> For the complete documentation index, see [llms.txt](https://docs.wandreferrals.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.wandreferrals.com/referrals-sales-and-reversals/fraud-monitor.md).

# Fraud monitoring

## What it does

The **Fraud monitoring** page is a read-only dashboard of suspicious activity over the **last 30 days**. It surfaces the signals Wand Referrals watches so you can decide whether to tighten a program's rules. It does not itself block anything — enforcement lives in your program settings and in the commission eligibility engine.

Fraud monitoring is **available on all plans**.

## The signals

Stat cards summarize the last 30 days:

* **Total clicks** — overall click volume for context.
* **Suspicious IPs (>50 clicks)** — IP addresses with unusually high click counts.
* **Self-referral attempts** — orders flagged where the buyer appears to be the affiliate.
* **Denied commissions** — commissions that were ruled ineligible.
* **Blocked registrations** — sign-ups stopped by IP or email blocking.
* **Bot-like clicks** — clicks whose browser signature matches known bots/crawlers.
* **Blocked IPs / Blocked emails (all programs)** — totals across your program blocklists.

Two tables give the detail:

* **Suspicious IP addresses** — IPs (shown as a truncated hash) with over 50 clicks, their click count, and when last seen. Use this to decide what to add to a program's blocklist.
* **Recent denied commissions** — order, affiliate, reason, tracking method, coupon, and date for commissions that were held or denied.

## What "held for review" means

When the eligibility engine can't clear a commission automatically it records a reason code that appears on the [Referrals & sales](https://github.com/wand-referrals-app/wand-referrals/tree/codex/gitbook-docs-foundation/docs/manual/sales/referrals-and-sales/README.md) pages, for example:

* **Self-referral** — the buyer looks like the affiliate.
* **Held for manual review — suspicious IP velocity.**
* **Held for review — attributed visit came from paid ad traffic.**
* **Order IP is on the program blocklist.**

## Take action

You don't approve or dismiss from the Fraud monitoring page. Instead:

* **Block IPs or emails** in the program's settings (each program keeps its own IP/email blocklist).
* **Tune the fraud toggles** under **Settings → Fraud Detection** (IP velocity, paid-ad traffic, etc.).
* **Review individual orders** on the [Referrals & sales](https://github.com/wand-referrals-app/wand-referrals/tree/codex/gitbook-docs-foundation/docs/manual/sales/referrals-and-sales/README.md) pages, where you can approve, deny, or reopen a referral.

## Related

* [Referrals & sales](https://github.com/wand-referrals-app/wand-referrals/tree/codex/gitbook-docs-foundation/docs/manual/sales/referrals-and-sales/README.md)
* [Settings overview](https://github.com/wand-referrals-app/wand-referrals/tree/codex/gitbook-docs-foundation/docs/manual/settings/settings-overview/README.md)
* [Geo restrictions & eligibility](https://github.com/wand-referrals-app/wand-referrals/tree/codex/gitbook-docs-foundation/docs/manual/programs/geo-and-eligibility/README.md)
* [How attribution works](https://github.com/wand-referrals-app/wand-referrals/tree/codex/gitbook-docs-foundation/docs/manual/attribution/how-attribution-works/README.md)
