🎉 Now live — a high-converting checkout that cuts RTO & lifts prepaid. Start free →
HomeBlog › OTP at Checkout: Stop Fake Orders, Keep Conversion
Checkout

OTP at Checkout: Stop Fake Orders, Keep Conversion

OTP on the phone field is the cheapest fraud filter in your checkout. But turn it on for everyone and you will quietly lose real buyers too. Here is how to use it like an operator, not a paranoid.

Kwikfy · 2026-07-18 · 9 min read

Key takeaways

A brand I was helping last Diwali had a weird spike: 40 COD orders overnight from one Shopify store, all going to different pincodes, all with phone numbers that looked fine on paper. Every single one bounced at the RTO stage because the numbers were junk. Someone had pointed a script at their checkout. One toggle would have stopped all of it: OTP on the phone field.

OTP verification at checkout is boring, unglamorous, and one of the highest-ROI things you can do to a COD-heavy Indian store. But it is also the toggle most people either ignore or abuse. Let me walk through when it earns its keep and when it just costs you sales.

What an OTP actually stops

When a buyer types their mobile number, you send a one-time code to that number and make them enter it back before the order goes through. Simple. Three specific problems it solves, and they are not the same problem.

That middle one is underrated. A big chunk of RTO in India is not fraud at all, it is unreachable customers because the number was wrong. Fixing the number at checkout is cheaper than any courier-side NDR chase. We go deep on this in reducing RTO on COD orders.

The conversion trade-off nobody admits

Here is the part the OTP vendors skip. Every extra step in checkout leaks buyers. An OTP screen is a real step. On genuine, warm, prepaid traffic I have seen it cost 2-4% of conversions, because a paying customer sitting on a slow 3G connection in Nagpur waits 20 seconds for a code, gets impatient, and bails.

So the honest framing is: OTP has a cost. You are trading a bit of top-line conversion for a lot less RTO and fraud downstream. On a COD order that trade is almost always worth it. On a prepaid order from a repeat customer, it usually is not, because the payment already proved the phone is theirs in spirit and money is already collected.

Never put an OTP wall in front of a prepaid customer who has already paid. The money cleared. You are only adding friction after the sale is done.

WhatsApp-first OTP, SMS as backup

The delivery channel matters more than people think. Classic SMS OTP in India is slow, sometimes stuck in operator queues for 30-60 seconds, and DLT template approvals are a headache. WhatsApp changed the math.

Sending the OTP over WhatsApp from your own approved business number has three advantages: it lands in a second or two, the customer already trusts that green tick, and it costs a fraction of transactional SMS. Because the code arrives from the brand they just bought from, open rates are near total. If you are not already sending from your own number, read setting up WhatsApp automation on Shopify.

But not everyone is on WhatsApp, and not every number the buyer typed is a WhatsApp number. So the smart pattern is a fallback chain.

  1. Try WhatsApp OTP first from your business number. Most buyers get it instantly.
  2. If WhatsApp delivery fails or times out after ~15-20 seconds, auto-fall back to SMS OTP on the same number.
  3. Give a 'resend' option and a 'call me the code' option for the stubborn 1% on a bad network.
  4. Cap attempts at 3-4 so a bot cannot brute-force the code, then soft-lock for a few minutes.

This way genuine buyers on WhatsApp fly through, buyers on a basic phone still get verified over SMS, and you are not paying SMS rates for 90% of your traffic.

When to turn it on: risk-based, not blanket

This is where most stores get it wrong. They flip OTP on for the entire checkout, watch conversion dip, panic, and turn it off completely, keeping the fraud. The right answer is in between: show OTP only when the order looks risky.

If your checkout has an order-level risk score, you gate on it. A first-time buyer, brand-new phone number, high cart value, going COD to a pincode with a bad RTO history? Show the OTP. A repeat customer, known-good number, prepaid, low value? Wave them through. We break down the scoring logic in RTO risk scoring for orders.

Order profilePaymentOTP decision
New number, high-RTO pincode, high valueCODYes, always
First-time buyer, average valueCODYes
Repeat customer, known-good numberCODOptional / skip
Any customerPrepaid (paid)Skip
Bulk / suspicious pattern (many orders, one IP)CODYes, mandatory

The point is proportionality. You accept a small conversion cost exactly where the fraud and RTO risk lives, and you leave your best customers alone. This is the same philosophy behind COD fraud detection in general: filter the risky, do not tax the loyal.

Start OTP on COD orders above your average order value only. Watch RTO for two weeks, then widen or narrow the net based on what the numbers say, not vibes.

The privacy and DPDP angle for saved addresses

There is a second, quieter reason OTP matters now, and it is about privacy, not fraud. If your checkout speeds things up by recognising a returning customer's phone and pre-filling their saved address (the address autofill pattern), you are about to reveal someone's home address on the say-so of a typed phone number.

Under India's DPDP Act, personal data like a home address deserves protection. Anyone could type a stranger's mobile number and see where they live. That is a real leak. The clean fix is: before you reveal a saved address tied to a number, verify with an OTP that the person holding the phone is the person you are showing data to.

So OTP does double duty here. It confirms the number is reachable and real (anti-fraud), and it confirms the person is entitled to see the saved profile (consent and privacy). One code, two problems solved. For a cross-store identity network especially, this verification step is non-negotiable.

Common mistakes I see

Add smart OTP to your checkout in one toggle

Kwikfy's one-page checkout does risk-based OTP over your own WhatsApp number with SMS fallback, so you stop fake COD orders without taxing real buyers.

Start Free →

OTP is not a growth hack and it is not a silver bullet. It is a filter with a known cost. Used bluntly it hurts. Used with a bit of judgment, on the orders that actually carry risk, delivered over the channel your customer already trusts, it quietly removes a whole category of RTO and fraud from your day. That is worth a toggle.

Frequently asked questions

Does OTP verification reduce my checkout conversion?
On risky COD traffic, no, because you were losing those orders to RTO and fraud anyway. On genuine prepaid or repeat-buyer traffic it can cost 2-4% of conversions, which is why you should not blanket-apply it. Gate OTP to high-risk orders and skip it for customers who have already paid.
WhatsApp OTP or SMS OTP, which is better?
WhatsApp-first, SMS fallback. WhatsApp OTP from your own business number lands in a second or two, costs less than transactional SMS, and comes from a number the buyer already trusts. But keep SMS as automatic fallback for buyers who are not on WhatsApp or whose number is not WhatsApp-enabled.
Should I turn on OTP for every order?
No. Blanket OTP costs you conversion on good traffic and stores usually end up disabling it entirely, keeping the fraud. Use a risk-based rule: OTP on new numbers, high-value COD, and RTO-prone pincodes; skip it for prepaid and known repeat customers.
Is showing a saved address after entering a phone number a privacy risk?
Yes, if there is no verification. Anyone could type a stranger's number and see their home address, which is a data leak under the DPDP Act. Requiring an OTP before revealing a saved address makes sure the person holding the phone is the one entitled to see the data.

Ready to run a tighter, more profitable store?

Join Indian D2C brands streamlining their entire operation on Kwikfy.

Get Started Free →