Automate High-Risk Onboarding: Streamline Risky Processes
Learn the best practices to automate high-risk onboarding, reduce security risks, and ensure a smooth, compliant onboarding experience.
Most PSPs trust what merchants declare. eComCharge checks what actually arrives.
Payment processing starts before the transaction is submitted. When a customer opens a checkout page, the browser records where they came from — the domain that sent them there. The platform captures this data and makes it available inside Smart Routing rules, so PSPs and banks can verify, in real time, whether incoming transactions originate from the domains their merchants actually declared — and act on any mismatch automatically.
With referer tracking enabled in Smart Routing, the mismatch surfaces at the transaction level — immediately.
When a customer arrives at the payment page, the platform captures the referring domain. Smart Routing then compares this against the domains registered for that merchant in the system.
Rules and alerts are configured by the eComCharge team based on the PSP’s or bank’s compliance requirements.
During traffic analysis on the platform, a pattern emerged: a merchant registered under one domain was generating transactions from three additional subdomains and regional variants of their site — none of which had been declared. The merchant was not blocked. But the PSP now had visibility they didn’t have before — and could have a conversation with the merchant about their actual traffic setup. That visibility is what Referer Control provides.
Important note. Referer data is captured from browser sessions and reflects the domain visible at the point of checkout. It is not a fraud prevention system and can be circumvented by technically sophisticated actors. Its primary value is transparency and early detection of undeclared traffic sources — not blocking determined fraud.
No. Referer Control works at the platform level. Merchants don't need to integrate or configure anything. You see the data. You decide what to do with it.
Yes. Rules are configured at the merchant or shop level. One merchant can be set to Alert, another to Block — depending on their risk profile and your relationship with their acquirer.
You can whitelist known domains per merchant. Referer Control only flags domains that aren't in the declared list — so legitimate multi-domain merchants won't generate false alerts once their domains are registered.
Referer Control captures the referring domain from the browser at checkout. It applies to card payments processed through the eComCharge checkout — where the browser initiates the session.