Velocity limits are fraud rules that cap how often something may happen in a window of time: authorization attempts per card per hour, transactions per IP address, account sign ups per device. Cross the threshold and the next attempt is blocked or challenged.
Why it matters
Velocity rules are the first and cheapest defense against card testing, which depends on volume to work. The craft is in the tuning. Set limits too tight and legitimate customers get declined, too loose and the rules catch nothing. Layering counters across card, IP, device, email and shipping address makes the rules far harder to sidestep than any single counter, and reviewing what the rules actually caught each month keeps them honest.
