Anti-Fraud And Email Verification For WHMCS
(→About Anti-Fraud & Email Verification For WHMCS) |
|||
| Line 5: | Line 5: | ||
{| | {| | ||
|style="padding: 10px 0px 10px 0px;"|'''Anti-Fraud & Email Verification For WHMCS''' enables you to verify client email addresses during checkout or before granting access to the client area.<br/> | |style="padding: 10px 0px 10px 0px;"|'''Anti-Fraud & Email Verification For WHMCS''' enables you to verify client email addresses during checkout or before granting access to the client area.<br/> | ||
| − | The module can deliver a clickable verification link or a code for the client to enter manually | + | The module can deliver a clickable verification link or a code for the client to enter manually.<br/> |
Configurable validity periods, reminders, account lifecycle actions, CAPTCHA protection, rate limiting and blocklist management give you greater control over client verification and help reduce fraudulent activity. | Configurable validity periods, reminders, account lifecycle actions, CAPTCHA protection, rate limiting and blocklist management give you greater control over client verification and help reduce fraudulent activity. | ||
|} | |} | ||
| Line 15: | Line 15: | ||
{| | {| | ||
|style="padding: 0px 0px 0px 30px;"|✔ Deliver Verification Through Clickable Links Or Codes Entered Manually | |style="padding: 0px 0px 0px 30px;"|✔ Deliver Verification Through Clickable Links Or Codes Entered Manually | ||
| − | |||
| − | |||
| − | |||
|} | |} | ||
{| | {| | ||
| Line 46: | Line 43: | ||
|} | |} | ||
{| | {| | ||
| − | |style="padding: 0px 0px 0px 30px;"|✔ Review Verification | + | |style="padding: 0px 0px 0px 30px;"|✔ Review Verification Status And Important Dates |
|} | |} | ||
{| | {| | ||
| Line 70: | Line 67: | ||
|} | |} | ||
{| | {| | ||
| − | + | |style="padding: 0px 0px 0px 30px;"|✔ Define Verification Link And Code Validity Period | |
| − | + | ||
| − | + | ||
| − | |style="padding: 0px 0px 0px 30px;"|✔ Define Verification Link And Code Validity | + | |
|} | |} | ||
{| | {| | ||
| Line 88: | Line 82: | ||
|} | |} | ||
{| | {| | ||
| − | |style="padding: 0px 0px 0px 30px;"|✔ Protect Verification Forms With | + | |style="padding: 0px 0px 0px 30px;"|✔ Protect Verification Forms With CAPTCHA Configured In WHMCS |
| + | |} | ||
| + | {| | ||
| + | |style="padding: 0px 0px 0px 30px;"|✔ Control Administrator Access To Module Sections And Actions | ||
| + | |} | ||
| + | {| | ||
| + | |style="padding: 0px 0px 0px 30px;"|✔ View And Manage Module Logs | ||
|} | |} | ||
{| | {| | ||
| − | |style="padding: 0px 0px 10px 30px;"|✔ | + | |style="padding: 0px 0px 10px 30px;"|✔ Customize Module Interface In Admin And Client Areas Using Built-In Theme Management Tool |
|} | |} | ||
| Line 130: | Line 130: | ||
=Installation= | =Installation= | ||
{| | {| | ||
| − | |style="padding: 10px 0px 5px 0px;"|'''This tutorial will show you how to successfully install and configure [https://www.modulesgarden.com/products/whmcs/anti-fraud-email-verification Anti-Fraud & Email Verification For WHMCS.]''' <br /> | + | |style="padding: 10px 0px 5px 0px;"|'''This tutorial will show you how to successfully install and configure [https://www.modulesgarden.com/products/whmcs/anti-fraud-and-email-verification Anti-Fraud & Email Verification For WHMCS.]''' <br /> |
We will guide you step by step through the whole installation and configuration process. | We will guide you step by step through the whole installation and configuration process. | ||
|} | |} | ||
| Line 178: | Line 178: | ||
You can access the module under '' 'Addons' '' → '' 'Anti-Fraud & Email Verification'. '' | You can access the module under '' 'Addons' '' → '' 'Anti-Fraud & Email Verification'. '' | ||
|} | |} | ||
| − | |||
| − | |||
=Management= | =Management= | ||
| Line 189: | Line 187: | ||
==Dashboard== | ==Dashboard== | ||
{| | {| | ||
| − | |style="padding: 10px 0px 15px 15px;"|The dashboard | + | |style="padding: 10px 0px 15px 15px;"|The dashboard provides an overview of recent verification and anti-fraud activity.<br/> |
