Forum Moderators: phranque
Solutions were:
FRAUD:
1) Change your merchant account to pre-auth if possible.
2) If you use WorldPay, you may be able to block selected email addresses.
3) Check all IP addresses are from the country that they state they are from.
4) Ensure that you do not respond to any emails from people who are using fraudulent cards - with the exception of requesting a fax copy of the card for proof of ownership. Make a standard email for this.
5) On your payment page, display the IP address of the user plus a notice that all fraud attempts are reported to the card issuing company and the police. (Most are not bothered about the police, but they don't want you to stop a stolen card number).
SPAM and VIRUSES:
1) Set up filters based on email address or subject line to delete spam automatically from the server, it will never be downloaded (thus any virus protection software will not cause an alert - but I don't suppose you are getting them, running a Mac :) ). They will be permanantly lost, so be careful when you set them up.