How to stop spam and bot attacks on Adobe Commerce Cloud
Fake registrations, newsletter spam and card testing on Adobe Commerce Cloud — how to detect them and block them with Fastly WAF, reCAPTCHA and rate limits.
Fake registrations, newsletter spam and card testing on Adobe Commerce Cloud — how to detect them and block them with Fastly WAF, reCAPTCHA and rate limits.
Signs your store is under a spam attack
Spam attacks rarely take a store offline, so they often go unnoticed until something else breaks — your email provider flags bounces, your payment gateway warns about declined transactions, or your CRM fills with gibberish accounts.
- Hundreds of new customer accounts with random names or Cyrillic/Chinese characters
- Newsletter sign-ups from disposable email domains
- Spikes of $0–$1 authorisation attempts in your gateway (card testing)
- Contact-form messages full of links
- High traffic to /customer/account/createpost or /newsletter/subscriber/new
Step 1: Turn on reCAPTCHA for every public form
Adobe Commerce ships with Google reCAPTCHA support. In the admin go to Stores → Configuration → Security → Google reCAPTCHA Storefront and enable reCAPTCHA v3 (invisible) for customer create, login, forgot password, newsletter, contact, product reviews, PayPal PayFlow and place order.
Use v3 “invisible” where you can — it scores traffic without showing a puzzle to real customers, so conversion is not affected.
Step 2: Use Fastly WAF and rate limiting
Every Adobe Commerce Cloud project includes Fastly CDN, and Pro plans include the Fastly Next-Gen WAF. Rules at the edge stop bots before they reach PHP, which also protects your server capacity during an attack.
- Rate-limit POST requests to registration, newsletter and checkout endpoints
- Block or challenge known bad ASNs and data-centre IP ranges
- Use Fastly Edge ACLs to block repeat offenders
- Add geo rules if you only sell in certain countries
Step 3: Stop card testing at checkout
Card testing is the most expensive form of spam: fraudsters use your checkout to validate stolen cards, and your gateway may suspend your account. Combine platform and gateway defences.
- Enable reCAPTCHA on “place order” and payment methods
- Turn on your gateway’s fraud tools (Stripe Radar, Adyen RevenueProtect, Braintree Advanced Fraud)
- Require a minimum order value for guest checkout during an attack
- Alert on unusual numbers of failed payments per hour
Step 4: Clean up the damage
Once the attack is blocked, remove fake customers and subscribers so they don’t damage email deliverability or skew analytics. Export suspicious accounts by creation date and email domain, review, then delete in bulk. Re-check your email platform list and suppress disposable domains.
Step 5: Monitor so it doesn’t happen again
Set alerts for new-account spikes, failed payments and 4xx/5xx rates in New Relic (included with Adobe Commerce Cloud). Review Fastly WAF logs weekly for the first month after an attack.
Common mistakes to avoid
How we help with security
Frequently asked questions
Does Adobe Commerce Cloud include a WAF?
Yes. Adobe Commerce Cloud Pro includes the Fastly Next-Gen WAF, and all Cloud projects include Fastly CDN with configurable rate limiting and edge ACLs.
Will reCAPTCHA hurt conversion?
reCAPTCHA v3 is invisible to most users and rarely affects conversion. Avoid v2 checkbox challenges on checkout.
How do I know if I am being card-tested?
Look for many small or failed authorisations from different cards in a short time, often with the same IP ranges or email patterns.