| − | + | The '' 'Anti-Fraud Activity Summary' '' shows the numbers of failed verification attempts, rate-limited requests, automatic blocklist entries, failed CAPTCHA challenges and resent verification emails recorded today, during the last 7 days and during the last 30 days.<br/><br/> | |
| + | The '' 'Verifications Over Time' '' chart compares verified and unverified records from the last 30 days, helping you identify recent activity and trends. | ||
|} | |} | ||
{| | {| | ||
| − | |style="padding: 0px 0px 30px 25px;"|[[File: | + | |style="padding: 0px 0px 30px 25px;"|[[File:Anti-Fraud_And_Email_Verification_5.png]] |
|} | |} | ||
| Line 210: | Line 209: | ||
|} | |} | ||
{| | {| | ||
| − | |style="padding: 0px 0px 20px 25px;"|[[File: | + | |style="padding: 0px 0px 20px 25px;"|[[File:Anti-Fraud_And_Email_Verification_6.png]] |
|} | |} | ||
{| | {| | ||
| Line 216: | Line 215: | ||
*'''Email''' - the email address used for verification. | *'''Email''' - the email address used for verification. | ||
| − | |||
*'''Status''' - '' 'Pending', '' '' 'Verified', '' '' 'Rejected' '' or '' 'Expired'. '' | *'''Status''' - '' 'Pending', '' '' 'Verified', '' '' 'Rejected' '' or '' 'Expired'. '' | ||
*'''Created At''' - when the verification was initiated. | *'''Created At''' - when the verification was initiated. | ||
| Line 249: | Line 247: | ||
|} | |} | ||
{| | {| | ||
| − | |style="padding: 0px 0px 20px 25px;"|[[File: | + | |style="padding: 0px 0px 20px 25px;"|[[File:Anti-Fraud_And_Email_Verification_7.png]] |
|} | |} | ||
{| | {| | ||
| Line 276: | Line 274: | ||
|} | |} | ||
{| | {| | ||
| − | |style="padding: 0px 0px 30px 25px;"|[[File: | + | |style="padding: 0px 0px 30px 25px;"|[[File:Anti-Fraud_And_Email_Verification_8.png]] |
|} | |} | ||
| Line 282: | Line 280: | ||
{| | {| | ||
|style="padding: 10px 0px 15px 15px;"|The '' 'Settings' '' section controls the verification workflow, reminders, account lifecycle and anti-fraud protection.<br/> | |style="padding: 10px 0px 15px 15px;"|The '' 'Settings' '' section controls the verification workflow, reminders, account lifecycle and anti-fraud protection.<br/> | ||
| − | The options are divided into | + | The options are divided into four panels. Press '' 'Submit' '' to save the configuration. |
|} | |} | ||
{| | {| | ||
| − | |style="padding: 0px 0px 20px 25px;"|[[File: | + | |style="padding: 0px 0px 20px 25px;"|[[File:Anti-Fraud_And_Email_Verification_9.png]] |
|} | |} | ||
| Line 295: | Line 293: | ||
** '''Checkout''' - prevents an unverified client from placing an order. | ** '''Checkout''' - prevents an unverified client from placing an order. | ||
*'''Verification Delivery''' - choose '' 'Clickable Link' '' or '' 'Code To Type In'. '' | *'''Verification Delivery''' - choose '' 'Clickable Link' '' or '' 'Code To Type In'. '' | ||
| − | *''' | + | *'''Token Validity (Days)''' - define how long the generated verification link or code remains valid. |
| − | + | ||
| − | + | ||
|} | |} | ||
| Line 303: | Line 299: | ||
{| | {| | ||
|style="padding: 10px 0px 15px 15px;"| | |style="padding: 10px 0px 15px 15px;"| | ||
| − | *''' | + | *'''Reminder After (Days)''' - send a reminder email after the client has remained unverified for the specified number of days. Enter '''0''' to disable reminders. |
| − | + | ||
*'''Resend Cooldown (Minutes)''' - the minimum wait before another verification email can be requested. | *'''Resend Cooldown (Minutes)''' - the minimum wait before another verification email can be requested. | ||
|} | |} | ||
| Line 312: | Line 307: | ||
|style="padding: 10px 0px 15px 15px;"|These options automate actions against client accounts that remain unverified: | |style="padding: 10px 0px 15px 15px;"|These options automate actions against client accounts that remain unverified: | ||
| − | *''' | + | *'''Auto-Inactivate After (Days)''' - set the client account to '' 'Inactive' '' after it has remained unverified for the specified number of days. Enter '''0''' to disable this action. |
| − | + | *'''Auto-Terminate After (Days)''' - permanently and irreversibly delete the client account and all of its WHMCS data after the specified number of unverified days. Enter '''0''' to disable this action. | |
| − | *''' | + | |
| − | + | ||
