August 4, 2026 / Tutorials / 20 min read

Smart COD Rules: Country, ZIP, Cart Value, Customer Tags

See how to control COD availability on Shopify by country, ZIP code, cart value, and customer tags, so the option shows up only where it makes sense.

cod cash-on-delivery fraud-prevention checkout-rules shopify

For many Shopify merchants, Cash on Delivery starts as a simple on/off setting: show it to everyone, or remove it completely. That is also the fastest way to either turn away good customers or absorb avoidable risk.

The fix is not to remove COD. It is to control where it appears. A customer buying a low-value item in a region with a clean delivery history is a very different case from a first-time buyer placing a high-value order in a postal code with a history of failed deliveries. Treating both the same, either by always showing COD or never showing it, ignores the difference.

This is what COD visibility rules are for. Instead of one on/off switch, the store decides who sees cash on delivery as an option in the first place, based on country, ZIP or postal code, cart value, and customer tags. This tutorial walks through setting up each lever in Progus COD Form & OTP SMS.

It is worth separating two things that are easy to conflate before you start. Visibility rules decide whether a customer sees cash on delivery as a payment option at all: if a rule hides COD for a given country, cart value, or customer, that customer never reaches a COD checkout step in the first place. OTP verification is a separate layer that confirms the phone number of a customer who has chosen COD, once they reach that step; it does not decide who sees the option, it checks who is real among the people who already see it. The two work in sequence: visibility rules narrow the field first, and OTP verification checks what is left. For the full picture of how these layers work together with block lists for repeat offenders, see Progus' COD fraud and return abuse playbook; this tutorial focuses specifically on setting up the visibility layer.

Step 1: Turn On Rules Before You Configure Anything

The rule builder needs to be activated before it will let you create rules. In Progus COD Form & OTP SMS, go to the app's Checkout section, choose which shipping rate should count as COD, and turn on COD in checkout. Until this activation is complete, the rules screen will show a "configuration required" message instead of the option to add a rule.

Step 2: Decide Which Levers You Actually Need

Before creating a rule, decide what problem it should solve. Instead of one on/off switch, the app lets you show or hide COD based on country, ZIP or postal code, cart value, and customer tags, and a single rule can combine several of these at once.

A few common starting points:

  • High-value order protection: Hide COD when cart value is above a defined threshold, so higher-risk orders require prepaid checkout.
  • Postal-code exclusion: Show COD in the main domestic market, but hide it for postal codes with repeated failed deliveries or return-to-origin issues.
  • Trusted customer exception: Use a customer tag to keep COD available for returning customers with a clean delivery history, even if broader rules would otherwise restrict it.

Steps 3 to 5 below cover each lever on its own. You do not need to use every lever: pick the ones that match the problem you identified here, and combine them into one rule if your plan allows only one active rule at a time (more on that in Step 7).

Before writing any rule, start from evidence, not assumptions: check which countries, postal codes, or cart-value ranges actually show a pattern of failed COD deliveries or fraud, since a rule based on a hunch is as likely to block good customers as bad ones. Once you know where the real problem is, prefer narrow exclusions over broad restrictions: excluding the specific postal codes with a real problem is safer than restricting an entire region, and restricting a cart-value band above a clear threshold is safer than disabling COD for an entire country because of a handful of bad orders.

The rule builder also supports conditions for discount presence, order weight, customer registration status, order count, customer email, product collections, gift cards in the cart, and date ranges for scheduled or seasonal rules. Those are worth knowing about even if this tutorial does not cover them in depth: a date-range condition, for example, can restrict COD only during a specific promotional window, and an order-weight condition can target COD availability by shipping complexity rather than price alone.

Step 3: Set Country and ZIP Code Conditions

Country. The most basic lever. Some stores offer COD only domestically, where delivery networks are reliable and returns are manageable, while international orders default to prepaid. Others need the opposite: COD enabled specifically in markets where prepaid checkout has low trust and low conversion, and disabled in markets where it is not needed.

ZIP or postal code. Country-level control is often too broad. Delivery reliability, return-to-origin rates, and courier coverage frequently vary by region within the same country. A store with COD problems concentrated in a handful of postal codes does not need to restrict the whole country, only those specific areas, either by excluding known problem codes or by allowing COD only in postal codes with a track record of successful delivery.

Country and postal code live in the same Location category. This means you can create one rule that allows COD in a country, but excludes selected postal codes with repeated failed deliveries, without needing two separate rules.

Separately, the app's fraud-protection area also includes its own postal-code blocking, alongside blocking by email, phone number, and IP address, and limiting how many orders the same customer can place in a given window. That tool is aimed specifically at known bad actors rather than shaping general COD visibility, so a store may end up using postal codes in both places for different reasons: broad visibility shaping in the rule builder here, and targeted fraud blocking in the protection settings.

Step 4: Add a Cart Value Limit

High-value orders carry more absolute risk if a COD delivery fails or is refused: more product cost exposed, more shipping cost sunk, more margin at stake. A common pattern is to cap COD below a cart-value threshold and require prepaid checkout above it, so the orders with the most to lose are the ones with payment confirmed upfront.

Set this as an Order Details condition in the same rule as your location conditions if you are on a plan with a limited number of rules, or as its own separate rule if your plan allows unlimited rules.

Step 5: Use Customer Tags for Trusted or Risky Buyers

Country, ZIP code, and cart value all apply before the store knows anything about the specific buyer. Customer tags let a rule respond to who the buyer actually is: a tag for customers with a clean COD delivery history can keep the option open for them regardless of other conditions, while a tag applied after a failed or refused delivery can restrict COD for that customer going forward without punishing anyone else.

