How to stop fake COD orders in Pakistan
Fake COD orders are caught before the courier is booked, not after. Five checks, in the order that saves the most money, built on WhatsApp.
A fake COD order is a cash-on-delivery order that was never going to be paid for at the door — a prank, a wrong number, an impulse the customer has already forgotten, or a duplicate. In Pakistan it costs twice: once to send the parcel out with Leopards, PostEx, M&P or TCS, and again to bring it back. The only cheap moment to catch one is before the courier is booked.
WhatsApp is how most Pakistani stores do that now, because the customer is already on it and a button tap is faster than a phone call. This guide is the full defence: what to check, in what order, and how to build each check without writing code.
Why COD fraud hits Pakistani stores hardest
Pakistan's online payments are growing fast, but they are not replacing cash on delivery for small stores yet. The State Bank of Pakistan's FY25 payment systems release reports that account- and wallet-based channels carry 93% of online transactions, and that digital channels were 88% of all retail transactions, up from 78% in FY23. Those figures count only payments that went through a bank, wallet or card — a parcel paid for in cash at the door never appears in them.
So beware of any precise figure for COD's share of Pakistani orders. We could not trace the widely repeated ones to an official source. The number that matters is yours: open your courier portal and divide returned parcels by shipped parcels for the last three months.
The five kinds of bad COD order
| Kind | What it looks like | What catches it |
|---|---|---|
| Prank or fake number | No WhatsApp on the number, or someone who never ordered | Confirmation message before booking |
| Changed mind | Real customer, ordered late at night, regrets it by morning | Confirmation with an easy Cancel button |
| Undeliverable address | "Near masjid, Gulshan" and nothing else | Address check that asks for more |
| Duplicate | Same customer, two orders a few minutes apart | One confirmation per order, and a human glance at the Pending list |
| Repeat refuser | Refused a parcel before, orders again | A customer tag written when the courier reports a return |
Every row is caught by a message or a tag, and none needs a phone call unless the customer stays silent.
WhatsApp, a phone call or an SMS code?
| Phone call | SMS code | WhatsApp buttons | |
|---|---|---|---|
| Staff time per order | A call, often two | None | None, unless silent |
| Works at 2am | No | Yes | Yes |
| Proves the number is real | Yes | Yes | Yes |
| Customer can cancel in one tap | No | No | Yes |
| Opens a free chat for follow-ups | No | No | Yes, for 24 hours |
| Writes the answer onto the Shopify order | Only if someone types it | Depends on the app | Yes, as a tag |
Calls still have a place: they are the right tool for the small group who never answer a message. The point of the flow is to shrink that group so your team calls dozens of customers a day instead of hundreds.
Check 1: confirm before you book the courier
This is the check that pays for everything else. The moment Shopify records a COD order, the customer gets a WhatsApp message with two buttons, and the order is tagged so your packing team does not ship it yet.
- In Automations, install the cash-on-delivery order confirmation blueprint. It arrives as a draft.
- It starts with Shopify Store Event → Order placed. Add an If Shopify Event Data step after it, with payment_gateway_names contains the name your COD method uses on your orders (often "Cash on Delivery"), so prepaid orders are skipped.
- The blueprint tags the order Pending Confirmation with Update Shopify Order Tags.
- Ask Customer a Question sends your approved template with the buttons Confirm order and Cancel order.
- On Confirm, the tag changes to confirm order and the customer is thanked. On Cancel, the tag changes to cancel order and Update Shopify Order Status → Cancel the order cancels it in Shopify.
- Test with a real order to your own number, then press Publish.
The template must be a utility template with no discount in it — one promotional line makes it marketing, which costs more and needs marketing opt-in. Meta's templates overview says review "can take up to 24 hours", so create it before the sale, not on the day. Wording and button rules are in confirming COD orders on WhatsApp.
Check 2: an address the rider can actually find
Many refused parcels were never refused — the rider could not find the house. The confirmation template can show the delivery address, so the customer sees it and can correct it. For addresses that are clearly too short, add a second step:
- After the customer taps Confirm, add If Shopify Event Data with Street address line 1 — character length is less than — a number such as 15. Orders with a longer address stop here.