*'''Auto-Delete Unverified Accounts''' - enable automatic cleanup of unverified accounts without active orders. | *'''Auto-Delete Unverified Accounts''' - enable automatic cleanup of unverified accounts without active orders. | ||
*'''Auto-Delete After (Days)''' - define the delay after Auto-Terminate before an eligible account is closed.<br/><br/> | *'''Auto-Delete After (Days)''' - define the delay after Auto-Terminate before an eligible account is closed.<br/><br/> | ||
| Line 321: | Line 314: | ||
'''''Important:''' Auto-Terminate actions are permanent and irreversible and may remove the client account together with all related WHMCS data. Review these settings carefully before enabling them in production.'' | '''''Important:''' Auto-Terminate actions are permanent and irreversible and may remove the client account together with all related WHMCS data. Review these settings carefully before enabling them in production.'' | ||
|} | |} | ||
| − | |||
| − | |||
===Rate Limiting & Anti-Fraud=== | ===Rate Limiting & Anti-Fraud=== | ||
| Line 331: | Line 322: | ||
*'''Auto-Ban After Failed Attempts''' - automatically block the related email address and IP address after this many failures. Enter '''0''' to disable it. | *'''Auto-Ban After Failed Attempts''' - automatically block the related email address and IP address after this many failures. Enter '''0''' to disable it. | ||
*'''Auto-Ban Window (Minutes)''' - the rolling period used to count failed attempts for automatic bans. | *'''Auto-Ban Window (Minutes)''' - the rolling period used to count failed attempts for automatic bans. | ||
| − | + | *'''Enable Captcha Verification''' - require a CAPTCHA challenge during email verification. The module uses the CAPTCHA type and credentials configured in WHMCS.<br/><br/> | |
| − | + | Before enabling this option, go to '' 'System Settings' '' → '' 'General Settings' '' → '' 'Security' '' in WHMCS and configure CAPTCHA.<br/> | |
| − | + | '''''Important:''' If CAPTCHA verification is enabled in the module but CAPTCHA has not been configured correctly in WHMCS, clients will encounter an error when attempting to complete verification.'' | |
| − | + | ||
| − | + | ||
| − | + | ||
| − | + | ||
| − | + | ||
| − | + | ||
| − | + | ||
| − | + | ||
| − | + | ||
| − | + | ||
|} | |} | ||
| Line 350: | Line 331: | ||
{| | {| | ||
|style="padding: 10px 0px 15px 15px;"|When verification is required, the client sees the '' 'Email Verification' '' page with the account email address.<br/> | |style="padding: 10px 0px 15px 15px;"|When verification is required, the client sees the '' 'Email Verification' '' page with the account email address.<br/> | ||
| − | The exact | + | The exact verification flow depends on the selected delivery method. The client can press '' 'Resend' '' to request another verification email after the configured cooldown period. |
|} | |} | ||
{| | {| | ||
| − | |style="padding: 0px 0px 20px 25px;"|[[File: | + | |style="padding: 0px 0px 20px 25px;"|[[File:Anti-Fraud_And_Email_Verification_1.png]] |
|} | |} | ||
{| | {| | ||
|style="padding: 0px 0px 15px 15px;"|The available flows are: | |style="padding: 0px 0px 15px 15px;"|The available flows are: | ||
| − | *'''Clickable Link''' - open the link received | + | *'''Clickable Link''' - open the link received in the verification email and complete any required CAPTCHA challenge. |
| − | *'''Code To Type In''' - enter the | + | *'''Code To Type In''' - enter the code received in the verification email in the form and press '' 'Verify'. '' |
| − | + | ||
| − | + | ||
| − | If | + | If '' 'Enable Captcha Verification' '' is active, the CAPTCHA configured in WHMCS is also displayed. After successful verification, the client can continue to the restricted page or complete checkout. |
| + | |} | ||
| + | {| | ||
| + | |style="padding: 0px 0px 20px 25px;"|[[File:Anti-Fraud_And_Email_Verification_2.png]] | ||
| + | |} | ||
| + | {| | ||
| + | |style="padding: 0px 0px 15px 15px;"|The verification email contains either a clickable verification link or a one-time code, depending on the selected delivery method. | ||
| + | |} | ||
| + | {| | ||
| + | |style="padding: 0px 0px 20px 25px;"|[[File:Anti-Fraud_And_Email_Verification_4.png]] | ||
| + | |} | ||
