAPTCHA V3, also review the minimum score. |