Customer tags are configured under the Customers category in the same rule builder, alongside conditions for registration status, order count, and customer email. Use tags to make exceptions, not just restrictions: a tag is equally useful for keeping COD open for a trusted, returning customer even if a broader rule would otherwise restrict it, so loyalty is not penalized by a rule aimed at strangers.

Step 6: Test How Show and Hide Conditions Work Together

If a single rule combines a "show" condition with a "hide" condition, the app displays a warning, because there is a fixed precedence to know before you rely on the rule: "show" always beats "hide." The "show" condition wins whenever it matches, regardless of what the "hide" condition says.

For example, if a rule hides COD for a specific postal code but also shows COD for customers tagged as [trusted-cod], a customer with that tag may still see COD even if their postal code is on the hide list. That can be useful, but only if it is intentional, so test this combination before assuming a "hide" condition is doing what you expect.

Step 7: Review the Rule After Launch

A postal code that had delivery problems six months ago may not have them now. Rules that are never revisited tend to drift from "targeted at a real problem" to "restricting customers for no current reason," so put a reminder in place to check rule performance rather than only reviewing it at setup.

This feature is listed in the app as Smart checkout rules, and how many rules you can review or add depends on the plan: Free and Basic allow 1 active rule, so review means confirming that single rule still combines the right conditions; Standard and Premium allow unlimited rules, so review means checking whether any rule has become outdated or redundant now that more are running.

Common Mistakes

  1. Writing rules for markets the store barely sells into. Spending configuration effort restricting a country that generates a handful of orders a year is a poor use of time compared to getting the domestic or largest-market rules right.
  2. Stacking too many conditions into one rule. A rule with several combined conditions becomes hard to reason about and hard to debug when something behaves unexpectedly. On plans with unlimited rules, simpler separate rules are usually easier to maintain. On Free or Basic, where only one active rule is available, the priority should be one focused rule that combines only the highest-impact conditions.
  3. Forgetting to test on mobile. Whatever the rule hides or shows, confirm the resulting checkout still looks correct on a phone, since that is where most COD-heavy traffic tends to convert or abandon.
  4. Never checking what the rules actually blocked. A rule that quietly hides COD for a broad condition can suppress real conversion without anyone noticing, if nobody looks at what orders were affected.

A Setup Checklist

Smart COD rules are working well when:

  • rules are based on actual delivery and fraud data for the store, not assumptions about which markets or regions are risky
  • postal-code exclusions are specific, not a proxy for excluding an entire region
  • a cart-value threshold exists for high-risk order sizes, reviewed against real order data rather than a guess
  • customer tags are used to protect trusted repeat buyers, not only to restrict risky ones
  • someone reviews rule performance on a schedule, not only at setup

Final Thoughts

Cash on delivery does not have to be all-or-nothing. Visibility rules let a store keep COD available where it earns its keep, converting hesitant buyers into completed orders, while narrowing it away from the specific countries, postal codes, cart-value ranges, and customer histories where it tends to create risk instead.

The goal is not to make COD rare. It is to make it available in exactly the situations where it works, and absent in the ones where it has not. If cash on delivery is part of your Shopify checkout, Progus COD Form & OTP SMS can help you build that rule set in one place - from COD visibility rules to OTP verification for orders that still need confirmation.

Frequently Asked Questions

What is the difference between COD visibility rules and OTP verification?

Visibility rules decide whether a customer sees cash on delivery as an option at all, based on conditions such as country, cart value, or customer tags. OTP verification is a separate step that confirms the phone number of a customer who has already chosen COD. Visibility rules narrow who reaches that step; OTP verification checks the ones who do.

Should I restrict COD by country or by postal code?

It depends on how concentrated the risk is. If delivery problems are spread evenly across a country, a country-level rule is simpler to manage. If problems are concentrated in specific postal codes within an otherwise reliable country, a postal-code exclusion protects the business without restricting customers who were never a risk.

Can I set a maximum cart value for COD without turning it off completely?

Yes. A cart-value threshold is one of the more common uses of visibility rules: COD stays available below the threshold, and orders above it default to prepaid checkout, so the highest-risk orders by value are the ones with payment confirmed upfront.

Do customer tags override other COD rules?

Not automatically. A customer-tag condition is a "hide" or "show" checkbox like any other condition in the rule builder, so it follows the same precedence as everything else: if a rule combines a "show" condition based on a tag with a "hide" condition based on something else, the "show" condition wins. If you want a trusted-customer tag to reliably guarantee COD regardless of other conditions in the same rule, set it as a "show" condition, since "show" takes priority over "hide" whenever both are present.

What happens if a rule combines both "hide" and "show" conditions?

The app displays a warning when a rule mixes both, and the rule follows a fixed precedence: "show" conditions always take priority over "hide" conditions within the same rule. In practice, this means if any "show" condition matches, COD will display regardless of a "hide" condition also being present, so it is worth checking a rule for this combination before assuming a "hide" condition is doing what you expect.

How many COD visibility rules can I create?

The Free and Basic plans allow 1 active rule at a time, so on those plans the priority is combining your most important conditions (for example, country, cart value, and a postal-code exclusion) into that single rule. The Standard and Premium plans allow unlimited rules, which suits stores that want several separate, simpler rules for different situations instead of one combined rule.