| + | {| | ||
| + | |style="padding: 0px 0px 15px 15px;"|If an unverified client attempts to place an order while '' 'Checkout' '' mode is enabled, WHMCS prevents the order from being completed and asks the client to verify the email address first. | ||
| + | |} | ||
| + | {| | ||
| + | |style="padding: 0px 0px 30px 25px;"|[[File:Anti-Fraud_And_Email_Verification_3.png]] | ||
|} | |} | ||
| − | < | + | ==[https://www.docs.modulesgarden.com/Access_Control Access Control]== |
| + | {| | ||
| + | |style="padding: 10px 0px 15px 15px;"|The '' 'Access Control' '' tool allows you to restrict administrator access to individual module sections and actions.<br/> | ||
| + | Create rules and assign them to selected administrators or administrator roles. For each rule, define the resources that should be available or restricted. | ||
| + | |} | ||
| + | {| | ||
| + | |style="padding: 0px 0px 20px 25px;"|[[File:Anti-Fraud_And_Email_Verification_10.png]] | ||
| + | |} | ||
| + | {| | ||
| + | |style="padding: 0px 0px 15px 15px;"|The '' 'Resources' '' tab lists the module resources available for access rules. Use the switches in the '' 'Log' '' column to decide which resource actions should be recorded in the access control logs.<br/> | ||
| + | For detailed instructions, see the dedicated [https://www.docs.modulesgarden.com/Access_Control Access Control documentation]. | ||
| + | |} | ||
| + | {| | ||
| + | |style="padding: 0px 0px 30px 25px;"|[[File:Anti-Fraud_And_Email_Verification_11.png]] | ||
| + | |} | ||
==[https://www.docs.modulesgarden.com/Logs Logs]== | ==[https://www.docs.modulesgarden.com/Logs Logs]== | ||
| Line 374: | Line 382: | ||
|} | |} | ||
{| | {| | ||
| − | |style="padding: 0px 0px 30px 25px;"|[[File: | + | |style="padding: 0px 0px 30px 25px;"|[[File:Anti-Fraud_And_Email_Verification_12.png]] |
| + | |} | ||
| + | |||
| + | ==[https://www.docs.modulesgarden.com/Theme_Management_Tool Themes]== | ||
| + | {| | ||
| + | |style="padding: 10px 0px 15px 15px;"|The '' 'Themes' '' tool allows you to customize the appearance of the module interface in the admin and client areas.<br/> | ||
| + | Create a new theme or activate an existing one separately for each area. The module includes the officially supported '' 'Default' '' and '' 'Dark' '' themes. | ||
| + | |} | ||
| + | {| | ||
| + | |style="padding: 0px 0px 20px 25px;"|[[File:Anti-Fraud_And_Email_Verification_13.png]] | ||
| + | |} | ||
| + | {| | ||
| + | |style="padding: 0px 0px 15px 15px;"|Theme settings allow you to adjust colors and styles for interface elements while checking the result in the live preview.<br/> | ||
| + | For detailed instructions, see the dedicated [https://www.docs.modulesgarden.com/Theme_Management_Tool Theme Management Tool documentation]. | ||
| + | |} | ||
| + | {| | ||
| + | |style="padding: 0px 0px 20px 25px;"|[[File:Anti-Fraud_And_Email_Verification_14.png]] | ||
| + | |} | ||
| + | {| | ||
| + | |style="padding: 0px 0px 15px 15px;"|The following screen presents the module dashboard with the officially supported '' 'Dark' '' theme enabled. | ||
| + | |} | ||
| + | {| | ||
| + | |style="padding: 0px 0px 30px 25px;"|[[File:Anti-Fraud_And_Email_Verification_15.png]] | ||
|} | |} | ||
| Line 380: | Line 410: | ||
{| | {| | ||
|style="padding: 10px 0px 15px 15px;"|1. '''Test every verification flow before applying restrictions to all clients.'''<br/> | |style="padding: 10px 0px 15px 15px;"|1. '''Test every verification flow before applying restrictions to all clients.'''<br/> | ||
| − | Use a test account to check the selected delivery method | + | Use a test account to check the selected delivery method, email content, CAPTCHA challenge and redirect behavior. |
|} | |} | ||
{| | {| | ||
| Line 404: | Line 434: | ||
{| | {| | ||
|style="padding: 10px 0px 30px 15px;"|Looking for greater flexibility, custom modifications and unrestricted access to the source code?<br/> | |style="padding: 10px 0px 30px 15px;"|Looking for greater flexibility, custom modifications and unrestricted access to the source code?<br/> | ||
