How velocity checks work
Every velocity rule has three parts: a key, an action and a window. The key is what you count by: a card, an account, an email, a device, an IP address or a phone number. The action is what you count: logins, failed logins, signups, payment attempts, password resets, OTP sends. The window is how far back you look: a minute, an hour, a day.
When the count crosses a threshold, the rule fires. The response can be a block, a step-up challenge, a manual review or simply a higher risk score. Velocity checks are cheap, easy to explain and fast, which is why almost every fraud team runs some.
Most teams run several rules at once, each with its own key and window, because a burst that hides under one key often shows up under another.
Common velocity checks and what they catch
| Rule | Catches | Typical page |
|---|---|---|
| Payment attempts per card per hour | Card testing | Checkout, card update |
| Different cards per device per day | Carding, stolen card lists | Checkout |
| Failed logins per account per hour | Password guessing | Login |
| Login attempts per device across accounts | Credential stuffing | Login |
| Signups per device per day | Fake accounts, multi-accounting | Signup |
| OTP sends per number range per hour | SMS pumping | OTP, phone verification |
Where velocity checks fall short
Attackers know velocity rules exist, so they spread their traffic to stay under them. The weak point is almost always the key. Counting by IP address fails against residential proxies that give each request a fresh home IP. Counting by account fails when every attempt uses a new account. Counting by cookie or basic fingerprint fails when an antidetect browser starts each session clean.
Low-and-slow attacks are the other gap. A bot that tries one card per hour per session, across thousands of sessions, never trips a rule while still testing a large list. Tight thresholds catch more, but they also block families on one home connection, office networks and busy mobile carriers.
Better keys make better velocity checks
A velocity check is only as good as the identity it counts. If you can recognize the real device behind rotating fingerprints and proxies, one actor stays one key, and a burst that was hidden across a thousand IP addresses shows up again as a burst.
Kavra gives each visitor an opaque, stable visitor ID and links sessions to the same actor even when the fingerprint rotates. It also watches for coordinated surges of new devices and shared infrastructure. Your velocity rules can count by that actor instead of by IP address. See how this applies to API abuse and card testing prevention.