# What is a velocity check?

Source: https://kavralab.com/glossary/velocity-check/

A **velocity check** is a fraud rule that counts how many times something happens within a time window, such as payment attempts per card per hour or signups per device per day, and flags or blocks activity above a threshold. It catches bursts that look normal one by one but abnormal together.

## How velocity checks work

Every velocity rule has three parts: a key, an action and a window. The key is what you count by: a card, an account, an email, a device, an IP address or a phone number. The action is what you count: logins, failed logins, signups, payment attempts, password resets, OTP sends. The window is how far back you look: a minute, an hour, a day.

When the count crosses a threshold, the rule fires. The response can be a block, a step-up challenge, a manual review or simply a higher [risk score](https://kavralab.com/glossary/risk-score/). Velocity checks are cheap, easy to explain and fast, which is why almost every fraud team runs some.

Most teams run several rules at once, each with its own key and window, because a burst that hides under one key often shows up under another.

## Common velocity checks and what they catch

| Rule | Catches | Typical page |
|---|---|---|
| Payment attempts per card per hour | [Card testing](https://kavralab.com/glossary/card-testing/) | Checkout, card update |
| Different cards per device per day | Carding, stolen card lists | Checkout |
| Failed logins per account per hour | Password guessing | Login |
| Login attempts per device across accounts | [Credential stuffing](https://kavralab.com/glossary/credential-stuffing/) | Login |
| Signups per device per day | Fake accounts, multi-accounting | Signup |
| OTP sends per number range per hour | SMS pumping | OTP, phone verification |

## Where velocity checks fall short

Attackers know velocity rules exist, so they spread their traffic to stay under them. The weak point is almost always the key. Counting by IP address fails against [residential proxies](https://kavralab.com/detect/residential-proxies/) that give each request a fresh home IP. Counting by account fails when every attempt uses a new account. Counting by cookie or basic fingerprint fails when an antidetect browser starts each session clean.

Low-and-slow attacks are the other gap. A bot that tries one card per hour per session, across thousands of sessions, never trips a rule while still testing a large list. Tight thresholds catch more, but they also block families on one home connection, office networks and busy mobile carriers.

## Better keys make better velocity checks

A velocity check is only as good as the identity it counts. If you can recognize the real device behind rotating fingerprints and proxies, one actor stays one key, and a burst that was hidden across a thousand IP addresses shows up again as a burst.

Kavra gives each visitor an opaque, stable visitor ID and links sessions to the same actor even when the fingerprint rotates. It also watches for coordinated surges of new devices and shared infrastructure. Your velocity rules can count by that actor instead of by IP address. See how this applies to [API abuse](https://kavralab.com/solutions/api-abuse/) and [card testing prevention](https://kavralab.com/solutions/card-testing/).

## FAQ

### What is a good velocity check threshold?

There is no universal number. Start from your own data: look at how often real customers repeat an action, for example card attempts at checkout, and set the threshold well above that. Run new rules in observe-only mode first to count how many real users they would have caught before you let them block anything.

### What is the difference between rate limiting and a velocity check?

Rate limiting protects infrastructure: it caps requests per client so a server is not overwhelmed. A velocity check protects the business: it counts meaningful actions like payments or signups by a fraud-relevant key and feeds a risk decision. Both count over time, but velocity checks care about who and what, not just how many requests.

### Can attackers bypass velocity checks?

Yes, if the key is easy to change. Rotating IP addresses, accounts, emails and device fingerprints lets an attacker spread activity so that no single key crosses the threshold. Counting by a stable identity for the real device and actor, rather than by values the attacker controls, closes most of that gap.

---
Kavra Lab: bot and fraud detection that explains every decision. Book a demo: https://kavralab.com/contact/
