Referral fraud prevention works best when each abuse pattern has a matching control. For a Shopify referral program, that means delaying purchase-based rewards until a qualifying order, verifying identities, watching shared IP addresses, flagging suspicious activity, and capping repeated rewards. The aim is not to block every unusual referral. It is to make abuse unprofitable without punishing honest advocates.

The five ways referral programs get gamed
Referral fraud usually appears as one of five behaviors: a self-referral, mass sharing on coupon sites, collecting rewards before buying, refunding after a reward, or creating fake accounts in bulk. These patterns leave different signals, so treating all unusual activity as the same problem leads to either weak protection or needless customer friction.
Self-referral with a second email
A customer creates another account, sends the referral to that address, and tries to collect both sides of the incentive. A different email does not necessarily represent a different person. Matching network or purchase details can make the relationship easier to review, but shared households and workplaces can produce legitimate overlap.
Referral-link farming on coupon sites
A referrer publishes a personal link where shoppers search for discounts. The resulting orders may be real, yet the referrer did not make a personal recommendation. Look for a sudden concentration of unrelated signups or purchases attributed to one customer rather than assuming every high-volume advocate is fraudulent.
Rewards issued on signup without a purchase
If the valuable reward arrives as soon as a friend registers, an abuser can repeat the account-creation step without generating an order. Rijoy’s referral page describes a purchase-based flow in which the friend completes a first purchase before purchase-based rewards are issued. That sequence ties the incentive to commercial value.
Refund after reward issuance
A referred friend may place a qualifying order, trigger rewards, and then return the order. In Rijoy the referral rule has a “Reward Return Handling” setting; set it to “Recall” so a reward issued for an order that is later refunded is taken back, and pair it with “Reward Issuance Timing: immediately after order payment” only if your refund window is short.
Bulk fake accounts
One operator can create many accounts using disposable inboxes or repeated connection details. Email verification adds a hurdle, while IP tracking and suspicious-activity alerts help expose repetition. None of those signals proves fraud alone; each should inform a review rather than automatically reject a legitimate customer.
The decision matrix: which control stops which abuse
Choose controls by abuse pattern instead of enabling maximum friction everywhere. A qualifying purchase is strongest against signup farming, while limits constrain repeated payouts and alerts surface unusual clusters. Verification and IP signals support identity checks, but they can also catch families, offices, or shared networks, so retain a review path for edge cases.
Abuse pattern | Signal to inspect | Best matching control | Side effect for honest customers |
|---|---|---|---|
Self-referral | Related account or network details | Email verification plus IP tracking | Adds verification and may flag shared households |
Coupon-site link farming | One referrer produces an unusual concentration of unrelated activity | Suspicious-activity alerts plus per-customer reward limits | Can constrain a genuine creator or ambassador |
Signup reward farming | Many registrations without qualifying orders | Minimum purchase requirement and purchase-based reward timing | Delays gratification until checkout |
Refund after reward | Reward followed by a refunded qualifying order | Set Reward Return Handling to Recall in the referral rule | Reversal rules need clear customer communication |
Bulk fake accounts | Repeated account patterns or connection details | Email verification, IP tracking, and suspicious-activity alerts | Shared networks may need manual review |
The matrix is intentionally selective. For example, a purchase condition will not establish whether two buyers are the same person. Likewise, an IP match is a signal rather than proof. Combine controls only when the observed pattern calls for them, then document how support should handle a false positive.
Minimum purchase, reward limits and verification: how to set each one
Sensible settings start with a qualifying first purchase, a per-customer cap based on normal advocate behavior, email verification, and alerts for review. Do not copy an arbitrary numeric threshold from another store. Rijoy publishes the available controls, but not universal default amounts, because order values, margins, return windows, and referral behavior differ by merchant.
The Rijoy referral program names five relevant controls: IP tracking, email verification, minimum purchase requirements, suspicious-activity alerts, and limits on referral rewards per customer. Configure them as separate layers rather than one all-or-nothing fraud switch.
Minimum purchase requirement
Use a minimum purchase requirement when a low-value order would cost more in discounts, products, cash, or points than it contributes in margin. Rijoy confirms that a merchant can require a qualifying purchase before issuing a reward. Set the amount from your own economics and eligible-order rules; Rijoy does not publish a recommended universal value.
Also decide which event earns each side’s reward. Rijoy supports different incentives for the referrer and friend, so a welcome discount can help the friend convert while the referrer’s reward waits for the first completed purchase. This separates acquisition help from the payout most attractive to an abuser.