- Then Ask Customer a Question with a text reply: "Please send your full address with a nearby landmark." Use its Save reply to setting to keep the answer on the customer.
- Add an Add Internal Note with the answer, and tag the Shopify order so the packer copies the new address onto the booking.
The customer's tap on Confirm opened a 24-hour customer service window, per Meta's sending messages documentation, so this question is free. More patterns are in delivery address verification on WhatsApp.
Check 3: what to do when nobody answers
Some customers never reply, and silence is not a no. The blueprint waits 24 hours for the tap. After that:
- From the question's No reply path, send one reminder template.
- Add Wait Before Next Step — a few hours — then Has Customer Replied?.
- If still silent, leave the order tagged Pending Confirmation. That tag in Shopify is your call list.
Do not auto-cancel on silence. Customers who do not read WhatsApp promptly are still customers, and a phone call converts many of them. And do not send a second reminder: each one is a charged template to someone who is not answering, and unanswered repeat messages lead to blocks that hurt your quality rating.
Check 4: remember who refused last time
A customer who refused a parcel once is the riskiest order you will get. You can catch them automatically if your courier is connected — ConvoFly reads parcel statuses from Leopards, PostEx and M&P, covered in tracking updates from Leopards, PostEx and M&P.
- In a courier flow, when the status class is returning or returned, add Update Customer Tags with a tag such as refused-parcel.
- In your order-placed flow, add Check Customer Tags for that tag on a separate rule.
- For those customers, tag the Shopify order hold - repeat refusal and use Assign Chat to hand it to a person, who can ask for the delivery charge in advance.
One limit to be honest about: this only knows refusals at your store. ConvoFly does not share a blacklist between merchants, so a customer who refuses everyone else's parcels arrives clean the first time.
Check 5: give a reason to pay upfront
The only COD order that cannot be refused is one that is not COD. Once the customer has tapped Confirm, the window is open and a follow-up offering a small benefit for paying by bank transfer, Easypaisa or JazzCash costs nothing to send. The trade-offs are in converting COD orders to prepaid.
How the checks compare
| Check | Stops | Messages per order | Charged by Meta? |
|---|---|---|---|
| 1. Confirm before booking | Pranks, changed minds, wrong numbers | 1 template, plus free replies | Yes, one utility template |
| 2. Address check | Rider-can't-find returns | 1 question | No — inside the window |
| 3. One reminder | Missed first message | 0 or 1 template | Yes, when sent |
| 4. Repeat-refuser tag | Known refusers | 0 | No |
| 5. Prepaid offer | COD risk entirely | 1 message | No — inside the window |
Charging rules are from Meta's pricing page: utility templates are charged outside a customer service window and free inside one, and non-template replies are free inside it. What that comes to in money is in WhatsApp API pricing in Pakistan.
Customers answer in Roman Urdu
Buttons avoid most language problems, but some customers type instead: "haan", "ji", "theek hai", "confirm hai". If you add a typed fallback, list those words, or the flow will treat a yes as silence. See multilingual automation.
How to tell it is working
- In Shopify: count orders tagged confirm order, cancel order and Pending Confirmation each week. Every cancelled order is a round trip you did not pay for.
- In ConvoFly: the Shipped, not delivered screen lists every parcel your courier still has, with a banner totalling the cash on delivery sitting on parcels that need attention.
- In your courier portal: compare your return rate for the three months before and after. That is the number that decides whether the flows paid for themselves.
Mistakes that make fake orders worse
- Booking the courier before the tap. If packing does not filter on the tag, the confirmation changes nothing.
- A discount in the confirmation. It turns a utility message into marketing.
- Messaging people who never ordered. WhatsApp's Business Messaging Policy requires opt-in for anything beyond the transaction they started.
Common questions
Is a WhatsApp confirmation better than an SMS code?
It does more. A code proves the number is real; a WhatsApp tap also opens a free 24-hour window for the address check and the prepaid offer.
Should I cancel orders that never confirm?
Not automatically. Hold them under Pending Confirmation and call.
Does this work without Shopify?
The blueprint needs Shopify's order events. Other stores can start a flow from their own system through an external event.