ReturnSift

Should return scores use device and IP signals?

Return scoring usually starts with behavior: return rate, frequency, reason codes, item categories. Those signals are strong, but they share a blind spot. They score the account, and fraudsters stopped using one account a long time ago. Device and IP signals score the actor behind the accounts, which is where the rings live.

The catch is that device and IP signals are noisy in exactly the ways that hurt honest customers: households share devices, offices share IPs, and mobile networks rotate addresses constantly. Used naively they punish families. Used carefully they are the best ring-detection signal you have.

What device and IP signals actually catch

The classic ring pattern is five accounts, one device. Each account stays under the per-account return threshold, so behavioral scoring sees five clean customers. Device fingerprinting sees one actor running five accounts and the score reflects reality. This is the single highest-value use of device signals in return scoring.

IP signals catch the lazier version: multiple accounts from one residential IP placing high-return orders in the same week. It also catches the organized version, where a ring runs accounts through a small set of proxies and the IP diversity is suspiciously low for the account count. Neither pattern is visible to account-level behavioral scoring.

The false positive problem, honestly

Households are the big one. Two or three family members ordering from the same phone or laptop, each with their own account, each returning at normal rates, looks exactly like a small ring to a naive device-linking model. The difference is in the behavior attached to the link: ring accounts show coordinated timing and correlated return patterns, households show independent purchase histories that happen to share hardware.

Shared IPs are the second trap. Corporate offices, dorms, and apartment buildings with shared wifi put dozens of unrelated customers behind one address. Scoring the IP itself, rather than using it as one linking input among many, turns a whole building into suspects. Mobile carrier IPs are worse: thousands of customers can share an egress IP in an hour.

How to weight them in the score

Treat device and IP as linking signals, not as risk scores on their own. The pattern that should move the score is linkage plus corroboration: shared device across accounts that also share return timing, item overlap, or address fragments. Linkage alone is a flag for review; linkage with behavioral corroboration is a score input.

Decay matters more for device signals than for most inputs. A device link from 18 months ago, a phone since replaced, should carry almost no weight. Rings rotate hardware too, so stale links are noise either way. Time-decay the linkage so the score reflects the current actor, not the historical one.

The practical setup

Start with device fingerprinting on the return flow specifically, not just checkout. Fraudsters are careful at purchase and sloppy at return, and the return flow is where the account-linking evidence accumulates. Pair it with a household-aware review rule: linked accounts with independent purchase histories get a pass, linked accounts with correlated return behavior get scored.

Device and IP signals will not replace behavioral scoring. They fix its blind spot. The accounts are the masks; the devices are the faces. Score both and the rings lose their favorite trick.