Referral reward limits
Referral reward limits cap how many rewards one customer can earn. Base the cap on your legitimate referral distribution and review it after campaigns or influencer activity. A hard limit protects the budget, but a genuine advocate who reaches it needs a documented escalation path rather than a silent rejection.
Email verification and IP tracking
Email verification tests whether the new customer controls the submitted inbox. IP tracking can reveal repeated activity from one connection. Use both as signals: students, families, and coworkers may share a network, while a determined abuser can change networks.
Suspicious-activity alerts
Alerts are the review layer. Define who receives them, which evidence the reviewer checks, and whether the outcome is approve, deny, or request more information. Keep a short reason for each decision so support can explain it consistently and future rule changes have an audit trail.
A 15-minute setup order in Rijoy
Use this five-step order to protect the program without blocking honest referrals at the start. Fifteen minutes is a planning estimate for a store with one referral program, not a measured configuration time. The order begins with reward timing, then adds proportionate checks, limits, and review ownership.

- Tie purchase-based rewards to the friend’s first purchase. Rijoy’s referral page states that the friend signs up and completes a first purchase before purchase-based rewards are issued.
- Add the minimum purchase requirement. Choose a qualifying amount from your margin, average order economics, and eligible products rather than using an unsupported industry default.
- Turn on email verification, then use IP tracking as a signal. Verification adds a direct identity hurdle; an IP match should prompt context-aware review, not automatic rejection.
- Set referral reward limits per customer. Start from the highest volume you expect from a real advocate, and define how staff will handle a legitimate customer who reaches the cap.
- Route suspicious-activity alerts to an owner. Specify the reviewer, evidence, response time, and possible outcomes before the first alert arrives.
After saving the settings, test the customer journey with permitted test data. Check the referral link, friend incentive, qualifying purchase event, referrer reward timing, limit behavior, and alert route. Do not use real customer identities in a test account.
What not to do
Avoid controls that create more support work than protection. Blanket manual approval slows every honest referral, signup-only rewards invite repeat registrations, unlimited payouts leave no budget boundary, and unexplained denials damage trust. Use purchase conditions, targeted signals, limits, and alerts together, then reserve manual review for activity that actually looks unusual.
- Do not manually approve every referral. Review the exceptions surfaced by alerts instead of placing every customer in a queue.
- Do not issue the valuable reward on signup alone. Use Rijoy’s documented first-purchase flow for purchase-based rewards.
- Do not leave rewards unlimited per referrer. Apply a per-customer limit and create a path for legitimate high-volume advocates.
- Do not treat one shared IP address as proof. A household or workplace can share a connection, so pair the signal with account and order context.
Set up referral fraud controls in Rijoy
Start with Rijoy pricing, then configure the referral flow and test each control before promotion. Merchants comparing platforms can review Rijoy vs Smile.io. Rijoy’s Free plan covers up to 100 orders a month; check the pricing page for the controls included in each plan.
FAQ
How do you prevent referral fraud in a loyalty program?
Match the control to the abuse: require a qualifying purchase, verify email addresses, inspect shared IP signals, review suspicious-activity alerts, and limit rewards per customer. Rijoy lists these controls on its referral page and in the Rijoy FAQ. Treat signals as evidence for review, not automatic proof.
Should a referral reward require a purchase?
Yes, when the reward is meant to pay for customer acquisition rather than registration. A purchase condition prevents an account signup by itself from triggering a purchase-based payout. Set the qualifying amount from your store’s margin and eligibility rules, not an unsupported universal default.
Can I limit how many referral rewards one customer earns?
Yes. Rijoy states that merchants can limit referral rewards per customer. Review customers near the cap regularly so a genuine advocate or campaign partner can be handled through a documented exception instead of being mistaken for abuse.
What happens to a referral reward if the order is refunded?
Yes, if you set it up that way. Rijoy’s referral rule includes a “Reward Return Handling” option; choosing “Recall” takes back a reward issued for an order that is later refunded, so the refund-after-reward pattern pays out nothing. Document the result in your program terms and support procedure.
Will fraud controls stop real customers from referring?
They can reduce legitimate participation if applied too broadly. Verification adds a step, minimums delay eligibility, limits can catch strong advocates, and shared-IP rules can flag households. Use alerts and exception handling so unusual but honest referrals can still proceed.