| − | Choose the [https://www.modulesgarden.com/products/whmcs/anti-fraud-email-verification#open-source-version Open Source version] of Anti-Fraud & Email Verification For WHMCS to receive these benefits together with prioritized support services.<br/><br/> | + | Choose the [https://www.modulesgarden.com/products/whmcs/anti-fraud-and-email-verification#open-source-version Open Source version] of Anti-Fraud & Email Verification For WHMCS to receive these benefits together with prioritized support services.<br/><br/> |
Press '' 'Get Source Code' '' or '' 'Upgrade To Lifetime' '' on the product page in our client area to complete the upgrade, with a '''dedicated discount''' already applied.<br/> | Press '' 'Get Source Code' '' or '' 'Upgrade To Lifetime' '' on the product page in our client area to complete the upgrade, with a '''dedicated discount''' already applied.<br/> | ||
Follow the [https://www.docs.modulesgarden.com/How_To_Upgrade_WHMCS_Module comprehensive guide] for the complete transition process. | Follow the [https://www.docs.modulesgarden.com/How_To_Upgrade_WHMCS_Module comprehensive guide] for the complete transition process. | ||
| Line 427: | Line 457: | ||
|} | |} | ||
{| | {| | ||
| − | |style="padding: 10px 0px 30px 15px;"|'''5. | + | |style="padding: 10px 0px 30px 15px;"|'''5. CAPTCHA verification fails.'''<br/> |
| − | + | Go to '' 'System Settings' '' → '' 'General Settings' '' → '' 'Security' '' and confirm that CAPTCHA has been configured correctly in WHMCS before enabling it in the module. | |
|} | |} | ||
| − | |||
| − | |||
Revision as of 13:02, 8 September 2026
Contents |
About Anti-Fraud & Email Verification For WHMCS
| Anti-Fraud & Email Verification For WHMCS enables you to verify client email addresses during checkout or before granting access to the client area. The module can deliver a clickable verification link or a code for the client to enter manually. |
- Core Features:
| ✔ Require Client Email Verification During Checkout Or Before Client Area Access |
| ✔ Deliver Verification Through Clickable Links Or Codes Entered Manually |
| ✔ Automate Reminders And Management Of Accounts That Remain Unverified |
| ✔ Protect Verification Forms With CAPTCHA, Rate Limiting And Automatic Bans |
- Addon Module:
| ✔ View Verification Activity From The Last 30 Days |
| ✔ View And Filter Email Verification Records By Status: |
| ✔ Pending |
| ✔ Verified |
| ✔ Rejected |
| ✔ Expired |
| ✔ Review Verification Status And Important Dates |
| ✔ Mark Verification Records As Unverified |
| ✔ Delete Verification Records |
| ✔ Manage Blocklist Entries For Email Addresses, IP Addresses And Email Domains |
| ✔ Create Permanent Or Time-Limited Blocklist Entries |
| ✔ View Manually And Automatically Added Blocklist Entries |
| ✔ Select Checkout Or All Pages Verification Mode |
| ✔ Deliver Verification Through Clickable Link Or Code To Type In |
| ✔ Define Verification Link And Code Validity Period |
| ✔ Configure Verification Reminders And Resend Cooldown |
| ✔ Automatically Set Unverified Client Accounts To Inactive |
| ✔ Configure Automatic Termination And Deletion Of Unverified Accounts |
| ✔ Configure Verification Attempt Rate Limits And Automatic Bans |
| ✔ Protect Verification Forms With CAPTCHA Configured In WHMCS |
| ✔ Control Administrator Access To Module Sections And Actions |
| ✔ View And Manage Module Logs |
| ✔ Customize Module Interface In Admin And Client Areas Using Built-In Theme Management Tool |
- Client Area:
| ✔ Verify Email Address To Place Orders Or Access Client Area |
| ✔ Verify Email Address Through Clickable Link Or Verification Code |
| ✔ Request Another Verification Email |
| ✔ Complete CAPTCHA Challenge When Enabled |
- General Info:
| ✔ Multi-Language Support |
| ✔ Supports PHP 8.3 Back To PHP 8.2 |
| ✔ Supports WHMCS Themes "Twenty-One" And "Nexus" |
| ✔ Supports WHMCS V9.X |
| ✔ Requires ionCube Loader V14 Or Later |
| ✔ Easy Module Upgrade To Open Source Version |
Installation
| This tutorial will show you how to successfully install and configure Anti-Fraud & Email Verification For WHMCS. We will guide you step by step through the whole installation and configuration process. |
| 1. Log in to our client area and download the module. |
| File:AFEV download.png |
| 2. Extract the package and upload its content into the main WHMCS directory. The content of the package to upload should look like this. |
| File:AFEV package.png |
| 3. When you install Anti-Fraud & Email Verification For WHMCS for the first time, rename the 'license_RENAME.php' file. The file is located in 'modules/addons/EmailVerificationAntiFraud/license_RENAME.php'. Rename it from 'license_RENAME.php' to 'license.php'. |
|
| 4. To configure your license key, edit the previously renamed 'license.php' file. Enter your license key between quotation marks, as shown on the following screen. You can find the license key in our client area under 'My Products'. |
| File:AFEV license2.png |
| 5. Activate the module in your WHMCS system. Go to 'System Settings' → 'Addon Modules'. Find 'Anti-Fraud & Email Verification' and press 'Activate'. |
| File:AFEV 2.png |
| 6. Permit access to the module. Press 'Configure', select the required administrator roles under 'Access Control', and press 'Save Changes'. |
| File:AFEV 1.png |
| 7. You have successfully installed Anti-Fraud & Email Verification For WHMCS! You can access the module under 'Addons' → 'Anti-Fraud & Email Verification'. |
Management
| Anti-Fraud & Email Verification For WHMCS lets you control when clients must confirm their email addresses and provides tools to manage the complete verification lifecycle. In this guide, we will walk you through every section and option of the module in detail. |
Dashboard
| The dashboard provides an overview of recent verification and anti-fraud activity. The 'Anti-Fraud Activity Summary' shows the numbers of failed verification attempts, rate-limited requests, automatic blocklist entries, failed CAPTCHA challenges and resent verification emails recorded today, during the last 7 days and during the last 30 days. |
|
Verifications
| The 'Verifications' section contains all email verification records created by the module. Five counters provide a quick overview:
Press 'Show' on a counter to filter the table by the selected status. |
|
The table lists:
Use the search field to find a record. The row actions allow you to mark it as unverified or delete it. |
Mark As Unverified
| Press the 'Mark As Unverified' icon to return a record to 'Pending', then confirm the action. Important: This changes the verification status only. It does not undo any order or account action already taken while the address was considered verified. |
|
Delete Verification Record
| Press the trash bin icon to permanently remove the selected verification record. The related WHMCS client account and order, if any, remain unaffected. This action cannot be undone. |
|
Blocklist
| The 'Blocklist' prevents selected email addresses, IP addresses and complete email domains from using the verification process. Entries may be added manually or created automatically after the configured number of failed attempts is reached. |
|
The table includes:
Press the eye icon to view the complete reason when it is shortened in the table. Use the trash bin icon to delete an entry. |
Add Blocked Entry
Press 'Add Blocked Entry' and configure:
Press 'Confirm' to add the entry. |
|
Settings
| The 'Settings' section controls the verification workflow, reminders, account lifecycle and anti-fraud protection. The options are divided into four panels. Press 'Submit' to save the configuration. |
|
Verification Mode
|
Reminders
|
Account Lifecycle
These options automate actions against client accounts that remain unverified:
Important: Auto-Terminate actions are permanent and irreversible and may remove the client account together with all related WHMCS data. Review these settings carefully before enabling them in production. |
Rate Limiting & Anti-Fraud
Before enabling this option, go to 'System Settings' → 'General Settings' → 'Security' in WHMCS and configure CAPTCHA. |
Client Area
| When verification is required, the client sees the 'Email Verification' page with the account email address. The exact verification flow depends on the selected delivery method. The client can press 'Resend' to request another verification email after the configured cooldown period. |
|
The available flows are:
If 'Enable Captcha Verification' is active, the CAPTCHA configured in WHMCS is also displayed. After successful verification, the client can continue to the restricted page or complete checkout. |
|
| The verification email contains either a clickable verification link or a one-time code, depending on the selected delivery method. |
|
| If an unverified client attempts to place an order while 'Checkout' mode is enabled, WHMCS prevents the order from being completed and asks the client to verify the email address first. |
|
Access Control
| The 'Access Control' tool allows you to restrict administrator access to individual module sections and actions. Create rules and assign them to selected administrators or administrator roles. For each rule, define the resources that should be available or restricted. |
|
| The 'Resources' tab lists the module resources available for access rules. Use the switches in the 'Log' column to decide which resource actions should be recorded in the access control logs. For detailed instructions, see the dedicated Access Control documentation. |
|
Logs
| The "Logs" tool makes monitoring and managing module activity records simple and efficient. It provides options to categorize, filter and view detailed entries, giving you control over the logs. For detailed guidance, check its dedicated article, available here. |
|
Themes
| The 'Themes' tool allows you to customize the appearance of the module interface in the admin and client areas. Create a new theme or activate an existing one separately for each area. The module includes the officially supported 'Default' and 'Dark' themes. |
|
| Theme settings allow you to adjust colors and styles for interface elements while checking the result in the live preview. For detailed instructions, see the dedicated Theme Management Tool documentation. |
| File:Anti-Fraud And Email Verification 14.png |
| The following screen presents the module dashboard with the officially supported 'Dark' theme enabled. |
|
Tips
| 1. Test every verification flow before applying restrictions to all clients. Use a test account to check the selected delivery method, email content, CAPTCHA challenge and redirect behavior. |
| 2. Use reminders and account inactivation before enabling permanent account removal. This gives legitimate clients additional time to complete verification and reduces the risk of unintended data loss. |
| 3. Set a resend cooldown and reasonable rate limits. These measures reduce repeated email requests while allowing legitimate clients to try again after a short wait. |
| 4. Review the blocklist and logs regularly. Check automatically created entries and repeated failures before removing a block or changing the anti-fraud thresholds. |
Update Instructions
| An essential guide to updating the module is available here. Follow every step carefully to prevent data loss or other unexpected issues. |
Upgrade Guide
| Looking for greater flexibility, custom modifications and unrestricted access to the source code? Choose the Open Source version of Anti-Fraud & Email Verification For WHMCS to receive these benefits together with prioritized support services. |
Common Problems
| 1. The client does not receive the verification email. Check the module and WHMCS mail logs, verify the mail configuration and ask the client to check the spam folder. Wait until the 'Resend Cooldown' ends before trying again. |
| 2. The verification link or code is rejected. The verification details may have expired, already been used or may not match the pending record. Request a new message and use the newest link or code within its validity period. |
| 3. The client cannot request another verification email. The resend cooldown or rate limit may have been reached. Wait until the relevant window ends or review the limits under 'Settings'. |
| 4. A legitimate client cannot complete verification. The client's email address, domain or IP address may be on the blocklist. Review 'Blocklist' and 'Logs', then remove the entry only after confirming the request is legitimate. |
| 5. CAPTCHA verification fails. Go to 'System Settings' → 'General Settings' → 'Security' and confirm that CAPTCHA has been configured correctly in WHMCS before enabling it in the module. |
















